The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Information Compliance Analyst (Internal Promotion)
3-5 years as an AnalystSkills to master
- Deep understanding of our internal systems and data flows, independent execution of routine compliance processes, strong foundational knowledge of GDPR/CCPA, and the ability to identify process improvements.
You're ready to move on when
- Consistently exceeds expectations in managing DSARs and conducting routine audits.
- Proactively identifies and flags potential compliance issues.
- Has taken the initiative to train new team members or document complex processes.
- Demonstrates strong problem-solving skills for non-routine compliance challenges.
- 2
Privacy Specialist / Data Protection Officer (External Hire)
5-7 years in a similar role elsewhereSkills to master
- Broad experience across various data protection regulations, strong policy development skills, experience with GRC platforms, and a proven track record of leading compliance initiatives.
You're ready to move on when
- Can articulate complex regulatory requirements and how they translate into practical controls.
- Has experience managing relationships with legal teams and external auditors.
- Brings a fresh perspective on compliance best practices from previous organisations.
- Demonstrates leadership potential and the ability to mentor junior staff.
- 3
IT Audit / Risk Specialist (External Hire)
5-8 years in IT audit or risk managementSkills to master
- Strong understanding of control frameworks (e.g., NIST, ISO 27001), experience with technical security controls, and the ability to assess and report on information risk.
You're ready to move on when
- Proven ability to conduct technical audits and identify control weaknesses.
- Understands the interplay between IT security and data privacy.
- Can translate technical risks into business impact for non-technical stakeholders.
- Eager to specialise in the specific nuances of information compliance within Knowledge Management.