The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Information Compliance Associate (L1)
2-3 yearsSkills to master
- Mastering the basics of DSAR processing, accurate record classification, and understanding core privacy principles. You'll be executing tasks under close supervision.
You're ready to move on when
- Consistently delivering accurate and timely completion of assigned compliance tasks.
- Proactively identifying minor issues and bringing them to your supervisor's attention.
- Demonstrating a solid grasp of internal policies and standard operating procedures.
- Showing initiative to learn new regulations and tools.
- 2
Junior Legal/Privacy Officer (from a law firm or in-house legal team)
2-4 yearsSkills to master
- Translating legal theory into practical operational steps, understanding business context, and developing strong communication skills for non-legal audiences.
You're ready to move on when
- A desire to move from purely legal advice to hands-on operational implementation.
- Experience in a client-facing role, even if internal, where you had to explain complex concepts.
- An interest in technology and how it impacts data handling.
- Ability to work independently on defined processes.
- 3
Records Coordinator / Archivist (from a regulated industry)
3-5 yearsSkills to master
- Expanding knowledge beyond physical records to digital information, understanding data privacy regulations, and applying records management principles to live business systems.
You're ready to move on when
- Strong foundational knowledge of records lifecycle management and retention schedules.
- Experience with digital archiving or document management systems.
- A keen eye for detail and a methodical approach to information organisation.
- A desire to broaden your scope into data privacy and information security.