The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
From Information Governance Analyst (L2)
2-3 years as an AnalystSkills to master
- Taking ownership of routine processes, identifying issues and proposing solutions, beginning to mentor new joiners, and consistently delivering reliable work within guidelines.
You're ready to move on when
- You've successfully managed several routine eDiscovery cases independently.
- You've taken the initiative to improve an existing governance process.
- You're regularly sought out by junior colleagues for advice or guidance.
- You've started drafting initial versions of policy updates or new procedures.
- 2
From Legal/Compliance Specialist
5-7 years in a legal or compliance roleSkills to master
- Translating legal requirements into practical business processes, understanding information systems, and developing strong project management skills.
You're ready to move on when
- You've been involved in data-related legal matters (e.g., eDiscovery, privacy).
- You've drafted internal compliance policies or guidelines.
- You have a keen interest in how technology impacts legal and compliance operations.
- You're comfortable explaining complex legal concepts to non-legal business teams.
- 3
From IT/Security Analyst with Data Focus
5-7 years in IT Security, Data Management, or a related fieldSkills to master
- Developing a deep understanding of regulatory requirements, policy drafting, and stakeholder engagement beyond purely technical teams.
You're ready to move on when
- You've worked with DLP solutions or data classification tools.
- You understand data storage and lifecycle management from a technical perspective.
- You're interested in the 'why' behind data security and compliance, not just the 'how'.
- You've had experience training users on security or data handling best practices.