The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Director of Data Protection & Privacy (Global)
3-5 years in this role before CPOSkills to master
- Enterprise programme management, global team leadership, board-level reporting, strategic vendor management, and complex regulatory engagement.
You're ready to move on when
- Successfully led a multi-year transformation of a key privacy domain (e.g., global incident response, PbD programme).
- Consistently received positive feedback from the Board and CEO on strategic insights and risk mitigation.
- Demonstrated ability to influence and align diverse business unit leaders on privacy initiatives.
- Built and mentored a high-performing team of privacy leaders.
- 2
General Counsel (with strong Privacy focus)
5-7 years in this role before CPOSkills to master
- Broad legal expertise (corporate, commercial, litigation), enterprise risk management, M&A legal oversight, and managing large legal departments, all with a deep understanding of privacy's intersection.
You're ready to move on when
- Successfully managed complex legal challenges with significant privacy implications.
- Proven ability to balance legal risk with commercial objectives at an executive level.
- Deep understanding of the company's overall legal and regulatory landscape beyond just privacy.
- Demonstrated leadership in managing external counsel and large legal budgets.
- 3
Chief Compliance Officer (with significant Privacy remit)
4-6 years in this role before CPOSkills to master
- Designing and overseeing enterprise-wide compliance programmes, ethical conduct, anti-bribery, and regulatory liaison, with a specific focus on integrating privacy into broader compliance frameworks.
You're ready to move on when
- Successfully built and operated an effective, enterprise-wide compliance management system.
- Proven ability to influence ethical behaviour and compliance culture across the organisation.
- Strong track record of positive engagement with multiple regulatory bodies.
- Demonstrated understanding of the interplay between privacy, ethics, and other compliance domains.