The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Associate General Counsel, Privacy (from a large enterprise)
3-5 years in previous roleSkills to master
- Deep understanding of enterprise-level risk management, executive-level communication, and leading cross-functional privacy initiatives. You'll need to have managed significant regulatory interactions.
You're ready to move on when
- Successfully led a major privacy programme component (e.g., incident response, global compliance) for a large, complex organisation.
- Regularly presented to senior leadership or Board committees on privacy matters.
- Managed a team of 10+ privacy professionals, including other managers.
- Proven ability to influence business strategy without direct authority.
- 2
Head of Data Protection / Chief Privacy Officer (from a smaller/mid-sized company)
4-6 years in previous roleSkills to master
- Scaling privacy programmes for rapid growth, navigating a broader range of regulatory challenges, and building out a larger, more diverse team. You'll need to adapt to a larger organisational structure and more complex stakeholder landscape.
You're ready to move on when
- Built a privacy programme from the ground up or significantly scaled an existing one.
- Directly managed all regulatory interactions and major data breaches.
- Owned the privacy budget and technology stack.
- Demonstrated ability to operate with significant autonomy and strategic oversight.
- 3
Senior Partner / Of Counsel (from a top-tier law firm, specialising in Privacy)
5-8 years as a senior lawyerSkills to master
- Transitioning from client advisory to in-house operational leadership, building and managing an internal team, and integrating legal advice directly into business strategy. You'll need to get comfortable with the 'messiness' of internal politics and resource constraints.
You're ready to move on when
- Led major privacy engagements for multiple large, complex clients.
- Provided strategic privacy advice to C-suite and Board-level clients.
- Managed large legal teams on complex projects.
- Demonstrated business acumen beyond pure legal advice.