The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Privacy Assessment Specialist (L2)
2-3 yearsSkills to master
- Independently managing standard PIAs, effective stakeholder communication for routine projects, basic regulatory interpretation, and meticulous documentation.
You're ready to move on when
- Consistently delivering accurate and timely PIAs for low-to-moderate risk projects.
- Proactively identifying and proposing solutions for common privacy issues.
- Receiving positive feedback from project teams on your collaborative approach.
- Demonstrating a strong understanding of our internal PIA methodology and tools.
- 2
Legal Counsel (Privacy Focus)
3-5 yearsSkills to master
- Deep expertise in privacy law, contract review (DPAs), legal advice on new products, and managing regulatory inquiries.
You're ready to move on when
- Proven ability to translate complex legal texts into practical business advice.
- Experience advising on a range of privacy-related legal issues beyond just assessments.
- Strong analytical and research skills in data protection law.
- Comfortable engaging directly with senior business leaders on legal risk.
- 3
Information Security Analyst (with Privacy Focus)
4-6 yearsSkills to master
- Understanding of security controls, risk management frameworks (e.g., ISO 27001), incident response, and how security impacts privacy.
You're ready to move on when
- Demonstrable knowledge of technical security measures and their privacy implications.
- Experience conducting security risk assessments or audits.
- Ability to articulate security requirements in a privacy context.
- Strong collaboration with legal teams on data protection matters.