The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Recent University Graduate (Law, IT, or related)
0-1 year in role to progressSkills to master
- GDPR fundamentals, our internal processes for DSARs and RoPAs, accurate data entry, clear communication.
You're ready to move on when
- Consistently accurate completion of all assigned tasks.
- Proactive learning and asking insightful questions.
- Demonstrated ability to follow complex procedures without constant supervision.
- 2
Paralegal or Legal Administrator
1-2 years in role to progressSkills to master
- Transitioning from general legal admin to specific data protection tasks, understanding the regulatory context of privacy work, using privacy-specific software.
You're ready to move on when
- Successfully managing a small caseload of routine privacy tasks.
- Ability to identify and escalate complex privacy issues effectively.
- Strong grasp of GDPR principles and how they apply to our business.
- 3
Compliance Support Officer
1-2 years in role to progressSkills to master
- Deepening knowledge of GDPR beyond general compliance, understanding data flows and technical aspects of data protection, stakeholder engagement.
You're ready to move on when
- Demonstrating initiative in improving small parts of privacy processes.
- Reliable in managing recurring privacy tasks and deadlines.
- Effective communication with internal teams on privacy matters.


