The pathway
How you actually get there, here
How you become one varies far more by country than what one does. This is the UK route. Most people take one of these ways in; the right one depends on where you're starting from.
- 1
Privacy Analyst (L1)
1-2 yearsSkills to master
- Mastering DSAR processing, understanding the basics of ROPA, initial incident logging, and learning core privacy principles.
You're ready to move on when
- Consistently closing DSARs on time with minimal supervision.
- Proactively identifying minor ROPA inaccuracies and correcting them.
- Confidently answering routine privacy queries from internal teams.
- Demonstrating a solid grasp of GDPR Article 5 principles in practice.
- 2
Legal Assistant / Paralegal (with privacy focus)
2-3 yearsSkills to master
- Translating legal advice into practical steps, understanding legal research methodologies, and managing legal documentation, specifically around data protection.
You're ready to move on when
- Successfully supported privacy counsel on multiple projects.
- Can independently conduct basic legal research on privacy topics.
- Demonstrates a clear understanding of legal risk in a business context.
- Has drafted or reviewed privacy-related legal documents (e.g., DPAs, privacy notices).
- 3
Compliance Administrator / Officer (with data focus)
2-4 yearsSkills to master
- Understanding regulatory frameworks, managing compliance processes, conducting internal audits, and developing compliance training, with a specific emphasis on data-related regulations.
You're ready to move on when
- Managed compliance for a specific data-heavy regulation (e.g., PCI DSS, ISO 27001).
- Conducted internal compliance reviews related to data handling.
- Developed or delivered training on data-related compliance topics.
- Can identify and assess compliance gaps in data processing activities.


