Group Data Compliance Manager
PureGym
Overview
In this role you will lead PureGym’s global privacy and data protection strategy as the designated Data Protection Officer, collaborating with the Health & Safety team to safeguard data and support growth. You will drive governance, regulatory engagement, and privacy by design across markets, shaping a culture of accountable data use. You will partner with executive leadership to balance compliance with commercial objectives, navigating cross-border transfers and complex DPIAs. This is a strategic, high-impact role in a fast-scaling, people-focused organisation.
Pay / Benefits
- Free nationwide gym membership for you + 1
- Hybrid working
- Private healthcare including digital GP
- Life insurance x4
- Company pension contribution
- 25 days annual leave plus 1 personal day
Responsibilities
- Lead the Data Protection Officer function and privacy governance
- Oversee regulatory engagement and compliance programme management
- Manage Data Protection Impact Assessments (DPIAs) and Data Subject Rights handling
- Govern cross-border data transfers and third-party data processor reviews
- Incident and breach management and data privacy risk reporting
- Maintain group policies, retention schedules, and data mapping activities
- Provide training, awareness, and culture around privacy
- Support ROPA and data governance practices
- Balance regulatory requirements with commercial objectives
- Advise senior leadership on privacy and data protection matters
Key requirements
- Significant experience leading data protection and privacy programmes in a multi-jurisdictional environment
- Experience as Data Protection Officer or senior privacy professional
- Expert knowledge of UK GDPR, EU GDPR, Swiss FADP, applicable US privacy legislation, and international transfer requirements
- Experience managing regulatory interactions and investigations
- Strong understanding of privacy by design, DPIAs, and privacy risk assessments
- Experience handling data subject rights requests and complaints
- Experience reviewing supplier privacy compliance arrangements
- Knowledge of information governance and records management
- Ability to influence senior leadership and balance compliance with business needs
- High integrity, accountability and professional judgement
- Strong stakeholder management and influencing abilities
- Excellent communication and presentation skills
- Attention to detail and organisational capability
- UK GDPR, EU GDPR, Swiss FADP, US privacy legislation
- DPIAs and privacy risk assessments
- Data mapping and ROPA
Reference: WJ-799_28484888