← The wire

Head of Compliance and Data Privacy - 12 month FTC

ASOS plc · London, gb

Posted 52m ago · first seen by the radar 52m ago · last checked on the employer's board 1m ago

Director · Onsite · Full-time

Company Description

We're ASOS, the online retailer for fashion lovers all around the world.

We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgement, and channel your creativity into a platform used by millions.

Everyone needs some help showing up as their best self. We're Disability Confident Committed - let our Talent team know if you need any reasonable adjustments throughout the recruitment process.

Job Description

At ASOS, data and trust are fundamental to how we serve millions of customers around the world. As our Head of Compliance and Data Privacy, you'll lead our global privacy and compliance agenda, acting as ASOS's Data Protection Officer (DPO) and trusted advisor to senior leaders across the business. This is a high-profile leadership role with responsibility for ensuring our approach to privacy, data protection and compliance is commercially focused, practical and fit for a fast-moving global retailer.

You'll partner with teams across Technology, Data, Marketing, Supply Chain, Procurement, People and Commercial functions, helping them navigate complex regulatory requirements while enabling innovation and growth. Alongside leading our Privacy team, you'll oversee the Compliance function, shaping frameworks, governance and policies that support ASOS's continued success.

The Details

  • Act as the independent Data Protection Officer (DPO) for UK and EU operations, ensuring global privacy compliance.
  • Provide expert guidance on current and emerging privacy legislation and regulatory changes.
  • Advise the business on privacy implications of strategic and commercial initiatives.
  • Support the management and mitigation of privacy risks across the organisation.
  • Design and deliver privacy programmes that demonstrate compliance and enhance customer trust.
  • Lead responses to data breaches and critical incidents, including stakeholder and executive communications.
  • Develop and maintain privacy governance frameworks, policies, standards and training programmes.
  • Advise on specialist privacy topics such as data retention, transfers, analytics and data usage.
  • Maintain Records of Processing Activities (ROPA), lawful basis governance and accountability evidence.
  • Oversee international data transfers, transfer risk assessments and localisation requirements.
  • Conduct privacy due diligence on third parties and ensure ongoing contract and processor compliance.
  • Manage relationships with regulators, supervisory authorities, employees and customers on privacy matters.
  • Lead data subject rights processes, including access requests and information disclosures.
  • Manage privacy audits, compliance reviews and remediation activities.
  • Draft and advise on privacy and security provisions within contracts and commercial agreements.
  • Maintain Data Protection Impact Assessment (DPIA) frameworks and advise on privacy risk mitigations.
  • Provide guidance on consent, marketing compliance and new technology initiatives.
  • Develop and oversee AI governance frameworks to ensure responsible and compliant AI usage.
  • Define, implement and continuously improve the organisation’s global compliance framework and policies.
  • Lead ethics and compliance programmes covering areas such as anti-bribery, anti-money laundering, sanctions, whistleblowing, conflicts of interest and regulatory engagement.

We believe being together in person helps us move faster, connect more deeply, and achieve more as a team. That's why our approach to working together includes spending at least 3 days a week in the office. It's a rhythm that speeds up decision-making, helps ASOSers learn from each other more quickly, and builds the kind of culture where people can grow, create, and succeed.

Qualifications

About You

  • Significant experience leading privacy and data protection programmes within a complex, global organisation.
  • Deep expertise in privacy legislation and regulatory requirements, with experience acting as a privacy subject matter expert.
  • A proven ability to translate complex legal and technical concepts into practical, commercial advice.
  • Strong leadership, influencing and stakeholder management skills, with experience working across multiple business functions.
  • Experience engaging with regulators and leading responses to investigations, enquiries and remediation programmes.
  • Knowledge of digital privacy, customer data, cookies, tracking technologies and data-driven business models.
  • Experience building governance, risk management and compliance frameworks.
  • Comfortable operating in a fast-paced, evolving environment with competing priorities.
  • Data Privacy certification (such as IAPP or equivalent) would be beneficial.
  • Experience within e-commerce, retail, technology or a listed business would be advantageous.
  • Someone who is excited by the opportunity to build, influence and make a meaningful impact.

Additional Information

BeneFITS'

  • Employee discount (hello ASOS discount!)
  • Employee sample sales
  • 25 days paid annual leave + an extra celebration day for a special moment
  • Performance-related bonus
  • Private medical care scheme
  • Opportunity for personalised learning and development experiences that help you thrive and grow in your career

Why take our word for it? Search #InsideASOS on our socials to see what life at ASOS is like.

 

Listing read directly from ASOS plc's applicant tracking system. Check frequency varies by source. Listings are removed after successful checks confirm they are no longer present.