Data Protection Manager
We are proud to be One Team at East Midlands Railway (EMR). We are passionate about keeping people safe, delighting our customers, doing the right thing and putting customers at the heart of our sustainable railway for the East Midlands. With over 2,600 employees, our people are the reason we are so successful, and our employees make a crucial contribution to this.
Ten times accredited as a Top Employer and Gold accredited for Inclusive Employers Standards, we value our people and are dedicated to making sure that everybody feels empowered to bring their authentic self to work.
At EMR we want to proactively embrace diversity across our workforce and recognise that we are under-represented in some areas. We’re therefore taking positive steps to promote a positive and inclusive culture and we welcome applications from everyone to help us better represent our communities.
We have an exciting opportunity to join #TeamEMR as a Data Protection Manager.
This pivotal role leads and manages EMR’s privacy framework to ensure full compliance with the UK GDPR, the Data Protection Act 2018, and related legislation. Providing expert, pragmatic advice and, embedding privacy by design across all business processes, and promote a strong internal culture of accountability and compliance.
Key Roles and Responsibilities
Data Protection Strategy & Governance - Own the organisation's data protection and privacy framework, ensuring compliance with UK GDPR, the Data Protection Act 2018, PECR and related legislation, and that policies, procedures and standards remain current and effective.
Advisory & Decision Support - Act as the organisation's principal source of data protection expertise, advising senior leadership and project teams on complex privacy matters, challenging proposals where risks or non-compliance arise, and embedding privacy by design across change initiatives and DPIAs.
Individual Rights & Breach Management - Own the end-to-end handling of data subject rights requests and personal data breaches, ensuring both are managed lawfully, efficiently and within statutory timescales, with regulatory notification where required.
Information Governance & Third-Party Assurance - Maintain oversight of the organisation's records of processing activities, and ensure data protection provisions are properly reflected in contracts, data processing and data sharing agreements with suppliers and partners.
Assurance, Risk & Retention - Provide ongoing assurance that data protection risks are identified, assessed and mitigated, that compliance actions are implemented, and that a robust retention and disposal framework keeps personal data held only as long as necessary and disposed of securely.
Culture, Capability & Awareness - Build organisational capability and awareness through training and campaigns, ensuring managers and stakeholders understand their responsibilities and a culture of privacy and accountability is embedded.
Regulatory Horizon Scanning - Monitor developments in data protection law, regulatory guidance and best practice, translating these into practical recommendations for the organisation.
Reporting & Governance Assurance - Produce accurate, timely reporting and management information for senior leadership, governance committees and the Board, providing assurance on compliance performance and the effectiveness of the data protection framework.
Stakeholder & Group Relationships - Build effective relationships with internal stakeholders, regulators and the Group Data Protection Officer, ensuring alignment with group-wide privacy strategy and consistent application of standards, and acting as or supporting the DPO role where required.
The above list is not exhaustive, and on occasion, the role may need to undertake other reasonable requests as required by their line manager, in line with grade and competence
All staff have a responsibility and accountability to ensure that their day-to-day activities support our commitments under the Sustainability Policy Statement and relevant management systems (e.g. ISO14001 or ISO50001); and to act in a sustainable manner and minimise impact on the environment.
About You
We’re looking for a confident and capable individual who brings:
- Certified Information Privacy Professional/Europe (CIPP/E) or a BCS Practitioner certificate
- Knowledge of UK GDPR, Data Protection Act 2018, PECR, ICO guidance, and information security principles. Desirable certification in Data Protection
- Understanding of privacy by design, information lifecycle management, data sharing, and supplier governance.
- Experience managing DPIAs, Data Subject Rights Requests, personal data breaches, and privacy risk assessments.
- Experience reviewing commercial contracts, Data Processing Agreements (DPAs), and Data Sharing Agreements.
- Experience producing Board-level reports and performance metrics to provide compliance assurance to senior leadership.
- Ability to interpret complex legislation and translate it into strategic, risk-based, and proportionate business solutions.
- Excellent communication (written and verbal), negotiation, and influencing skills to challenge and advise confidently at all organisational levels and committees within a diverse workforce.
- Experience of leading a GDPR governance programme (continuous improvement against minimum standards)
As well as a competitive salary, we’ll also offer you:
- 32 days annual leave (including bank holidays), rising to 34 days after 2 years of service
- Free travel on East Midlands Railway and other train companies operated by Transport UK
- 75% discount on other national rail train companies, including for partners and dependants
- Discounted friends and family tickets on the EMR network
- Various personal development and progression opportunities
- Excellent pension scheme
This position is based in our Derby Head office, but we've adopted a flexible hybrid working model that creates the opportunity to work in your own way at home but also provides great spaces for in-person collaboration.
Informal enquires welcome: Stuart Dean, Information Security & Governance Senior Manager stuart.dean@eastmidlandsrailway.co.uk
We are open minded to applications from people who wish to have flexible working. Many of our staff work flexibly in many ways. Please talk to us at interview about the flexibility you need. We can’t promise to give you exactly what you want, but we do promise not to judge you for asking.
Ready to take on this exciting opportunity? Submit your online application form and upload your CV. As we operate a blind screening process, please remove all personal information including your name from your CV.
Important Notice to Candidate: AI Use Monitoring
Please be advised that all responses to questions on this application form will be carefully monitored for indications of AI assistance. It is important to us that you are being your authentic self so please base your answers on your personal knowledge and experience.
Any detected use of AI-generated content will result in disqualification from the application process. We value integrity and transparency in all applications and appreciate your cooperation in maintaining these standards.
Supporting Our Frontline
If you're successful in this role, you'll be expected to support our frontline colleagues at some points throughout the year. This might be undertaking safety critical work, for which you'll receive training, but it could just be helping out with Customer Service when our stations are busy. We're One Team, and that means our managers step up for the frontline, not just manage from a distance. Supporting frontline colleagues is part of our DNA at EMR.
We welcome applicants from diverse backgrounds, we promote equal opportunities for all. East Midlands Railway is a non-discriminatory employer committed to the recruitment and promotion of all on the basis of ability and merit irrespective of disability, race, gender, health, social class, sexual preference, marital status, nationality, religion, employment status or age. We’ll treat your application fairly and assess you for the job based on merit and skills.