Apply Edge Start your job search

Data Protection Specialist

Spencer Recruitment · Sandyford, Dún Laoghaire-Rathdown, Ireland

Apply & track with Apply Edge
Data Protection, Governance & Compliance SpecialistDublin | Full-time | HybridSpencer Recruitment is partnering with a leading national organisation to recruit a Data Protection, Governance & Compliance Specialist.This is a senior specialist position responsible for leading our partner’s data protection programme, strengthening its data governance framework and ensuring compliance with GDPR, the Data Protection Act 2018 and wider regulatory requirements.Reporting to the Head of Risk, Governance & Digital Transformation, the successful candidate will act as the organisation’s statutory Data Protection Officer. They will provide expert advice across the organisation and champion privacy, information governance and responsible data management.Key responsibilitiesData protection and GDPR complianceAct as the organisation’s statutory Data Protection Officer.Monitor compliance with GDPR and the Data Protection Act 2018.Conduct compliance audits, risk assessments and policy reviews.Maintain data protection policies, procedures and guidance.Deliver data protection training and awareness programmes.Provide expert advice to colleagues, senior management and governance committees.Data incidents and individual rightsLead the response to data incidents and personal data breaches.Investigate incidents, assess risk and maintain appropriate documentation.Manage regulatory notifications to the Data Protection Commission where required.Oversee Subject Access Requests and other Data Subject Requests.Act as the principal contact for internal and external data protection queries.Advisory and regulatory governancePrepare and present reports to the Audit & Risk Committee.Lead and review Data Protection Impact Assessments.Conduct Privacy by Design reviews for new systems, projects and processes.Review contracts, procurement processes and data-sharing agreements for GDPR compliance.Act as the designated point of contact for the Data Protection Commission.Maintain Records of Processing Activities and other audit-ready documentation.Data governance and information managementLead the continued development of the organisation’s data governance framework.Establish governance structures, responsibilities and standards for data management.Promote responsible data use, quality and stewardship.Oversee the full data lifecycle, including collection, storage, use, sharing, retention and deletion.Develop and implement data retention and disposal schedules.Support data classification, metadata standards, data mapping and quality controls.Maintain information-management policies and procedures.Work with IT and security colleagues to ensure information is handled securely and consistently.Supplier, compliance and risk managementConduct assessments of suppliers and third-party data processors.Review vendors’ technical and organisational data-protection measures.Support supplier assurance, procurement governance and third-party risk management.Contribute to enterprise risk management and the mitigation of data-related risks.Support internal and external audits, including evidence gathering and corrective actions.Provide compliance reporting to senior management and governance committees.Experience and qualificationsCandidates should have:A relevant third-level qualification in law, business, public administration, risk management, information systems or a related discipline.Strong knowledge of GDPR, the Data Protection Act 2018 and data governance principles.Experience in data protection, regulatory compliance, information governance or risk management.Demonstrable experience managing data incidents, DPIAs and regulatory engagement.Experience in supplier risk management or procurement governance.Strong analytical, organisational and problem-solving capabilities.Excellent communication skills and the ability to work collaboratively across different teams.The professional judgement, independence and discretion required of a Data Protection Officer.Experience within the public sector, a regulated environment or an organisation with a complex data ecosystem would be particularly relevant.Professional certifications such as CIPP/E, CIPM, CDMP or an equivalent data protection or governance qualification are desirable.Application processApplicants should submit:A comprehensive CV.A short application letter of no more than two pages outlining relevant achievements, experience and motivation for the position.Closing date: 5:00 p.m. on Monday, 10 August 2026.