How to Become a UK Data Protection Officer
At this year’s ICO Data Protection Practitioner Annual Conference, the “Life of a DPO” panel received many questions about how to break into DPO roles. I have addressed some of them here based on my own experience.
@laughayette on Unsplash
There is a running joke in my family – my parents are doctors and other relatives are qualified accountants, lawyers – that if your job title after university cannot be named with certainty, the degree you’re doing isn’t the “right” one.
It was a surprise and a bit of a shock to them when I graduated with an LLB and announced I wasn’t going to pursue a solicitor qualification in the UK. They were supportive but I knew there was genuine concern “what I was going to do with this law degree if I wasn’t practising law”.
For a very long time I had to manage people’s expectations that while I enjoyed the academia of law, practising it in the UK was not the same. It was hard because I had moments when I wasn’t sure I’d done the right thing, so it felt like I was convincing both me and them I’d be fine.
I worked in financial risk recruitment, content production, and at a law firm specialising in intellectual property and commercial before I finally entered the data protection world.
Almost a decade later, I am happy to say everything worked out because I followed my interest even though it wasn't linear. You can read about my career.
I had tangent roles but information law and data kept attracting me. The roles that were “irrelevant” taught me many transferable skills for the DPO role. I have not looked back.
So, without further ado, here are some FAQs I wish I had – or saw pop up in the chat during the ICO conference.
How Do I Become a DPO?
You need to start asking why someone needs personal data and why that particular type is needed.
You should be curious about their reasons, challenge them occasionally and question why they can’t do without this data to achieve their goals. Keep going until you satisfy the requirements of data protection law.
People get in this zone from various paths of life. They come from security, legal, general compliance or fall into it because life happens.
Many DPOs I know (myself included) have started as “doers” from entry roles such as as DPO assistants. They read and dealt with data requests, wrote policies and procedures, and maintained registers.
When you have your first moral dilemma, make a hard decision or enter a grey zone of the legislation in practice, you’re ready to step up.
What Qualifications Do I Need to Become a DPO in the UK?
In the UK, no specific qualification is prescribed by law. Any degree is acceptable.
Article 37 of the UK GDPR says the DPO is expected to have the right level of qualifications for the data processing taking place at the organisation they advise. In practice, the hiring team often decides what this is.
This means they may ask for a disproportionate amount/level of experience for the role if they don’t understand it, or just want someone – with some knowledge – to be a DPO so they can say they have satisfied the requirement.
This is both good and bad news. On the one hand, you’re free to study whatever you like and work in whatever job you fancy as long as you can prove you understand the law and can apply it when the time comes.
On the other hand, some people feel they have to keep spending on courses, certifications and degrees to show they are qualified. That’s fine for people who enjoy learning and can pay for it, but it puts pressure on others who cannot afford continued paid training.
You can consider:
Data Protection and Information Governance Practitioner apprenticeship
Study and practise what you're learning. I've had the privilege of assessing apprentices and hearing what they have done in various roles, industries and from all walks of life. It’s something you can do with no previous experience or as an experienced professional who wants a career change/enhancement.
IAPP qualifications
They are more international/Europe-oriented, but widely recognisable and looked for as a keyword in applications. You can read about my experience passing the CIPM.
Data Protection Practitioner Certificate with PDP / The British Computer Society
These are targeted at UK law and UK professionals, both reputable and CV-enhancing in my opinion. I did the PDP certification some years ago and you are required to do a few compulsory modules and pick some more electives.
Certifications complement and do not replace experience.
Do I Need to be Legally Qualified to be a DPO?
Firstly, you don’t need a law degree to be a DPO, but if you have one, it helps.
Of course I’m biased as a law graduate. Looking at this objectively, however, as a DPO, you will spend a lot of time reading laws and need to be comfortable with citing sections, research and applying them in practice. You don’t need to have a law degree to do this but if you do, you are already prepared and it feels like home.
Secondly, you don’t need to be legally qualified, i.e. be a solicitor or a barrister; but you can be, if that’s where life has taken you first. If you are, I’d still recommend doing some qualification in data protection because data / information law is not a required module in mainstream law qualifications. You can also gain practical experience if you choose to work in a firm specialising in data and technology.
What Do Recruiters Look for in a CV for DPO Jobs?
I’m putting my recruiter hat on. As a start, I would define my pool of candidates with some keywords (including qualifications) and number of years of experience.
If someone doesn’t have a qualification, I’d be asking about their experience and roles to gauge whether they have necessary knowledge for the position I am recruiting for. This is often the case for experienced professionals who haven’t done much academically but are seasoned DPOs.
I’d also look for these skills:
Stakeholders management
Clear communication
Negotiation and persuasion
Organisation and prioritisation
Knowing when you don’t know and asking for help.
Extra points would receive a candidate who can give examples of:
When they fixed, improved or researched something on their own accord;
Spotted an error and convinced a senior of the benefit or need to fix it;
Made a hard decision that was correct and can explain the logic;
What they do when their advice isn’t followed.
How Do I Build my DPO Network?
Get out there. This may mean becoming more active on LinkedIn to build out your network or physically going to events (to meet your LinkedIn connections) and making new connections.
I’ve been on LinkedIn for many years but only started posting about 3-4 years ago. I found it intimidating. I started with about 200 connections, changed my profile to “content creator” so my posts got more visible and allowed people to follow me even if we weren’t connected.
As of today, I have almost 1,570 followers and engagement levels I never thought I’d have. All I did was to acknowledge the unease at first and take it slow.
Consider these events / membership groups:
The Information Records and Management Society
Privacy Space
NADPO Annual Conference
JISC data protection emailing list
When you start looking, you will find your tribe. During the ICO conference, someone in the comments said they struggled with the more popular groups because it was the same voices of prominent commentators that took over. This may be true, but if you don’t speak up, no-one will hear you even in the smaller communities.
Good luck!