# Privacy Programme Specialist

> ABM UK · Hounslow, United Kingdom · Full-time · Posted 2026-10-06

**Workplace:** on_site

**Department:** All Roles - Susan Mason-Thomas

## Description

REPORTING TO: VP, Technology UK&I and dotted line reporting to Head of Products, Partnerships & Innovation 

LOCATION: Heathrow

SHIFT PATTERN: 45 hours per week. Monday to Friday (Part-time: 3 days per week OR condensed working hours across 5 days.)

SALARY: Competitive

_If you require any additional support or adjustments during the recruitment process, please don't hesitate to contact our Recruitment Department at recruitment@abm.com. We're here to help!_

ROLE OVERVIEW AND PURPOSE 

ABM UK & Ireland is committed to maintaining high standards of data protection and privacy across its business. We are seeking an experienced Data Privacy Specialist to manage and continuously improve the UK & Ireland data privacy programme, ensuring that proportionate and effective controls are embedded across the organisation. 

The role will support compliance with the UK GDPR and, for the Republic of Ireland, the EU GDPR, together with relevant internal policies and procedures. The Data Privacy Specialist will provide practical guidance to business stakeholders, maintain core privacy governance records, coordinate individual rights requests, oversee the management of data incidents, and ensure appropriate privacy training is delivered. 

A key priority will be to align data privacy processes, controls, policies and working practices across acquired companies in Ireland, creating a consistent and efficient UK & Ireland approach while recognising applicable local requirements. This is a part-time role, offered either as three working days per week or through condensed working hours across five days. 

KEY RESPONSIBILITIES 

Privacy Programme Governance 

-   Manage the day-to-day UK & Ireland data privacy programme, ensuring activities are planned, tracked and completed in line with applicable data protection requirements and internal governance expectations 

-   Maintain an effective privacy governance framework, including clear ownership, records, controls, actions and reporting 

-   Provide regular updates on privacy activity, risks, incidents, requests and improvement priorities to relevant stakeholders 

Records of Processing Activities (RoPAs) 

-   Own and coordinate the ongoing maintenance of Records of Processing Activities (RoPAs), ensuring they are accurate, complete and kept up to date across the UK & Ireland business 

-   Work with business owners to validate processing purposes, categories of personal data, data subjects, recipients, retention periods, international transfers and security measures 

-   Identify gaps or inconsistencies in RoPAs and drive timely remediation with accountable business stakeholders 

Data Protection Impact Assessments (DPIAs) 

-   Review and support Data Protection Impact Assessments (DPIAs) for new or changed systems, processes, suppliers and business initiatives involving personal data 

-   Provide practical challenge and guidance to ensure privacy risks are identified, assessed and appropriately mitigated before implementation 

-   Maintain an auditable record of DPIAs, actions, decisions and approvals 

Data Subject Access Requests (DSARs) & Individual Rights 

-   Coordinate Data Subject Access Requests (DSARs) and other applicable individual rights requests in partnership with HR Business Partners and relevant business teams 

-   Ensure requests are logged, progressed, quality checked and completed within required timescales 

-   Provide guidance to stakeholders on evidence gathering, redaction, exemptions and appropriate response handling, escalating complex matters where required 

Data Incidents & Breach Management 

-   Record, assess and manage personal data incidents and suspected breaches from initial notification through investigation, containment, remediation and closure 

-   Coordinate input from relevant stakeholders to establish facts, assess risk to individuals and maintain complete incident records 

-   Ensure actions and lessons learned are captured and followed through, and escalate incidents promptly where regulatory assessment or senior review is required 

Training & Awareness 

-   Arrange and coordinate annual HR data privacy training and any additional privacy training deemed necessary for specific teams, roles or business risks 

-   Maintain training records and support targeted awareness activity to reinforce privacy responsibilities and good data handling practices 

-   Review training content periodically to ensure it remains relevant, practical and aligned to the UK & Ireland privacy programme 

Policy, Procedure & Acquired Company Alignment 

-   Review and update all policies, procedures, guidance and supporting documentation relating to GDPR and data privacy compliance 

-   Drive alignment of privacy processes and controls across acquired companies in Ireland, working with local stakeholders to establish consistent ways of working 

-   Identify legacy practices, documentation or controls that require harmonisation and manage actions through to completion 

-   Ensure privacy requirements are embedded into relevant business processes and change activity across the UK & Ireland organisation 

Advisory & Continuous Improvement 

-   Act as a trusted subject matter specialist, providing practical advice on data protection requirements, privacy risks and best practice 

-   Build strong working relationships across HR, Technology, Legal, Operations, Procurement and other relevant functions 

-   Continuously seek better, simpler and more efficient ways to manage the privacy programme while maintaining appropriate governance and control 

-   Monitor recurring issues and trends, using insight to recommend improvements to processes, controls, training and business practice

## Requirements

-   Minimum 5+ years of substantive experience in data privacy, data protection or a closely related compliance role, with hands-on responsibility for GDPR programme activities 

-   Strong working knowledge of the UK GDPR and EU GDPR, with the ability to apply regulatory requirements pragmatically in a commercial environment 

-   Demonstrable experience maintaining RoPAs and reviewing DPIAs 

-   Practical experience coordinating DSARs and other data subject rights requests, including working with HR and business stakeholders 

-   Experience managing personal data incidents and maintaining clear, auditable incident records 

-   Experience developing, coordinating or delivering data privacy training and awareness activities 

-   Experience reviewing and maintaining privacy policies, procedures and governance documentation 

-   Proven ability to work across multiple legal entities, business units or acquired organisations and to standardise processes while managing local requirements 

-   Excellent organisational skills, with the ability to prioritise multiple activities, maintain accurate records and meet regulatory deadlines 

-   Effective written and verbal communication skills, with the confidence to explain data privacy requirements clearly to stakeholders at different levels of the organisation 

-   Strong analytical and problem-solving capability, with sound judgement and attention to detail 

-   Ability to work independently, take ownership of the programme and escalate material risks appropriately 

QUALIFICATIONS & PROFESSIONAL CERTIFICATIONS 

-   Recognised professional qualification in data privacy or data protection is required, such as CIPP/E, BCS Practitioner Certificate in Data Protection, or an equivalent relevant qualification 

-   Additional privacy, information governance, risk, compliance or information security qualifications are advantageous 

-   Ongoing evidence of continuing professional development in data protection and privacy is desirable 

KEY COMPETENCIES & DESIRABLE EXPERIENCE 

-   Highly organised, methodical and able to maintain accurate governance records 

-   Clear and credible communicator with strong stakeholder engagement skills 

-   Pragmatic and solutions-focused approach to interpreting data protection requirements 

-   High level of integrity, discretion and sound judgement when handling sensitive and confidential information 

-   Ability to influence stakeholders and drive actions to completion without relying on direct authority 

-   Strong attention to detail combined with the ability to identify themes, risks and improvement opportunities 

-   Comfortable operating independently in a part-time role while maintaining clear priorities and dependable follow-through 

-   Experience of post-acquisition integration or harmonisation of privacy processes across multiple entities is highly desirable 

-   Experience within a large, operational, services-based or matrixed organisation is advantageous

## Benefits

We’re proud to offer a great range of benefits including:

-   24/7 GP: Both you and your immediate family can speak to a UK-based GP from the comfort of your own home
-   Mental Health support and Life Event Counseling
-   Get Fit Programme
-   Financial and legal support
-   Cycle to work scheme
-   Access Perks at Work, our innovative employee app where you can find:

-   Perks: discounts, gift cards, cashback, and exclusive offers
-   Life: Search for resources and tools on topics ranging from family and life to health, money and work
-   Support: Online chat or telephone service for urgent support in a crisis

For more information about ABM’s benefits, visit our 

**About ABM:**

ABM (NYSE: ABM) is one of the world’s largest providers of integrated facility, engineering, and infrastructure solutions. Every day, over 100,000 team members deliver essential services that make spaces cleaner, safer, and efficient, enhancing the overall occupant experience.

ABM serves a wide range of market sectors including commercial real estate, aviation, mission critical, and manufacturing and distribution. With over $8 billion in annual revenue and a blue-chip client base, ABM delivers innovative technologies and sustainable solutions that enhance facilities and empower clients to achieve their goals. Committed to creating smarter, more connected spaces, ABM is investing in the future to meet evolving challenges and build a healthier, thriving world. ABM: Driving possibility, together.

For more information, visit .

ABM are committed to employment practices that promote diversity and inclusion in employment regardless of age, disability, gender reassignment, sex, marriage and civil partnership status, pregnancy and maternity status, race, religion or belief. We are proud members of the Armed Forces Covenant Employer Recognition Scheme.

## Apply

[Apply at ABM UK](https://apply.workable.com/abm-careers/j/BFF93BBE48/apply)

---
Powered by [Workable](https://www.workable.com)
