Data protection officer jobs · DPO vacancies · Permanent first

Data protection officer jobs · permanent, interim and fractional

Data protection officer jobs are roles in which one person advises an organisation on data protection law, monitors its compliance and acts as its contact point with the ICO, reporting to the highest level of management. The board below lists the DPO roles on our board, permanent roles first where the posting says full-time.

We recruit permanent, interim, fractional and part-time privacy and compliance leaders. On every brief we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

3–5
Shortlist · with pay or day rate, availability and IR35 set out

15 minutes · video or phone

Book 15 minutes to hire a data protection officer

Tell us the scope and the days a week. We come back with data protection officer candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

On the board · last 3 months

Data protection officer jobs jobs on the board

0 Data protection officer jobs · 2 legal, privacy and compliance

No Data protection officer jobs roles on the board in the last three months. Showing legal, privacy and compliance roles instead.

Current data protection officer roles

Fractional recruitment works differently from a permanent search — shorter, scoped by days a week, and priced on the engagement. Send a data protection officer brief and we come back with a shortlist of three to five vetted candidates.

01/ the role

Data protection officer jobs: what the seat is and what the board lists

A data protection officer is a statutory role. Article 37 of the UK GDPR requires public authorities and bodies to designate one, as well as organisations whose core activities involve large-scale regular and systematic monitoring of people or large-scale processing of special category or criminal offence data. Many other organisations appoint one voluntarily. Either way, the ICO’s guidance says the DPO must be independent, an expert in data protection, adequately resourced, and report to the highest management level. For the role itself, see what a data protection officer does.

The board below lists data protection officer roles. Where a posting says full-time we list it as permanent and show those first; interim and fractional roles follow under their own labels. When there are few DPO roles, the board widens to legal, privacy and compliance roles and says so.

Because the law allows the DPO to be a member of staff or to work under a service contract, DPO jobs come in more shapes than most: employed roles in public bodies, health, financial services and technology; roles inside firms that sell an outsourced DPO service; and part-week fractional seats. The Article 38 protections travel with the seat in every case: no instructions on how to do the tasks, and no dismissal or penalty for doing them.

02/ scope

How to get a data protection officer job

1. Build expert knowledge of the law, and prove it

Article 37 asks for expert knowledge of data protection law and practices, in proportion to the processing. No single qualification is required, but employers look for one. The BCS Practitioner Certificate in Data Protection is written to the UK GDPR and the Data Protection Act 2018 and covers the designation, position and tasks of a DPO; the IAPP’s CIPP/E covers European and national data protection law, and its CIPM covers running a privacy programme. Keep current: the Data (Use and Access) Act 2025 has changed parts of the UK GDPR, and interviewers ask about it.

2. Get the casework

Most DPOs come from privacy, information governance, compliance, legal or information security roles. What shortlists you is evidence you have done the work: data protection impact assessments, records of processing, subject access requests, breach assessments and ICO correspondence. Name the scale and the sector, and have a referee who saw it.

3. Know the sector you are applying to

The ICO advises that a DPO’s knowledge should match the processing, and that knowledge of the industry is an advantage. A DPO for a hospital trust, a bank and an adtech business face different data, different regulators alongside the ICO and different risks. Pick a sector and learn its rules.

4. Show you can work independently

Employers test whether you will give unwelcome advice to senior people and record it when they decline it. Prepare an example where you did. Avoid applying for a combined role that would make you decide on the processing you are meant to monitor; the ICO treats that as a conflict of interests.

03/ comparison

Data protection officer vs CISO vs general counsel

Three seats that overlap on personal data. Read the scope, not the title.

Data protection officerCISOGeneral counsel
OwnsAdvice on and monitoring of data protection complianceInformation security controls, the security team and incident responseThe organisation’s legal risk: contracts, disputes, employment, regulation
Set by law?Yes: UK GDPR Articles 37–39NoNo
Reports toDirectly to the highest management levelUsually the CIO, CTO or CEOUsually the CEO
IndependenceCannot be instructed on how to do the tasksNormal line managementNormal line management

04/ vetting

How we vet data protection officers

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify data protection officer tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

05/ dpo jobs

DPO jobs and vacancies what the titles mean

DPO jobs and data protection officer vacancies are advertised under several titles: data protection officer, privacy officer, head of privacy, data protection manager and information governance lead. Only the person designated under Article 37 is the DPO; the ICO advises that other specialists in a privacy team should not be called the DPO. Read the job description for the word “designated”, or for the Article 39 tasks, before you assume the seat is the statutory one.

Many vacancies are with organisations that must appoint a DPO: public authorities, and businesses that monitor people at scale or process health, biometric or criminal offence data at scale. Others sit with firms that provide an outsourced DPO service to several clients, which the ICO confirms is allowed under a service contract.

For part-week roles, see fractional DPO jobs. The board on this page lists every engagement type.

06/ permanent dpo jobs

Permanent data protection officer jobs: what the seat pays

We do not quote a DPO salary here: we state pay figures only where we can verify them at source, and we have none we can verify today. Pay for a permanent data protection officer job depends on whether the appointment is mandatory, the scale and risk of the processing, the sector and its other regulators, whether the role leads a team, and the location. On every shortlist we set out each candidate’s pay or day rate.

Permanent DPO roles suit organisations with constant, high-risk processing, where the DPO needs to sit in project meetings every week. Employers hiring for one usually brief a recruiter; see data protection officer recruitment for how that search runs.

Interim and fractional DPOs who work through their own company may fall under the off-payroll working rules (IR35). Status depends on how the engagement runs, and a medium or large client makes the determination. Our IR35 guide sets out the tests.

07/ jobs by type

Data protection officer jobs by type

Fractional. A named DPO for an agreed number of days, often for a growing business or a group of companies sharing one DPO. See fractional DPO jobs, or hire a fractional DPO.

Permanent recruitment. How a permanent search for the seat runs, and what employers test for: data protection officer recruitment.

Interim. We have no separate interim DPO page; interim cover for the seat is briefed through interim executive recruitment.

Neighbouring seats. General counsel jobs for the wider legal seat, CISO jobs for information security, chief data officer jobs for data strategy, and part-time compliance officer roles for wider regulatory work.

08/ questions

Data protection officer jobs FAQ

The questions people ask before bringing in a data protection officer.

Roles in which one person advises an organisation on data protection law, monitors its compliance, advises on data protection impact assessments and acts as its contact with the ICO, reporting to the highest management level. The UK GDPR makes the appointment mandatory for some organisations.
Informs and advises the organisation and its staff, monitors compliance, advises on DPIAs, cooperates with the ICO and is a contact point for people whose data is held. See what a data protection officer does.
It depends on the sector, the scale and risk of the processing, whether the role leads a team, and the location. We only quote figures we can verify at source, and we hold none today; on every shortlist we set out each candidate’s pay or day rate.
Build expert knowledge of data protection law, usually proven with a qualification such as the BCS Practitioner Certificate in Data Protection or the IAPP’s CIPP/E; get casework on DPIAs, rights requests and breaches; learn the sector you want to work in; and show you can give independent advice to senior people.
Not always. Only the person designated under Article 37 is the DPO. A privacy manager may support the DPO or run the privacy programme without the statutory role. Check whether the job description names the designation or the Article 39 tasks.
Yes, where the employer’s posting says full-time; those are listed as permanent and shown first. Interim and fractional roles follow under their own labels, and when DPO roles are few the board widens to legal, privacy and compliance roles.
Yes. Article 37 lets a group of companies appoint a single DPO if the DPO is easily accessible from each establishment, and lets the DPO work under a service contract. That is what an outsourced or fractional DPO does. The ICO adds that the DPO must still be able to do the job across all of them.
Brief us on the processing, the reporting line and whether the role is permanent, interim or fractional. We send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after five-stage vetting. See data protection officer recruitment.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

For executives

Your next role, read against your repo.

Sign up now →Browse the board

  1. Build your repo once; every job on the board is read against it
  2. Fractional, interim, part-time, permanent and board roles
  3. Nothing goes on your repo until you confirm it
  4. A call when it suits you — five minutes, then it is written down for your yes
Fractional Quest logo — how to hire a data protection officer, data protection officer jobs