Skip to main content
Byoma logo

Privacy & Data Governance Manager

Byoma
11 hours ago
Full-time
On-site
Glasgow, Scotland, United Kingdom

 

Hi, we’re BYOMA 

We’re one of the world’s fastest growing beauty brands. We have applied the research, science, and credibility of dermatologist-backed brands and supercharged it with the efficiency and results of clinically effective, ingredient-led brands.

We’re on a mission to democratize and demystify beauty by empowering consumers to make smart, informed and educated choices. 

BYOMA was built on four fundamental principles; Efficacy, Accessibility, Education, Engagement, and these inform, inspire and underpin everything we do. We’re committed to delivering the most efficacious products to our consumer and our dedication to accessibility and education have led to us becoming the #1 fastest growing skincare brand in the world, and a top 10 skincare brand across all our key retail partners.

As a people powered business, none of this would have been possible without our incredible team who are committed to achieving our BYOMA vision: to build better beauty and inspire positive change.

Join us as we build an inclusive community, because let’s face it, barriers aren’t beneficial for anything other than your skin.


 

Job Title 

Privacy & Data Governance Manager 

Department 

IT, Data & Business Intelligence

Reporting Manager 

Head of Data & BI / Data Protection Officer 

Role Banding 

3

Location 

Glasgow, UK Head Office

Direct Reports (Number + Title) 

0

 

BYOMA is growing quickly across multiple markets, systems and customer touchpoints. That makes privacy and data governance more than a compliance requirement. It is part of how we protect customer trust, make better decisions and scale responsibly. 

BYOMA’s data function is young and growing. Although small, we deliver enterprise grade capability and transformation and were recently nominated for Data Team of the Year at the British Data Awards. As we scale, we need a hands-on Privacy & Data Governance Manager to take operational ownership of our privacy programme and help build the governance framework around our growing data estate. 

This is a delivery role, not a purely advisory one. You will own the day-to-day running of our privacy compliance, including our Record of Processing Activities, data subject and consumer rights requests, privacy notices, DPIAs, vendor due diligence and core privacy documentation. Alongside this, you will help define and maintain the governance standards that shape how BYOMA classifies, retains, accesses and controls data across the business. The role works closely with the Head of Data & BI, who is also BYOMA’s Data Protection Officer. The DPO sets direction and retains statutory responsibility. You make the programme run. Privacy and data governance are closely connected at BYOMA. A good ROPA, clear data maps and a useful data catalogue all depend on understanding what data we hold, where it moves, who has access to it, how long we keep it and why. This role brings those activities together, so our documentation, controls and ways of working stay current as the business grows. 

 

RECORDS, DATA MAPPING AND PRIVACY DOCUMENTATION

  • Own and maintain BYOMA’s Record of Processing Activities, ensuring it reflects how the business uses personal data. 
  • Maintain associated registers, including the sub-processor register and data protection documentation. 
  • Map personal data flows across business areas, systems, vendors and jurisdictions. 
  • Document what data we hold, where it is processed, who it is shared with, the lawful basis for processing and any international transfer considerations. 
  • Keep documentation to the standard expected under UK GDPR Article 30 and equivalent consumer privacy disclosure expectations in relevant US markets. 
  • Work with business teams so privacy documentation is updated as systems, vendors, processes and marketing activities change.

 

DATA GOVERNANCE

  • Own and maintain BYOMA’s data classification approach, ensuring the sensitivity of key data assets is documented and understood. 
  • Develop and maintain retention schedules, working with system owners to ensure they are practical and applied. 
  • Coordinate periodic access reviews across key platforms so permissions reflect current business roles and responsibilities. 
  • Work with the DPO to define governance standards for classification, retention, access control, data ownership and documentation, and own them day to day once agreed. 
  • Support the development of Microsoft Purview, or equivalent tooling, as the backbone for classification, retention, eDiscovery, DLP and data governance. 
  • Coordinate a lightweight data governance forum so decisions about data are made deliberately and consistently. 
  • Work closely with data engineering so governance requirements are understood and built into how the data platform operates. 

 

USER RIGHTS AND CONSUMER REQUESTS

  • Own the end-to-end handling of data subject access requests and consumer rights requests. 
  • Manage requests relating to access, deletion, correction, restriction, objection and relevant US consumer rights. 
  • Ensure requests are handled within statutory timeframes and in line with BYOMA’s documented processes. 
  • Verify requester identity and manage authorised agent requests appropriately. 
  • Build and refine repeatable processes so request handling remains consistent as volumes grow. 
  • Keep records of requests, decisions and outcomes. 

 

POLICIES, NOTICES AND ASSESSMENTS

  • Maintain and update BYOMA’s privacy policies, notices and disclosures across the UK, EU and US, keeping them accurate as law and practice evolve. 
  • Keep cookie notices, consent records and marketing consent documentation aligned with how the business operates. 
  • Conduct DPIAs and legitimate interests assessments for new systems, tools, products, campaigns and processing activities. 
  • Translate privacy requirements into practical business actions. 
  • Work with the DPO and external advisers where specialist legal advice is required. 

 

VENDORS, CONTRACTS AND THIRD PARTIES

  • Conduct privacy and data protection due diligence on vendors and processors. 
  • Review data processing agreements and support contract review from a privacy and governance perspective. 
  • Maintain oversight of processors and sub-processors. 
  • Work with legal, procurement and business owners to ensure vendor processing is documented, risk-assessed and appropriately controlled. 
  • Support international transfer assessments where relevant. 

 

US PRIVACY DEVELOPMENTS

  • Track US state privacy developments that may affect BYOMA, including CCPA/CPRA and other relevant consumer privacy laws. 
  • Coordinate with the DPO and external advisers to understand the practical implications for BYOMA. 
  • Translate US privacy requirements into practical process updates, notices and disclosures, working with the DPO and external advisers where needed. 
  • Support a risk-based approach to reducing privacy, regulatory and customer trust risks. 

 

TRAINING, AWARENESS AND BUSINESS PARTNERSHIP

  • Work with teams across marketing, e-commerce, customer service, sales, operations, IT and data to embed privacy and good data practice into day-to-day work. 
  • Design and deliver practical privacy and data-handling training. 
  • Help colleagues understand when to involve privacy, how to handle personal data and how to escalate issues. 
  • Promote a culture where personal data and business data are managed responsibly. 

 

RISK, INCIDENTS AND REGULATORY CHANGE

  • Support breach and incident response, including logging, initial assessment, evidence gathering and escalation to the DPO. 
  • Assist the DPO with notification assessments and documentation. 
  • Monitor relevant developments in UK, EU and US privacy law. 
  • Flag changes that could affect BYOMA’s processes, policies, vendors or customer-facing disclosures. 
  • Support audit readiness and ongoing improvement of BYOMA’s privacy and governance controls. 

 

What were looking for:

Essential 

  • Three or more years’ experience in a privacy, data protection, information governance or compliance role. 
  • Strong working knowledge of UK GDPR, EU GDPR and PECR. 
  • Practical experience handling DSARs or equivalent rights requests end to end. 
  • Experience maintaining a ROPA, data inventory, processing register or equivalent documentation. 
  • Experience documenting how data moves through a business — systems, vendors, teams and purposes — rather than working from documentation someone else produced. 
  • Ability to turn legal, technical or policy requirements into practical business processes. 
  • Comfortable working with vendors, reviewing DPAs and coordinating privacy input into supplier assessments. 

 

Desirable 

  • Experience with US privacy law, particularly CCPA/CPRA. 
  • Awareness of other US state consumer privacy laws or biometric privacy requirements. 
  • CIPP/E, CIPM or CIPP/US certification, or actively working towards one. 
  • Practical data governance experience — cataloguing, classification, retention scheduling, access reviews or governance forums. 
  • Experience working in a Microsoft 365 environment, including SharePoint and Teams. 
  • Experience with Microsoft Purview for classification, retention, eDiscovery, DLP or data governance. 
  • Experience in e-commerce, retail, FMCG, beauty, consumer goods or a consumer brand. 
  • Familiarity with analytics and marketing technology — GA4, consent management platforms, advertising pixels or CRM. 
  • Data analysis knowledge, or confidence working alongside data engineers and technical teams. 
  • Experience delivering training or awareness programmes. 
  • Exposure to a multi-entity or international group structure. 

 


Equal opportunities for everyone 

BYOMA is an equal opportunity employer. We value a culture of inclusion and diversity within our team. We are committed to maintaining a workplace free from prohibited employment conduct, including discrimination based on age, color, disability, marital or parental status, national origin, race, religion, sex, sexual orientation, gender identity, veteran status or any other legally protected status in accordance with applicable federal, state and local laws.

If you have a preferred name, please use it to apply. We don't need full or birth names at application stage.