
Head of Compliance and Data Privacy - 12 month FTC
Job Description
Company Description
We're ASOS, the online retailer for fashion lovers all around the world.
We exist to give our customers the confidence to be whoever they want to be, and that goes for our people too. At ASOS, you're free to be your true self without judgement, and channel your creativity into a platform used by millions.
Everyone needs some help showing up as their best self. We're Disability Confident Committed - let our Talent team know if you need any reasonable adjustments throughout the recruitment process.
Job Description
At ASOS, data and trust are fundamental to how we serve millions of customers around the world. As our Head of Compliance and Data Privacy, you'll lead our global privacy and compliance agenda, acting as ASOS's Data Protection Officer (DPO) and trusted advisor to senior leaders across the business. This is a high-profile leadership role with responsibility for ensuring our approach to privacy, data protection and compliance is commercially focused, practical and fit for a fast-moving global retailer.
You'll partner with teams across Technology, Data, Marketing, Supply Chain, Procurement, People and Commercial functions, helping them navigate complex regulatory requirements while enabling innovation and growth. Alongside leading our Privacy team, you'll oversee the Compliance function, shaping frameworks, governance and policies that support ASOS's continued success.
The Details
- Act as the independent Data Protection Officer (DPO) for UK and EU operations, ensuring global privacy compliance.
- Provide expert guidance on current and emerging privacy legislation and regulatory changes.
- Advise the business on privacy implications of strategic and commercial initiatives.
- Support the management and mitigation of privacy risks across the organisation.
- Design and deliver privacy programmes that demonstrate compliance and enhance customer trust.
- Lead responses to data breaches and critical incidents, including stakeholder and executive communications.
- Develop and maintain privacy governance frameworks, policies, standards and training programmes.
- Advise on specialist privacy topics such as data retention, transfers, analytics and data usage.
- Maintain Records of Processing Activities (ROPA), lawful basis governance and accountability evidence.
- Oversee international data transfers, transfer risk assessments and localisation requirements.
- Conduct privacy due diligence on third parties and ensure ongoing contract and processor compliance.
- Manage relationships with regulators, supervisory authorities, employees and customers on privacy matters.
- Lead data subject rights processes, including access requests and information disclosures.
- Manage privacy audits, compliance reviews and remediation activities.
- Draft and advise on privacy and security provisions within contracts and commercial agreements.
- Maintain Data Protection Impact Assessment (DPIA) frameworks and advise on privacy risk mitigations.
- Provide guidance on consent, marketing compliance and new technology initiatives.
- Develop and oversee AI governance frameworks to ensure responsible and compliant AI usage.
- Define, implement and continuously improve the organisation’s global compliance framework and policies.
We believe being together in person helps us move faster, connect more deeply, and achieve more as a team. That's why our approach to working together includes spending at least 3 days a week in the office. It's a rhythm that speeds up decision-making, helps ASOSers learn from each other more quickly, and builds the kind of culture where people can grow, create, and succeed.
Qualifications
About You
- Significant experience leading privacy and data protection programmes within a complex, global organisation.
- Deep expertise in privacy legislation and regulatory requirements, with experience acting as a privacy subject matter expert.
- A proven ability to translate complex legal and technical concepts into practical, commercial advice.
- Strong leadership, influencing and stakeholder management skills, with experience working across multiple business functions.
- Experience engaging with regulators and leading responses to investigations, enquiries and remediation programmes.
- Knowledge of digital privacy, customer data, cookies, tracking technologies and data-driven business models.
- Experience building governance, risk management and compliance frameworks.
- Comfortable operating in a fast-paced, evolving environment with competing priorities.
- Data Privacy certification (such as IAPP or equivalent) would be beneficial.
- Experience within e-commerce, retail, technology or a listed business would be advantageous.
- Someone who is excited by the opportunity to build, influence and make a meaningful impact.
Additional Information
BeneFITS'
- Employee discount (hello ASOS discount!)
- Employee sample sales
- 25 days paid annual leave + an extra celebration day for a special moment
- Performance-related bonus
- Private medical care scheme
- Opportunity for personalised learning and development experiences that help you thrive and grow in your career
Why take our word for it? Search #InsideASOS on our socials to see what life at ASOS is like.
Other jobs you might like
Senior Data Privacy Manager
Copenhagen, DK | Denmark
Data Governance Lead
Handforth, UK
Compliance and Contracts Manager
Farnborough, UK
Working at ASOS

3 office days / week – may vary across teams (tech teams 3 days at home)

A little flex time
