As a Data Protection Audit Specialist, you will play a key role in strengthening our global privacy and compliance posture across GEDU and its entities that process personal data under the UK GDPR and EU GDPR.
In this role, you will lead and support internal data protection audits, partner closely with IT, Cybersecurity, Legal, and operational teams, and help build a privacy environment that is transparent, secure, and audit-ready. Your work will directly contribute to identifying risks, closing compliance gaps, and ensuring our global operations meet regulatory expectations with confidence.
Key Responsibilities Compliance Monitoring
- Monitor and support GDPR compliance efforts across all global entities.
- Help maintain the global data protection governance framework.
- Review departmental processes to ensure personal data is processed lawfully, fairly, and transparently.
Internal Data Protection Audits
- Plan and conduct GDPR compliance audits across business units, systems, and regions.
- Develop and maintain structured audit programs, checklists, and evidence frameworks.
- Assess compliance with key GDPR principles, including:
- Lawfulness and lawful basis
- Purpose limitation and data minimisation
- Retention and secure deletion
- Data subject rights and response processes
- Produce explicit, actionable audit reports focusing on:
- Identified gaps
- Associated risk levels
- Remediation recommendations
- Track mitigation and corrective actions with stakeholders through closure.
Collaboration with IT Cybersecurity
- Work closely with IT and Cybersecurity teams to assess technical and organisational measures required under GDPR (Article 32).
- Review controls related to:
- Access management
- Encryption and key management
- System logging, monitoring, and backup practices
- Security of cloud platforms and SaaS applications