Interim Data Protection Officer
Key responsibilities and accountabilities:
- Monitor compliance with data protection laws and internal policies, including regular audits and reviews.
- Advise and inform staff on their obligations under data protection legislation and best practice procedures, including setting standards to ensure compliance.
- Develop, implement, maintain and deliver data protection policies, procedures, and training programmes.
- Serve as the primary point of contact for data protection queries from the business and for the Information Commissioner’s Office (ICO).
- Manage and respond to Data Subject Access Requests (DSARs), and support all other data subject rights (erasure, rectification, objection, restriction and portability) within statutory deadlines. Oversee the handling of personal data breaches, ensuring prompt reporting and appropriate remedial action.
- Work with key internal stakeholders in the review of projects and related data to ensure compliance with applicable laws.
- Undertake DPIAs (and work with the business to identify when DPIAs are required)
- Maintain records of processing activities and ensure documentation is up to date and accurate.
- Review and provide guidance on contracts and data sharing agreements to ensure compliance with data protection requirements.
- Keep abreast of developments in data protection law and advise management of any changes affecting the organisation.
- Participate in LLA’s Information Security Committee meetings, ensuring that data protection risks, DPIA outcomes, and compliance issues are considered in cybersecurity decision‑making, program planning, and incident reviews.
Collaborate with the Cybersecurity to:
- raise employee awareness of data privacy and security risks through training sessions, targeted communications, and ongoing awareness programs;
- Maintain comprehensive records of all data assets, data flows, record of processing activities, and data exports to support governance and audit readiness;
- Embed privacy by design and default into airport and IT projects, ensuring early consultation on system changes, and new or high‑risk data processing;
- Review and maintain the incident response plan from data protection perspective, ensuring timely detection, escalation, investigation, remediation and regulatory reporting;
- Support internal and external audits, including those from the ICO, CAA, DfT, NCSC, and independent assurance providers; and
- Support LLA to achieve ISO 27001 certification, helping to ensure information security and privacy controls are embedded and operationally effective.
- Working with LLA’s IT team to ensure that IT systems and procedures continue to comply with all relevant data protection laws and policy (including in relation to the retention and destruction of data).
- Working with LLA’s legal team to help advise on data protection law issues.
- Provide regular reports to the Audit and Risk Committee and the Information Security Committee on data protection compliance.
- Review and authorise the release of CCTV footage to external third parties.
- Review resourcing requirements for the DPO function, develop scope, structure and mandate and support the recruitment into the permanent DPO role to ensure it is in place for the end of the fixed term contract.
Our partners








Luton Adult Learning
Point, Luton Adult Learning, Floor 2 Arndale House, Luton LU1 2LJ