About this role
Vacancy Type
Permanent/Full Time
Job Summary
The Data Protection and Compliance Officer is responsible for the development, implementation, maintenance, and continual improvement of Maintel Integrated Management System (IMS), ensuring compliance with multiple international standards, regulatory requirements, customer obligations, data protection obligations, privacy governance requirements, and governance frameworks.
The role provides leadership across certification management, corporate governance, regulatory compliance and reporting, supplier assurance, environmental reporting, information security programmes*,*and data protection governance*.* The postholder will act as the primary coordinator for internal and external audits (excluding financial audit), certification bodies, regulatory submissions, supplier assurance portals, and data protection compliance activities*,*ensuring that risks are managed and compliance obligations are met.
The role is accountable for maintaining certification, compliance activities and reporting relating to multiple ISO standards, Cyber Essentials, Cyber Essentials Plus, PCI-DSS, NHS-DSP, NHS Evergreen Assessment, Ecovadis, UNGC, CDP, SECR, ESOS*,*UK GDPR, Data Protection Act 2018, PECR, privacy governance requirements, and customer assurance requirements and portals.
- Lead the management, maintenance, and continual improvement of the Integrated Management System.
- Ensure effective integration of business processes across all management system standards, certifications and customer supplier portals.
- Provide oversight of data protection governance as Data Protection Officer (DPO) ensuring privacy obligations and records are embedded across relevant business processes.
- Develop, review, and maintain policies, procedures, standards, forms, and registers.
Manage
- control processes and governance requirements.
- Coordinate management reviews and continual improvement activities.
- Produce compliance dashboards, KPI reports, and performance metrics for senior leadership.
- Lead Operational risk management and corporate risk review and reporting
- Management of team member focussed on Environmental aspects
ISO Certification Management
Maintain and support certification activities for
- ISO 9001 – Quality Management
- ISO 14001 – Environmental Management
- ISO 45001 – Health and Safety
- ISO 22301 – Business Continuity Management
- ISO 27001 – Information Security Management
- ISO 27701 – Privacy Information Management
- ISO 42001 – Artificial Intelligence Management Systems
Responsibilities include
- Internal audit planning and delivery.
- Certification audit coordination.
- Corrective action management.
- Risk and opportunity management.
- Objectives and performance monitoring.
- Management review preparation.
- Evidence gathering and audit readiness activities.
Governance & Compliance
- Maintain governance frameworks, compliance registers, legal registers, and regulatory obligations.
- Monitor relevant legislation, standards, and industry requirements.
- Support Board, Operating Board, and management governance reporting.
- Lead compliance improvement initiatives and governance projects.
- Manage risk registers and compliance controls.
- Provide subject matter expertise on regulatory and certification requirements.
Information Security & Cyber Compliance
- Coordinate annual Cyber Essentials and Cyber Essentials Plus assessments.
- Support PCI-DSS compliance activities and certification requirements.
- Coordinate annual NHS-DSP submission and external audit.
- Maintain security policies, standards, and awareness programmes.
- Assist with customer assurance requests and security questionnaires.
- Support security incident investigations and corrective actions.
- Monitor control effectiveness and governance requirements.
Data Protection, Privacy Governance & DPO
- Undertake Data Protection Officer (DPO) responsibilities in line with UK GDPR requirements, including acting independently and providing advice on data protection obligations.
- Monitor compliance with UK GDPR, Data Protection Act 2018, PECR, organisational privacy policies, and related data protection standards.
- Advise on and monitor Data Protection Impact Assessments (DPIAs), privacy risk assessments, records of processing activities, lawful basis assessments, and privacy by design requirements.
- Act as a point of contact for data subjects, internal stakeholders, customers, suppliers, and the Information Commissioner’s Office (ICO) on data protection matters, where required.
- Oversee data subject rights request processes, personal data breach assessment, investigation, reporting, remediation, and lessons learned activities.
- Maintain data protection policies, privacy notices, retention schedules, training materials, awareness programmes, and governance reporting.
- Support supplier and customer due diligence by reviewing data processing agreements, privacy clauses, international transfer requirements, and data protection assurance evidence.
Environmental Compliance & Sustainability Reporting
Lead the organisation's environmental compliance programme including:
- Streamlined Energy and Carbon Reporting (SECR).
- Energy Savings Opportunity Scheme (ESOS).
- United Nations General Council (UNGC).
- CDP (Formally Carbon Disclosure Project)
- Carbon emissions data collection and reporting.
- Climate-related reporting requirements.
- Carbon reduction plans and Net Zero initiatives.
- Environmental objectives, targets, and performance monitoring.
- Customer compliance programmes, i.e. NHS Net Zero
Responsibilities include
- Data collection and validation.
- Regulatory submissions.
- Auditor liaison.
- Environmental performance reporting.
- Sustainability programme support.
Supplier Assurance & Customer Compliance
Manage compliance activities across multiple customer and supplier portals, including:
- Supplier onboarding and assurance programmes.
- Risk Ledger.
- EcoVadis.
- Customer compliance portals.
- Public sector framework compliance requirements including NHS Evergreen assessment and NHS-DSP.
Responsibilities include
- Maintaining organisational profiles.
- Coordinating evidence uploads.
- Managing renewal cycles.
- Responding to customer due diligence requests.
- Maintaining supplier security and compliance records.
Audit & Assurance
- Develop and maintain annual internal audit programmes.
- Arrange internal audits across business functions using external partner.
- Coordinate external audits and regulatory inspections.
- Track findings, non-conformities, observations, and actions.
- Report compliance performance trends.
- Deliver audit training and awareness activities to audit attendees.
Stakeholder Management
- Work with business leaders to ensure compliance requirements are embedded.
- Liaise with certification bodies, auditors, regulators, customers, and suppliers.
- Provide guidance and training to employees.
- Support bids and public sector tender submissions requiring compliance evidence.
About Us
Solid solutions for a dynamic world
About us
Maintel is a communications managed services provider. We empower our clients across the public and private sector to deliver mission critical services and achieve their workplace, service and customer experience goals.
We consult on the design, deploy and manage network infrastructures, platforms and software, including our own, that keep ongoing operations running smoothly and dependably, protecting business as usual, at the same time being flexible enough to adapt.
When customer, employee, the general public and regulatory expectations are ever-changing, choose Maintel. We provide progressive, solid solutions that help you succeed in a demanding, dynamic world.
A brief history
Maintel, founded in 1991 by Tim Mason and Angus McCaffery, started as a small operation providing telephone maintenance contracts.
About compliance & regulatory roles for ex-police
Compliance, AML and regulatory roles. Working to PACE, RIPA and CPIA is a stronger regulatory grounding than most civilian applicants can offer — firms increasingly recognise this.
See all compliance & regulatory jobs in London →Why this fits a police background — match score 75/100
- Evidence & case files
- Intelligence & OSINT
- Incident command & response
- Investigative casework
- Digital forensics & cybercrime
What compliance & regulatory roles pay ex-police
Advertised UK ranges, editorial estimates reviewed July 2026
| Compliance analyst | £32,000–£42,000 |
| Compliance / AML officer | £40,000–£55,000 |
| Compliance manager | £55,000–£80,000 |
| Senior manager / head of compliance | £80,000–£120,000+ |