About The Position

BCM One is looking for a Privacy and Compliance Analyst to join our global Legal team. This role will become a key privacy resource for BCM One globally. You will work closely with Legal, Information Security, IT, Product, Engineering, and other teams across the business to help turn privacy obligations into practical policies, processes and controls. The Privacy and Compliance Analyst will have a strong focus on data privacy, customer and supplier questionnaires, privacy assessments, due diligence, and process improvement. You will also support wider Governance, Risk and Compliance activities, including audit preparation, evidence collection, and security compliance work. This role offers the opportunity to develop real ownership. You will begin by learning about our business, reviewing existing policies and documentation while working alongside experienced colleagues. As your knowledge grows, you will be encouraged to recommend improvements and take greater responsibility for building and maintaining our privacy processes.

Requirements

  • 3+ years of experience in privacy, data protection, compliance, information governance, or GRC
  • Practical knowledge of GDPR, UK GDPR, PECR, and international privacy requirements
  • Experience with privacy assessments, documentation, supplier reviews, and customer questionnaires
  • Understanding of cloud technology, information security principles, and frameworks such as ISO 27001 and SOC 2
  • Strong research, critical thinking, and problem-solving skills
  • Clear communication skills with the ability to explain complex topics simply
  • Organised, detail-oriented, and confident managing priorities across teams
  • Familiarity with Microsoft Office Suite with proficiency in Excel

Responsibilities

  • Lead customer and supplier privacy reviews, questionnaires, and due diligence
  • Conduct privacy and security due diligence on suppliers and third parties
  • Support compliance with GDPR, UK GDPR, PECR, CCPA, CPRA, and other privacy laws
  • Conduct DPIAs, TIAs, LIAs, and other privacy risk assessments
  • Maintain and improve ROPAs, data inventories, and privacy documentation
  • Partner with Product, Engineering, IT, and business teams on privacy by design
  • Support Legal on privacy notices, consent, data retention, and contractual commitments
  • Support audits and compliance programs through evidence collection and remediation tracking
  • Contribute to ISO 27001, SOC 2, and other compliance initiatives
  • Support privacy, security, and third-party risk assessments and maintain risk registers
  • Support privacy incident investigations and remediation activities
  • Monitor privacy laws and recommend policy or control improvements
  • Partner with our GRC Specialist to support privacy awareness and compliance training as needed
  • Identify ways to improve efficiency, strengthen processes, and reduce privacy risk

Benefits

  • Competitive base salary
  • Annual salary reviews
  • Holiday entitlement (paid annual leave)
  • Paid UK bank holidays
  • Critical illness cover
  • Income protection insurance
  • Private medical insurance (PMI)
  • Employer-matched NEST pension scheme
  • Life assurance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service