Search

Privacy and Compliance Manager

HeliosX
locationLondon, UK
PublishedPublished: Published 1 week ago
Business Compliance
Ready to revolutionize healthcare, making it faster and more accessible than ever before?

How we started:

Back in 2013, our founder Dwayne D'Souza saw an opportunity to give people faster and more convenient access to medications using technology. We've grown rapidly since our inception, without any external funding whatsoever - achieving profitability through innovation and a highly disciplined approach to growth.

Where we are now:

We've earned the trust of millions of people worldwide through our top-selling products and well-known brands: MedExpress, Dermatica, ZipHealth, RocketRX, and Levity. A lot of our success is down to having our own pharmacies, manufacturers and products - spearheaded by leading in-house medical teams, researchers and pharmacists. Between 2023 and 2024 our global revenue tripled; £60m to £180m (300% year-on-year growth). We're looking to do the same in 2025; move into new territories, and further accelerate our growth journey. There's never been a more exciting time to join HeliosX.

Where we're going:

Over the next five years, you'll support our goal to become a world-leading healthcare partner, deepening our customer relationships, expanding into new countries, and diversifying our product portfolio to treat more conditions. You'll be part of helping more people access prescription treatments and, most importantly, making personalised care better, quicker and easier for everyone.

Come be a part of making our dream of easier and faster healthcare a reality!

About the Role

Are you passionate about data privacy, regulatory compliance, and ethical business practices? Do you thrive in a fast-moving, high-growth environment where you can have a direct impact? We're looking for a Privacy & Compliance Manager to join our growing Legal team at HeliosX, a company revolutionising healthcare through digital innovation.

In this role, you will be at the forefront of safeguarding our customers' trust, ensuring compliance with global data protection regulations, and embedding privacy-first principles into everything we do. You'll have the autonomy to shape policies, guide strategic decisions, and collaborate with senior stakeholders to navigate the evolving regulatory landscape of the HealthTech sector.

What you'll do
  • Drive Compliance & Risk Management - Monitor and ensure adherence to GDPR, UK Data Protection Act 2018, PECR, and other key privacy regulations while staying ahead of legislative developments.
  • Champion Best Practices - Advise on handling personal data, including clinical regulations related to health data, while supporting key areas such as SARs, DPIAs, and marketing consent policies.
  • Strategic Advisory - Work closely with the Head of Legal and senior stakeholders, providing expert insights into regulatory and compliance matters within the HealthTech sector.
  • Risk Identification & Mitigation - Oversee risk assessment and mitigation strategies, helping leadership navigate cross-border data transfers (SCCs, UK IDTA) and broader compliance risks.
  • Global Risk Register Management - Maintain an accurate, up-to-date risk register, ensuring a clear view of potential challenges across all markets.
  • Privacy by Design - Implement and maintain a privacy-first approach across the business, integrating compliance seamlessly into operations.
  • Training & Awareness - Design and deliver company-wide compliance training programs, ensuring every team member understands their role in upholding data protection standards.
  • Audits & Policy Development - Conduct internal compliance audits, draft and refine privacy policies, and help shape internal procedures to align with evolving regulatory requirements.
  • Reporting & Leadership Engagement - Prepare reports for the leadership team, keeping them informed on compliance operations, emerging risks, and strategic plans.
What you'll bring to HeliosX
  • Professional Certifications - CIPP/E, CIPM, or equivalent credentials are highly desirable.
  • Educational Background - A degree in Law, Information Governance, or a related field is a plus but not essential.
  • Experience & Expertise - At least 2-3 years of hands-on experience in privacy and compliance, preferably in Tech or HealthTech.
  • Regulatory Knowledge - Deep understanding of GDPR, UK Data Protection Act 2018, and PECR, with the ability to translate complex regulations into actionable business strategies.
  • Global Privacy Frameworks - Familiarity with European data laws, and knowledge of CCPA is an advantage.
  • Technical Understanding - Experience handling DPIAs, SARs, tracking cross-border data transfers, and working with ISO 27001 standards is beneficial.
  • Analytical & Communication Skills - Ability to assess regulatory landscapes, communicate complex information clearly, and influence decision-making at all levels.
  • Interest in HealthTech - A passion for healthcare innovation and the unique data privacy challenges in this space.
Life at HeliosX

At HeliosX, we want to improve healthcare for everyone, and to do this we need a team of brilliant people who share that ambition. We are currently a diverse team of engineers, scientists, clinical researchers, physicians, pharmacists, marketeers, and customer care specialists committed to our mission - but we need more talented folks to join us, if we want to achieve our global ambitions!

Aside from working with our all-star team, here are the other benefits of coming on board:
  • Generous equity allocations with significant upside potential
  • 25 Days Holiday (+ all the usual Bank Holidays)
  • Private health insurance, along with extra dental and eye care cover
  • Pension scheme
  • Enhanced parental leave
  • Cycle-to-work Scheme
  • Electric Car Scheme
  • Free Dermatica and MedExpress products every month, as well as family discounts
  • Home office allowance
  • Access to a Headspace subscription, discounted gym memberships, and a learning and development budget
#LI-Hybrid #LI-Associate