The Data Privacy Analyst role is operationally focused, requiring a hands-on and collaborative approach to managing privacy processes. The analyst will ensure that Vanguard’s privacy framework is robust and compliant with relevant regulations, particularly European data protection laws. The role involves process enhancements, stakeholder collaboration, and protection of client and employee data, advancing Vanguard's commitment to privacy excellence.
About Vanguard
We are Vanguard. Together, we’re changing the way the world invests.
For us, investing doesn’t just end in value. It starts with values. Because when you invest with courage, when you invest with clarity, and when you invest with care, you get so much more in return. We invest with purpose—and that’s how we’ve become a global market leader. Here, we grow by doing the right thing for the people we serve. And so can you.
In this role you will
- Monitor, analyse, and support compliance with European Data Protection Privacy laws including GDPR and Vanguard’s Global Privacy Policy
- Conduct and support privacy risk assessments such as Data Protection Impact Assessments (DPIAs), Transfer Impact Assessments (TIAs), and Legitimate Interest Assessments (LIAs)
- Maintain and update Records of Processing Activities (ROPAs) to ensure regulatory compliance
- Develop, implement, and continuously enhance privacy policies, procedures, and operational controls
- Provide guidance and training to stakeholders on privacy requirements and operational procedures, including leading privacy-related forums and training to increase awareness
- Support the maintenance and evolution of the privacy program framework, including policy and standard development, and oversee privacy incident control and response frameworks
- Consult with business leaders to implement Privacy by Design principles and assess data privacy and security risks to mitigate potential incidents
- Monitor emerging privacy risks in the industry and participate in privacy organizations to stay updated on best practices
- Oversee daily incident assignments, investigations, and ensure adherence to regulatory and notification requirements
- Collaborate with legal counsel to implement new privacy requirements and review program metrics to provide insights to management
- Participate in special projects as assigned
What it takes
- Relevant work experience in risk, compliance or regulatory roles, preferably within the financial services industry
- CIPP/E certification is preferred; CIPP/US certification is considered a plus
- An undergraduate degree or an equivalent combination of training and experience is required
- Strong stakeholder management skills with the ability to influence, prioritize, and communicate risks clearly
- Ability to interpret and apply privacy requirements to real-world business processes, systems, and data flows
- Strong administrative, organizational, program management, and presentation skills, with attention to detail and a practical, outcome-driven mindset
- Experience with privacy management tools such as OneTrust is a plus
Special factors
- Vanguard is not offering sponsorship for this position
- This is a hybrid position and would require you to work in the office 3 days per week (Tuesday, Wednesday & Thursday)
Why Vanguard?
Vanguard is a different kind of investment company. It was founded in the United States in 1975 on a simple but revolutionary idea: that an investment company should manage its funds solely in the interests of its clients.
This is a philosophy that has helped millions of people around the world to achieve their goals with low-cost, uncomplicated investments.
It's what we stand for: value to investors.




