Summary
Overview
Work History
Education
Skills
Certification
Technical Proficiencies
Personal Information
Timeline
web
Allan Simpson

Allan Simpson

Data Protection
Alloa,CLK

Summary

Data protection leader with 10+ years' experience building privacy programs that balance regulatory compliance with practical business needs. My approach puts individuals and data value - not just regulations - at the centre of privacy work, creating sustainable outcomes where compliance emerges naturally from trust as a happy outcome of the work involved. Specialised in transforming data protection from a perceived burden into integrated business-as-usual practice, with particular expertise in AI governance, privacy technology implementation (OneTrust, TrustWorks), and cross-sector program development across public, private, and charitable organisations.

Overview

33
33
years of professional experience
3
3

Certifications

Work History

Data Strategy and Information Governance Officer

VisitScotland
Edinburgh
10.2024 - Current
  • Reporting to Head of Legal and Director of Corporate Services as DPO for Scotland's national tourist authority. Lead data strategy, AI governance, and records management across all organisational functions including Events, Business Development, Marketing, Online Operations, Communications, HR, IT, Legal, Finance, Compliance, and Procurement for organisation of 350 employees.
  • DPO for VisitScotland; point of contact for all data protection and privacy matters;
  • Project lead for new data strategy aligned to Scottish tourism global objectives;
  • AI governance architect applying UK GDPR and EU AI Act controls to insights/marketing programmes;
  • Records manager for non-departmental government agency; developed new Business Classification Scheme;
  • Member of Scottish Government Business Support Partnership DPO group (Master Customer Record project);
  • Oversight of DSAR processing, breach investigation/response, DPIA monitoring, and risk register updates;
  • Advisory role to procurement on systems-as-a-service acquisitions (Oracle, AWS, specialist services);
  • Regular reporting to Audit & Risk Committee, Board, and Executive Leadership Group;
  • Member of Data Governance & Security Group and AI Steering Group.
  • Privacy Centre redesign - Replaced traditional privacy policy with user-friendly Privacy Centre, improving information accessibility and reducing 'policy fatigue';
  • AI use-case intake system - Developed visibility and evaluation framework for AI projects with organisation-wide awareness sharing;
  • Procurement risk management - Created assessment system for vendors proposing AI-enabled services to enforce accountability mechanisms;
  • Data sharing agreement automation - Implemented semi-automated template system improving consistency and turnaround times;
  • Analytics platform migration - Initiated and supported transition from Google Analytics to privacy-preserving Matomo, improving accuracy and reliability;
  • Data strategy development - Delivered new organisational data strategy currently in implementation phase;
  • Lawful basis optimisation - Restructured approach to increase 'Public Task' utilisation over Consent, aligning with legal remit and customer relationships;
  • Training programme innovation - Replaced annual mandatory training with frequent, role-specific 'short-form' interventions progressing toward a role based 'just-in-time' model;

Data Protection Officer

VisitScotland
Edinburgh
08.2023 - 10.2024
  • Established and operationalised comprehensive data protection and privacy management functions for the national public sector tourist authority.
  • Managed DSAR responses, breach investigations, DPIAs, and processing activity records;
  • Configured and migrated data processing records from legacy systems to OneTrust/TrustWorks platform;
  • Delivered organisation-wide data protection training programme;
  • Supported major database migration projects (Oracle, HR, procurement, direct marketing, payroll).

Managing Director

Responsible Data Use (Allstrat Ltd)
Inverness
04.2022 - 08.2023
  • Founder-led consultancy delivering outsourced DPO and privacy management advisory services to UK hotel industry sector.
  • GDPR/Data Protection Act 2018/PECR readiness assessments and implementation;
  • Privacy management system configuration (OneTrust, DPOrganizer);
  • Client training, DPAs, TRAs, data mapping, vendor assessments, breach response management;
  • Technology stack: Google Workspace, Microsoft 365.
  • Accreditations & Memberships: Corporate member, Data and Marketing Association (DMA); Founder member, Data Privacy Protocol Alliance; ISO Council Member (BSI/ISO31030 Travel Risk Management standard—GDPR SME until role ceased upon joining VisitScotland).
  • [Note: Allstrat Ltd operates as an ongoing directorship since 2002 alongside subsequent employment]

Information Governance Senior Specialist (Contractor)

NHS Education for Scotland (NES) Digital Directorate
Edinburgh
10.2021 - 03.2022
  • SME resource for agile IT project teams developing COVID-related systems across NHS Scotland and Scottish government organisations.
  • Supporting vaccination management systems and COVID passport verification infrastructure;
  • Representing directorate as IG specialist on fast-moving vaccination project teams involving Scottish government agencies;
  • Collaborating with external data controllers/processors on Vaccination Management Tool (VMT) and National Clinical Data Store (NCDS);
  • Maintained directorate OneTrust tenant; trained colleagues on system utilisation.
  • "Easily the best, most relatable information governance guy I've come across." - Project Manager, NES Digital Directorate

Information Governance Manager (Contractor)

NHS National Services Scotland (NSS)
Edinburgh
01.2021 - 09.2021
  • Digital & Security department role supporting digital transformation across 22 NHS Scotland health boards.
  • DPIA documentation for Office 365 rollout across health board network;
  • OneTrust privacy management system implementation for all 22 NHS Scotland health boards;
  • COVID-19 testing and vaccination programme support;
  • Privacy notices and data sharing agreements (including DHSC interfaces);
  • Critical service protection for food production/distribution and emergency control centres.

Data Protection Officer

The Church of Scotland
Edinburgh
07.2019 - 12.2020
  • First-ever DPO appointed to Scotland's 5th largest charity (800 congregations, 100 care homes, significant safeguarding operations). Law Department Central Services position with advisory role across Presbyteries and Congregations.
  • RoPA from standing start - Completed Article 30 Records of Processing for all Central Service departments;
  • Breach risk scoring system - Implemented consistent, understandable framework to guide and inform data incident response decisions;
  • OneTrust implementation - Deployed enterprise privacy management system (DSAR, DPIA, mapping, risk, vendor, breach tracking);
  • Phishing awareness programme - Rolled out KnowBe4 threat management and training infrastructure;
  • COVID-19 attendance system - Rapidly deployed privacy-respecting registration system to 400 congregations for Test & Protect activities (later described as 'world-leading').

General Manager

Glen Mhor Hotel
Inverness
11.2006 - 09.2008
  • Operational and marketing leadership for hotel and restaurant under new ownership. Managed budget allocation, team development, and technology refresh including PMS and online sales systems.

Director

Possible Futures Ltd
Inverness
08.1999 - 02.2002
  • Management support services for technology startups. Led high-performing development teams; sold 50% equity stake to US-based investor.

General Manager

Palace Hotel
Inverness
01.1994 - 09.1998

Education

Management of Emerging Technology -

University of Stirling
Stirling, United Kingdom
01.2023

GDPR Practitioner -

The Knowledge Academy
Glasgow, United Kingdom
01.2017

Master of Business Administration -

Strathclyde University Business School
Glasgow, United Kingdom
01.2003

BA - Hotel & Catering Management

Queens College
01.1990

Fellow of Information Privacy -

International Association of Privacy Professionals

Fellow of Privacy Technology -

OneTrust Certification

Certified Information Privacy Professional -

IAPP

Certified Information Privacy Manager -

IAPP

Skills

  • Data Protection
  • Leadership
  • DPO Functions
  • Board-Level Reporting
  • UK/EU GDPR Compliance
  • Multi-Agency Collaboration

Certification

  • CIPP/E
  • CIPM
  • FIP
  • OneTrust Fellow of Privacy Technology

Technical Proficiencies

OneTrust, TrustWorks, DPOrganizer, Microsoft 365, Google Workspace, SharePoint, Matomo, Google Analytics, KnowBe4

Personal Information

Title: Data Protection Officer | Privacy Management Professional | AI Governance Specialist

Timeline

Data Strategy and Information Governance Officer

VisitScotland
10.2024 - Current

Data Protection Officer

VisitScotland
08.2023 - 10.2024

Managing Director

Responsible Data Use (Allstrat Ltd)
04.2022 - 08.2023

Information Governance Senior Specialist (Contractor)

NHS Education for Scotland (NES) Digital Directorate
10.2021 - 03.2022

Information Governance Manager (Contractor)

NHS National Services Scotland (NSS)
01.2021 - 09.2021

Data Protection Officer

The Church of Scotland
07.2019 - 12.2020

General Manager

Glen Mhor Hotel
11.2006 - 09.2008

Director

Possible Futures Ltd
08.1999 - 02.2002

General Manager

Palace Hotel
01.1994 - 09.1998

BA - Hotel & Catering Management

Queens College

Fellow of Information Privacy -

International Association of Privacy Professionals

Fellow of Privacy Technology -

OneTrust Certification

Certified Information Privacy Professional -

IAPP

Certified Information Privacy Manager -

IAPP

Management of Emerging Technology -

University of Stirling

GDPR Practitioner -

The Knowledge Academy

Master of Business Administration -

Strathclyde University Business School
Allan SimpsonData Protection