Summary
Overview
Work history
Education
Skills
Certification
Timeline
Generic

Robert Smith

North West,United Kingdom

Summary

Accomplished professional with expertise in third-party vendor risk management and data privacy, including GDPR compliance. Proficient in assurance methodology, control testing, and records management, ensuring robust data governance. Skilled in conducting risk and control self-assessments (RCSA) and adept at supplier and stakeholder management. Known for problem-solving, critical thinking, and business process improvement. Strong leadership abilities complemented by negotiation and influence skills. Committed to enhancing organisational resilience through strategic risk management initiatives.

Overview

15
15
years of professional experience
2009
2009
years of post-secondary education
1
1
Certification

Work history

Data Privacy Manager

Lloyds Banking Group
2023.10 - 2026.03
  • Ensuring GDPR-compliant processing across the HR function and wider change agenda.
  • Liaising with and influencing Senior Stakeholders within HR Function and Group-wide including Group DPO, Legal, IT Security, Audit, Procurement, and Supplier Management.
  • Providing expert guidance on Data Privacy and Records Impact Assessments. Leading stakeholders through required governance for data processing activities, linked records management requirements and resolution of data privacy breaches.

Key achievements:

  • Launched new low risk privacy assessment journey which enhanced review of data processing activities, associated controls, and regulatory obligations, delivering 75% reduction in average completion time from 2 weeks to under 3 days for 250 low risk assessments allowing for greater focus on governance of high-risk processing activities.
  • Led the Data Hub’s controls framework refresh and path to green remediating and enhancing 23 controls, improving residual risk scores to bring them within tolerance.
  • Advised on controller/processor relationships and assessed third-party data protection risks, conducting vendor data risk assessments and defining governance standards aligned to risk profiles. Launched new supplier risk matrix and quarterly interlock with supplier management, driving a 15% reduction in third-party related incidents and non-conformances.
  • Led cross-functional team to enhance the Right To Be Forgotten process for external applicants. Reducing average response times by 33% from 3 to 2 weeks and aligning retention requirements and response processes to produce a 35% reduction in possible treatment strategies and scenarios.
  • Owned the Employee, Applicant, and Contractor Privacy Notices annual refresh, including launch of new targeted communication method driving a 300% increase of colleague views.

Supplier Assurance Manager

Lloyds Banking Group
2016.05 - 2023.09
  • Delivered supplier assurance across LBG’s global supply chain as part of the Third-Party Risk Management framework. Assessing the control framework of LBG’s critical supplier population to determine alignment to regulatory requirements, LBG policies/risk appetites, allowing for the identification of third-party risks and negotiating remediation with suppliers and internal stakeholders.

Key Achievements

  • Led the Supplier Cyber Security Assessment programme, overseeing outsourced assurance activity covering 65% of LBG’s supplier reviews.
  • Directly managed over 200 onsite assurance reviews across 11 countries, including scoping, gap analysis, reporting, escalation and remediation activities. Including leading cross-functional teams to assess impact/likelihood scoring and agree remediation plans with senior third party stakeholder for all failed controls. Over 80% of suppliers developed an improvement in RAG ratings and both severity and volume of findings following annual retesting activities across their contractual lifecycle.
  • Owned 7 Severe-High Priority Findings which were escalated to LBG’s Group Executive Board and required tactical resolution activities to immediately reduce LBG’s risk exposure.
  • Acted as Data Privacy, Records Management, and Supply Chain Risk Policy Lead, providing expert guidance and training to the team and also leading and influencing policy owners through the annual refresh of assurance test scripts.
  • Led implementation and launch of the Data Management third-party assurance methodology.
  • As Records Management Champion, established the team’s Records Management framework and control activities to ensure alignment to LBG’s policy and regulatory requirements.
  • Conducted control effectiveness testing across LBG’s 23 Third Party Policy suite including Supply Chain risk, Data Privacy, Records Management, Financial Crime, Operational Risk, Business Continuity/Operational Resilience, Regulatory Compliance, and Customer Service.

Buyer

Lone Star Leeds
2013.07 - 2015.06
  • Supported supplier management and regulatory compliance activities.
  • Analysed supplier KPIs and audit results to maintain risk appetite.
  • Managed stakeholder expectations using data-driven insights.
  • Delivered procurement projects to consolidate supply chains, reduce costs, and improve efficiency.
  • Supervised a team delivering improvements in indirect supply processes.

Buyer

Surgical Innovations
2010.12 - 2013.06
  • Sole buyer responsible for supplier management and procurement.
  • Worked with Production, Quality, Regulatory, and Engineering teams to address supply, compliance, and cost-efficiency issues.
  • Supported supplier audits and regulatory compliance activities.

Education

LLB - English Law with European Studies

University of Leeds

Skills

  • Third-Party Vendor Risk Management
  • Data Privacy & GDPR Compliance
  • Assurance Methodology & Control Testing
  • Records Management & Data Governance
  • Risk & Control Self-Assessments (RCSA)
  • Supplier & Stakeholder Management
  • Problem Solving & Critical Thinking
  • Business Process Improvement
  • Leadership, Negotiation & Influence

Certification

  • BCS Practitioner Certificate in Data Protection (2025)
  • BCS Level 4 Certificate in Purchasing & Supply (2012)

Timeline

Data Privacy Manager

Lloyds Banking Group
2023.10 - 2026.03

Supplier Assurance Manager

Lloyds Banking Group
2016.05 - 2023.09

Buyer

Lone Star Leeds
2013.07 - 2015.06

Buyer

Surgical Innovations
2010.12 - 2013.06

LLB - English Law with European Studies

University of Leeds
Robert Smith