Ehr

Data Governance Consultant

London, London, City ofContractPosted Jul 20, 2026

Company Overview

EC Markets is a globally recognised financial brokerage, providing advanced FX and CFD trading services. As part of its growing finance team, EC Markets is seeking an Accounts Assistant to support daily financial operations and reporting, ensuring compliance, accuracy, and efficiency across the department.



Role Purpose

Support the business in achieving launch readiness by assessing, documenting and implementing the data governance, privacy and information security controls required for an FCA-regulated financial services platform.

The consultant will work across Product, Technology, Operations, Risk and Compliance to ensure customer data is appropriately governed, protected and processed in accordance with UK GDPR and FCA expectations.

This is a delivery-focused engagement with the primary objective of identifying launch blockers, closing critical gaps, and leaving behind sustainable governance processes.



Key Responsibilities



  1. Data Discovery & Governance

Lead an end-to-end review of customer data across the organisation, including:

  • What data is collected
  • Why it is collected
  • Where it is stored
  • Who has access
  • How it moves through systems
  • Who external processors are

Deliverables: data inventory, data classification framework, Information Asset Register, data flow diagrams.

  1. GDPR & Privacy

Review compliance with UK GDPR and Data Protection Act requirements, including:

  • Lawful basis
  • Consent
  • Retention
  • Deletion
  • Subject access requests
  • International transfers
  • Processor agreements

Deliverables: gap assessment, risk register, required remediation plan.

  1. Data Security Review

Assess current controls covering:

  • RBAC (role-based access control)
  • MFA (multi-factor authentication)
  • Encryption
  • Secrets management
  • Audit logging
  • Backup strategy
  • Disaster recovery
  • Production access

Identify launch-critical risks.

  1. AI & Data Usage Governance

Review the use of Claude, Snowflake, other LLMs, and internal reporting tools. Define:

  • Acceptable use
  • Access model
  • PII handling
  • Prompt handling
  • Data retention
  • User permissions

Produce governance recommendations.

  1. Third Party Risk

Review all vendors processing customer data, including cloud providers, AI providers, communications platforms, and payment providers. Ensure processor agreements, data residency, contractual protections, and security posture are appropriate.

  1. Policies & Documentation

Produce or review:

  • Privacy Notice
  • Data Retention Policy
  • Information Security Policy
  • Data Classification Policy
  • Access Control Policy
  • Incident Response Plan
  • Data Governance Policy
  1. Launch Readiness Assessment

Produce a quick-turnaround executive report identifying:

  • Green — ready for launch
  • Amber — acceptable with known risks
  • Red — must be resolved before launch

With clear, prioritised, actionable tasks to achieve launch readiness.

Success Criteria

By the end of the engagement, the business should be able to confidently answer:

  • What customer data do we hold, and why do we hold it?
  • Where is it stored, and who has access?
  • Is that access appropriate?
  • Where does data leave our environment?
  • Which suppliers process customer data?
  • What data is considered sensitive?
  • Are we compliant with GDPR and FCA expectations — and can we evidence this?

Essential Requirements

Regulatory & Compliance Background

  • Demonstrable experience leading data governance and privacy programmes for FCA-regulated or financial services businesses
  • Prior experience supporting an FCA authorisation process or a regulated product launch, ideally in fintech or payments
  • Strong working knowledge of UK GDPR and the Data Protection Act 2018 — lawful basis, consent, retention, deletion, subject access requests, and international transfers
  • Practical understanding of FCA expectations around data handling and customer outcomes, not just theoretical GDPR knowledge
  • Experience producing gap assessments, risk registers, and remediation plans that stand up to regulatory scrutiny

Data Discovery & Documentation

  • Hands-on experience running end-to-end data discovery and mapping exercises across an organisation, not just reviewing existing documentation
  • Track record of producing data inventories and data classification frameworks from scratch
  • Experience building Information Asset Registers and data flow diagrams
  • Ability to identify data processors and third parties handling customer data as part of a discovery exercise

Technical Security Assessment

  • Ability to assess technical security controls directly with engineering teams, rather than relying solely on policy-level documentation
  • Working knowledge of RBAC (role-based access control) and MFA (multi-factor authentication) implementation
  • Familiarity with encryption standards and secrets management practices
  • Experience reviewing audit logging, backup strategy, disaster recovery, and production access controls
  • Ability to translate technical findings into launch-critical risk ratings for non-technical stakeholders

AI, Data & Vendor Governance

  • Practical experience governing the use of AI/LLM tools (e.g. Claude, other LLMs) in a regulated environment, including acceptable use and access models
  • Understanding of PII handling and prompt-handling risk in AI-assisted workflows
  • Experience with data platform governance (e.g. Snowflake) — data retention and user permissions
  • Experience conducting third-party and vendor risk assessments, including cloud providers, AI providers, communications platforms, and payment providers
  • Working knowledge of data residency requirements and contractual/processor agreement protections

Delivery, Communication & Working Style

  • Track record of producing clear, regulator-ready policy documentation (privacy, retention, information security, access control, incident response) at speed
  • Comfortable operating as an autonomous, hands-on contractor in a lean startup environment — able to self-direct and work with minimal oversight
  • Ability to prioritise launch-critical risk over process, making pragmatic calls where a startup may lack mature governance infrastructure
  • Strong stakeholder management skills across Product, Technology, Operations, Risk and Compliance
  • Ability to translate technical and regulatory detail into a clear, executive-level Red/Amber/Green narrative
  • Proven ability to deliver a full assessment and documentation set against a tight, fixed deadline ahead of a live launch date

Location

30 City Road, London

Keep exploring

View all data & analytics jobs