Quick Overview
Job Description
Lanes Group Ltd is a leading nationwide utility services provider with c.5000 dedicated employees. Our diverse subsidiaries drive our success across various sectors, contributing to a remarkable turnover of over £650 million. We are committed to excellence and innovation, ensuring we provide industry leading services to our clients and stakeholders. Join us to be part of a dynamic and growing team that values diversity and fosters professional growth.
Department:
IT works closely with operational and support teams across the UK, providing the technology, systems, and infrastructure that enable the business to operate efficiently, securely, and effectively.
The team is responsible for maintaining, securing and supporting business-critical applications, networks, devices, and digital services, while driving technology improvements and innovation across the organisation.
Through responsive support, robust security practices, and continuous development of IT solutions, the team helps ensure employees have the tools and technology they need to perform at their best.
Purpose of the role:
DSAR Analyst
Location: Leeds/Midlands (remote with ad hoc office visits)
Hours: Full-time, Monday to Friday (37.5 hours per week), with flexible working options.
The DSAR Analyst is responsible for managing and coordinating Data Subject Rights Requests (DSRRs), including Subject Access Requests (SARs), in accordance with UK GDPR and other applicable privacy regulations. The role ensures that individual rights requests are processed accurately, within statutory timescales, and in compliance with organisational policies.
In addition to DSAR management, the role supports the wider data protection and privacy programme, including Data Protection Impact Assessments (DPIAs), privacy risk assessments, records of processing activities, incident investigations, compliance monitoring, and privacy awareness initiatives.
Key Responsibilities:
- Manage and support a wide range of data protection activities, including Data Subject Rights Requests (DSRs), Data Protection Impact Assessments (DPIAs), privacy risk management, personal data breach investigations, and ongoing compliance monitoring.
- Coordinate the end-to-end handling of Data Subject Rights Requests, ensuring requests are validated, processed, and responded to within statutory timeframes, while maintaining accurate records, evidence trails, and management reporting.
- Support the assessment and mitigation of privacy risks by conducting DPIAs, maintaining Records of Processing Activities (RoPA), contributing to audits and compliance reviews, and assisting with third-party and supplier privacy assessments.
- Assist in the investigation and management of personal data incidents and breaches, including risk assessments, root cause analysis, remediation activities, record keeping, and regulatory notification requirements where applicable.
- Provide practical data protection advice and guidance to stakeholders across the business, supporting projects involving new technologies, data sharing arrangements, international transfers, and privacy-by-design principles.
- Develop and maintain data protection policies, procedures, guidance materials, and governance documentation to support compliance with data protection legislation and organisational standards.
- Promote a culture of privacy awareness through training, communications, awareness campaigns, and the development of educational resources to improve understanding of data protection obligations and individual rights.
- Build effective relationships with internal and external stakeholders, including Legal, IT, HR, Procurement, operational teams, and third-party partners, to embed data protection best practice across the organisation.
Key Requirements
Essential Requirements
- Experience managing Data Subject Rights Requests (DSRs), including DSARs, within a GDPR-regulated environment.
- Good knowledge of UK GDPR, the Data Protection Act 2018, and data protection principles, including individual rights.
- Experience handling personal and special category data with a high degree of confidentiality and discretion.
- Ability to review, analyse, redact, and assess sensitive information accurately and appropriately.
- Strong stakeholder management skills with experience working across multiple business functions.
- Excellent organisational, case management, planning, and prioritisation skills, with the ability to manage multiple deadlines.
- Strong written communication skills, attention to detail, and sound judgement when dealing with complex or sensitive matters.
- Effective problem-solving and investigative skills with the ability to assess risk and make informed recommendations.
Desirable Requirements
- Experience supporting or conducting Data Protection Impact Assessments (DPIAs).
- Experience maintaining Records of Processing Activities (RoPA).
- Experience supporting personal data breach investigations and compliance activities.
- Experience working within Information Governance, Compliance, Legal, Risk, Information Security, or a similar function.
- Familiarity with privacy management platforms, eDiscovery tools, and data governance technologies.
- Understanding of recognised privacy and information security frameworks, such as ISO 27701 and ISO 27001.
- Experience working within a regulated industry.
- Data Protection qualification (held or currently working towards).
Living the Company Values
By embedding our companies core values and purpose into each role, ensures that every employee, regardless of their role or level, understands how their individual development and contributions align with our purpose of ‘improving today for a better tomorrow’.
Each role and value has an alignment to set proficiency levels and expectations; this role holder is expected to:
- Leading: Acts as a role model, shaping the learning agenda and influencing change.
- Agile: Anticipates learning needs, adjusts quickly to changing operational contexts.
- Nurturing: Supports the development of others through coaching and structured development plans.
- Engaging: Inspires and motivates learners, builds trust and credibility
- Safe & Secure: Ensures all learning is aligned to safety and compliance standards.
Your Contribution to the company:
- Strive to be always positive and constructive
- Adhere to all company policies
- Straight talking about the facts of the situation – open discussions are the best way to find solutions
- Help others through communicating clearly
- Deliver on commitments
- Ensure that any ideas that may enhance the productivity or systems of the company are brought to the attention of Senior Management, or your colleagues
- Deliver our Company Values understanding that by working together in unity we are ‘Stronger Together’
Equality, Diversion & Inclusion
At Lanes Group, we are dedicated to fostering a diverse and inclusive workplace where everyone feels valued and empowered. We believe that our differences make us stronger and are committed to providing equal opportunities for all employees. We welcome and encourage applications from individuals of all backgrounds, including those from underrepresented groups. Join us in our commitment to creating a more inclusive and diverse world.