Suki Sandhar e

Group Privacy & Security Grc Analyst @Spotlight Sports Group

Birmingham, GB
MOBILE NUMBERS
+91 *********19

Signup · Get unlimited contacts

WORK HISTORY

Feb 2025 — Present

Group Privacy & Security Grc Analyst @Spotlight Sports Group

View department →

London, GB

I act as the first point of contact for stakeholders on privacy by design, advising teams across the business. Early on, I reduced unnecessary data collection, redrafted the recruitment privacy notice and introduced audits to strengthen review global privacy standards with a focus on GDPR, CCPA and Australian Data Protection Law. I partnered with the US team on Pickswise projects to ensure compliance and reviewed Japanese data protection legislation from scratch, briefing senior management on key requirements.Working closely with Security, I helped design a tailored due diligence framework, moving from manual spreadsheets to a central database with audit trails. This improved vendor oversight, reduced risk and supported ISO27001 audit expectations. I also drove the launch of a Data Studio report integrating OneTrust assessments, PPIAs and DPIAs, embedding privacy by design.Within three months I updated 10 outdated Data Privacy and Security policies, introducing clear ownership, sign-off records and annual reviews to strengthen governance and reduce liability. I also redrafted three customer-facing privacy notices across multiple brands, including Racing Post, and created two employee notices from scratch to improve transparency.I implemented and streamlined the DPIA process, creating a register of 40 assessments and revisiting 10. I introduced sign-off controls, stakeholder walkthroughs and annual sampling, supported by Data Studio/Looker tracking to improve awareness of risks including AI. I also created SOPs and flow charts for SARs, due diligence and breach response.I have managed four ICO cases on breaches and complex SARs, all with favourable outcomes and no fines, securing positive compliance feedback and demonstrating accountability. I also supported ISO27001 pre-audits in HR and Finance, addressing gaps in policies, ROPAs and retention and preparing the business for certification.

EDUCATION

N/A

Privacy Pros Academy | Become a World-Class Privacy Expert

UltimateCIPP/EMasteryProgramforWorld-Class Professionals, Data Privacy

2006 — 2010

Aston University

BSc European Studies and French

ABOUT SUKI SANDHAR E

Data Privacy Analyst skilled in Data Governance and Legal & Regulatory Compliance, delivering bespoke solutions that enhance compliance and protect sensitive data across diverse industries.With a strong foundation in Data Privacy Compliance and Governance, I have over nine years of experience driving organisational compliance and operational efficiency. I am skilled in auditing, risk management, and project leadership within complex environments, including international locations such as Saudi Arabia. From successfully implementing GDPR-compliant systems to leading compliance with emerging laws such as Saudi Arabia’s PDPL, I can navigate complicated regulations pragmatically.At RTX, I led audits across Europe, the US, and the Middle East, identifying gaps, improving internal controls, and delivering actionable insights. I am a Data Protection Champion for Read Easy UK, where I have guided charities in transitioning to secure, GDPR-compliant Achievements: Global Privacy Governance Overhaul: Updated and standardised 10 outdated Privacy and Security policies across global operations within 3 months, introducing clear ownership, sign-off records, and annual review cycles, supporting GDPR and ISO27001 readiness. Saudi Arabia PDPL Compliance: Led a compliance project, addressing gaps in sensitive data handling and improving organisational awareness Privacy by Design & DPIA Framework Implementation: Implemented and streamlined a Data Protection Impact Assessment (DPIA) process with a register managing 40+ assessments, embedding privacy by design and enhancing awareness of privacy risks including AI. Training & Awareness: Delivered bespoke GDPR training to improve compliance among management and volunteer teams Global Audit Excellence: Identified compliance risks and improved operational controls across multi-region Areas of Expertise:Data Privacy Compliance | GDPR Implementation | Data Governance Risk Assessment | Internal Auditing | Legal & Regulatory Compliance Substantive Testing | Project Management | SOP Development Stakeholder Collaboration | Process Flow Mapping | One Trust & Trust Seeking opportunities to advocate and empower organisations and individuals to make informed, secure choices about data sharing and governance, ensuring privacy compliance and fostering trust.

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.