About the job
About the Role
Montu UK is seeking a dedicated Data Privacy Counsel to spearhead and enhance our privacy, data protection, and information governance initiatives within our UK operations. In this pivotal role, you will integrate comprehensive UK GDPR, DPA 2018, and PECR compliance into our telehealth clinic, Alternaleaf, and our online pharmacy, ensuring innovation while safeguarding patient trust.
This is a dynamic, hands-on role at the core of a regulated digital health scale-up, collaborating with Clinical, Pharmacy, Product/Engineering, Governance, and Operations teams to make privacy practical and scalable from the outset.
Key Responsibilities
Compliance & Governance
- Lead and enhance Montu UK’s privacy compliance framework, ensuring adherence to UK GDPR, DPA 2018, PECR, and healthcare information regulations.
- Maintain essential privacy documentation, including RoPA, policies, DPIA framework, retention schedules, and cookie/marketing practices, while providing clear internal reporting.
- Serve as the UK privacy subject matter expert (SME), translating complex regulations into actionable outcomes.
Advisory & Stakeholder Partnership
- Provide expert advice to senior leadership and cross-functional teams on privacy-by-design principles and data ethics.
- Support both new and existing products/workflows (telehealth, patient portal, remote prescribing, pharmacy systems) through DPIAs/LIAs, risk assessments, and practical controls.
- Advise on controller/processor roles, vendor due diligence, cybersecurity expectations, and international data transfers.
Contracting & Regulator Interface
- Draft, review, and negotiate Data Processing Agreements (DPAs), data-sharing contracts, and privacy/security clauses within commercial agreements.
- Act as the Data Protection Officer (DPO) for Montu UK group companies and be the primary liaison with the Information Commissioner's Office (ICO) regarding UK processing activities.
Enablement & Culture
- Foster a robust privacy culture through training, awareness initiatives, and user-friendly guidance that teams can easily implement.
- Empower teams to innovate safely, balancing compliance with patient access, innovation, and business objectives.

