Skip to main content

How the CMA Privacy Sandbox Monitoring Trustee Role Works

What a CMA Privacy Sandbox Monitoring Trustee Does

A CMA Privacy Sandbox Monitoring Trustee is a person or organisation appointed by the UK Competition and Markets Authority (CMA) to oversee how companies handle personal data within the Privacy Sandbox testing environment. The role exists because the Privacy Sandbox — a set of tools Google and other tech companies are developing to replace third-party cookies — involves collecting and processing sensitive user information during trials. The trustee acts as an independent watchdog, checking that participating companies follow data protection rules and don't misuse the information they gather during testing.

This is not a role you inherit or volunteer for casually. The CMA selects trustees based on specific expertise in data protection, privacy law, and audit procedures. If you are being considered for this appointment or need to understand what it involves, you should know upfront that it requires technical knowledge of privacy frameworks, the ability to review complex data handling systems, and a commitment to regular monitoring over the course of the testing period.

Key Takeaways

  • The CMA appoints Privacy Sandbox Monitoring Trustees to oversee how companies handle personal data during Privacy Sandbox trials, not as a personal or family appointment.
  • Trustees must have demonstrated expertise in data protection law, privacy compliance, and audit procedures to be considered for appointment.
  • The role involves regular monitoring visits, reviewing data handling practices, and reporting findings back to the CMA at set intervals.
  • Appointment is formal and contractual, with specific terms, duration, and expectations set out by the CMA before you accept.
  • This appointment is distinct from personal trustee roles — it is a professional engagement with a regulatory body overseeing commercial testing.

Who the CMA Appoints and Why

The CMA does not open this role to general applications. Instead, it identifies and approaches organisations or individuals with the right background. Candidates typically come from audit firms, privacy consultancies, law firms specialising in data protection, or independent compliance bodies. The CMA looks for people or organisations that have no financial stake in the Privacy Sandbox outcome — independence is essential because the trustee's job is to report honestly on what they find, even if the findings are critical.

If you work in data protection, privacy law, or audit and the CMA contacts you about this role, they will outline what they are looking for: experience reviewing how organisations collect, store, and use personal data; familiarity with UK data protection law (particularly the Data Protection Act 2018 and UK GDPR); and the ability to produce clear, factual reports on compliance findings. You will also need to demonstrate that you can commit the time required — monitoring is not a one-off task but an ongoing responsibility over months or years.

What the Appointment Actually Involves

Once appointed, your core responsibility is to monitor participating companies' data handling practices during the Privacy Sandbox testing phase. This means visiting company sites or systems, reviewing how they collect user data, checking what they do with it, and verifying that they are following the rules the CMA has set for the trial. You will examine technical infrastructure, interview staff, and review documentation about data flows and storage.

You will produce reports at intervals set by the CMA — typically quarterly or at key milestones in the testing period. These reports describe what you observed, whether the company is complying with its obligations, and any risks or breaches you have identified. The reports go to the CMA, not to the public, though the CMA may use findings to inform its own public statements about how the Privacy Sandbox is working. You are not responsible for enforcing rules or punishing breaches — that is the CMA's job — but you are responsible for spotting them and reporting them accurately.

The Formal Appointment Process

The CMA will issue a formal letter of appointment setting out the terms. This document specifies your duties, the period of the appointment (usually tied to the end of the testing phase), how often you must report, what access you will have to company systems, and what fees or expenses you will receive. You will need to sign this before the appointment becomes active.

You will also be required to sign a confidentiality agreement. Information you learn during monitoring — about companies' technical systems, business practices, or data volumes — is confidential. You cannot share it with competitors, the media, or other third parties, even after the appointment ends. The CMA may also require you to declare any conflicts of interest and confirm that you have no financial or personal ties to the companies you will be monitoring.

Access, Reporting, and Accountability

Participating companies must grant you reasonable access to their systems, staff, and documentation. "Reasonable" is defined in your appointment terms — it usually means scheduled visits, access to relevant data systems, and the right to interview people who handle Privacy Sandbox data. Companies cannot refuse access or hide information from you, though they can ask you to sign additional confidentiality agreements specific to their business.

Your reports must be factual and evidence-based. You are not making judgments about whether the Privacy Sandbox is a good idea or whether the CMA's rules are fair — you are reporting on whether companies are following the rules as written. If you find a breach, you describe it clearly: what the rule was, what the company did, and what evidence supports your finding. The CMA uses these reports to decide whether to allow testing to continue, whether to impose conditions on companies, or whether to end the trial.

You remain accountable to the CMA throughout the appointment. If you miss reporting deadlines, fail to visit companies as required, or produce reports that lack evidence, the CMA can terminate your appointment. You are also expected to maintain professional standards — if your personal circumstances change in a way that creates a conflict of interest, you must disclose it immediately.

Duration and End of Appointment

Your appointment runs for a set period, usually aligned with the Privacy Sandbox testing timeline. The CMA may extend it if testing continues longer than planned, or end it early if the trial is halted. When the appointment ends, you have no further obligations to monitor or report, though confidentiality obligations typically continue indefinitely.

If you need to step down before the appointment ends — due to illness, a conflict of interest, or other reasons — you must notify the CMA in writing as soon as possible. The CMA will then appoint a replacement trustee. Stepping down does not release you from confidentiality obligations for information you learned while in role.

Costs, Fees, and Practical Considerations

The CMA covers the costs of monitoring — travel, access to systems, and reasonable expenses for conducting your work. You will also receive a fee for your time, though the amount varies depending on the scope of the role and the CMA's budget. The CMA will specify the fee structure in your appointment letter, and it is usually paid quarterly or at the end of each reporting period.

This is not a high-income role. It is a professional engagement that requires expertise and time but is typically compensated at market rates for compliance and audit work rather than as a premium appointment. If you are considering whether to accept, factor in the time commitment — monitoring visits, report writing, and follow-up can amount to several days per month depending on how many companies you are overseeing and how complex their systems are.

Frequently Asked Questions

Can I apply for this role, or does the CMA only approach people?

The CMA identifies and approaches candidates rather than opening applications. If you work in data protection, privacy law, or audit and believe you have relevant expertise, you can contact the CMA to express interest, but there is no formal application process. The CMA will assess whether your background matches what they need for a particular monitoring phase.

What happens if I find a company breaking the rules?

You report the breach to the CMA in your monitoring report, with full details and evidence. The CMA then decides what to do — it may ask the company to correct the breach, impose conditions on continued testing, or end the company's participation. You are not responsible for enforcement; your job is to report accurately.

Can I talk about this appointment publicly or on my CV?

You can say you hold or held a CMA Privacy Sandbox Monitoring Trustee appointment, as this is a matter of public record. You cannot disclose details about what you found during monitoring, which companies you worked with, or any confidential information about their systems or practices. Check with the CMA if you are unsure whether a specific disclosure is permitted.

What if my circumstances change and I can no longer do the role?

Notify the CMA immediately in writing. Explain the change and whether it is temporary or permanent. The CMA will discuss options — it may allow a temporary pause, ask you to step down, or work with you on adjustments. Do not simply stop reporting or visiting companies; that breaches your appointment terms.

Is this the same as being a trustee for a will or family trust?

No. This is a professional appointment with a regulatory body to oversee a commercial testing programme. It has nothing to do with managing personal assets, estates, or family arrangements. The title "trustee" refers to your role as an independent overseer of data handling, not to managing money or property on behalf of others.

This guide is general information, not professional advice. Offices and providers set their own rules, so check the details with the one you’re seeing. See our Editorial Policy.