About the Role
Information Governance Senior Compliance Officer and Deputy Data Protection Officer (DPO)
Fixed Term Contract (18 months)
Opportunity to use your significant experience of working in a public sector setting in a Data Protection compliance role in supporting the organisation’s compliance with Data Protection laws and ensuring data/cyber security and information governance standards and compliance across the organisation.
Reporting to the Information Governance Manager (Compliance), you will support the development of Information Governance and Data Security policies and guidance, working closely with the IT Team and IG Casework Manager, to ensure compliance with relevant legislation and best practice, and inform delivery of training to staff to increase awareness of data protection and information security measures. The role will also involve supporting the IG Casework team during peak times on complex requests for information.
As the organisation’s Deputy Data Protection Officer, you will support the DPO as the point of contact for providing advice to staff and senior management including the Senior Information Risk Owner (SIRO); undertake escalated breach management (reportable to the ICO) casework; and support initiatives and best practice implementation into the organisation to develop compliance with ‘data protection by design and default/Security by design’ concepts.
Likely to be Data Protection Practitioner qualified (or equivalent), essential requirements include:
Significant successful experience of working in a public sector setting in a Data Protection compliance role;
In-depth knowledge of DPA/GDPR and associated legislation;
Considerable successful experience of managing highly confidential and sensitive information in a professional and restricted manner; and
Proven successful experience in supporting data security compliance and DP compliance activities (DPIA/RoPA/IAR).
Your ability to communicate effectively in a variety of formats with all levels of colleagues and stakeholders, including explaining legal concepts in non-legal terms, will also be key.
Tech Stack
GDPRdata protectionDPA 2018information governancedata securitycomplianceDPIAincident management