Information Governance & Data Protection Lead
Job Summary
The post holder leads the development, implementation and ongoing management of a comprehensive Information Governance (IG) framework, supporting the Chief Information Security Officer (CISO). Responsible for the delivery and assurance of the NHS Data Security and Protection Toolkit (DSPT), the role ensures compliance with UK GDPR, Data Protection Act 2018, Freedom of Information Act, Environmental Information Regulations and other relevant legislation and standards.
The position provides specialist expertise across Information Governance Management, Confidentiality and Data Protection, Information Security, Clinical Information, Information Quality, Records Management, Secondary Use and Corporate Information. The role supports senior leadership, including the CISO, Caldicott Guardian and Senior Information Risk Officer (SIRO), while acting as a key liaison with NHS England, Integrated Care Boards (ICBs), the Information Commissioner's Office (ICO) and other regulatory bodies.
Key Responsibilities
- Lead and maintain the organisation's Information Governance framework, strategy, policies and annual work programme.
- Manage and assure compliance with the NHS Data Security and Protection Toolkit (DSPT).
- Provide expert advice on UK GDPR, Data Protection Act 2018, Freedom of Information Act, Environmental Information Regulations and NHS information governance requirements.
- Support the completion and review of Data Protection Impact Assessments (DPIAs), Data Sharing Agreements and Data Processing Agreements.
- Act as the Information Security subject matter expert, working closely with Digital and Technology teams to improve security compliance.
- Lead investigations into information governance incidents, confidentiality breaches and data security events, producing reports and recommendations.
- Maintain Information Asset Registers and Records of Processing Activities (ROPA).
- Develop, implement and monitor Information Governance policies, procedures and best practice frameworks.
- Deliver training, awareness programmes and communications relating to information governance and data protection.
- Support organisational compliance with the NHS Confidentiality Code of Practice and other NHS information standards.
- Act as a key point of contact for the ICO, NHS England, ICBs and other external stakeholders.
- Produce governance reports for senior leadership and board-level committees, escalating risks and compliance concerns where required.
- Lead Freedom of Information (FOI) compliance activities, including policy development, internal reviews and publication scheme management.
- Establish and monitor Information Governance performance measures and improvement plans.
- Support contract management, business continuity and service delivery from an Information Governance perspective.
- Provide expert guidance on research governance, regulatory compliance and data protection requirements for research projects.
- Line manage Information Governance staff, including FOI and IG administrative resources.
- Drive continuous improvement and ensure alignment with national NHS standards, guidance and best practice.
Key Skills & Experience
- Extensive experience in Information Governance, Data Protection and Information Security.
- Strong knowledge of UK GDPR, Data Protection Act 2018, FOIA 2000 and NHS Information Governance requirements.
- Proven experience delivering and assuring compliance with the NHS Data Security and Protection Toolkit (DSPT).
- Experience engaging with the ICO, NHS England, ICBs and other regulatory bodies.
- Strong stakeholder management, policy development, audit and compliance experience.
- Ability to influence senior leaders and drive organisational change.
- Experience conducting DPIAs, incident investigations and information governance audits.
- Strong leadership and people management skills.