This
role sits within the Information Governance team, in the Practice and
Compliance division. It is a home based role (12 months fixed term) with occasional travel to a
Society office for wider departmental meetings.
The role being advertised is a full time (35 hours per week) but applicants seeking a part-time role that can work a minimum of 21 hours per week, who have suitable data protection experience in a second line advisory role, may also apply.
The Information
Governance team are the champions of Data Protection and Information Governance
within Alzheimer's Society. The team’s key objective is to enable all areas to
use information appropriately whilst achieving the Society’s overall aim of
creating a world without dementia. The Senior Information Governance Officer
will support the wider Information Governance team in achieving this objective.
They will be
the first point of contact in the Society for data protection, information
governance and records management questions, providing advice and guidance as
appropriate to ensure the safe and legal processing of information. These
queries will be from across the Society and could be in relation to service
delivery, fundraising, campaigns, IT, volunteering or employment matters.
The Senior IG and
Records Management Officer will also handle personal data breaches and identify
remedial actions, compile relevant management information and reports on
Information Governance matters for senior management audiences, manage rights
requests, review data protection elements in contracts, conduct Data Protection
Impact Assessments and support the Information Governance Manager to develop,
deliver and maintain learning resources and opportunities for Society
colleagues to help ensure information is processed safely and legally whilst
enabling the Society to operate effectively.
The
Senior Information Governance and Records Management Officer will also help the
IG team to continue to develop and implement a process framework, standards and
procedures for the management of organisational records (hard copy and
electronic) in compliance with applicable legislation and standards - helping
the Information Governance team to establish a culture of effective records
management and support the Society in measuring and maintaining the quality of
its records.
About you
We are looking for a motivated individual with experience
in a second line data protection role looking for a fresh challenge and wishing
to make a real difference to the lives of people affected by dementia.
You must have expert knowledge of privacy legislation
and regulations (including the UK General Data Protection regulation (GDPR) and
Data Protection Act 2018 (DPA)) AND have experience of applying that
expert knowledge within a data protection or information governance role to
advise colleagues across an organisation on how to comply with privacy
requirements across a range of situations:
·
experience of
working in an information governance / data protection advisory role providing
expert data protection advice across multiple elements including personal data
breaches
·
experience of
working in an information governance / data protection or privacy rights role
managing GDPR rights requests including subject access requests, including
review, redaction and response to requestors
·
experience of creating
records management procedures and processes and how to successfully embed them
into working practices.
Applicants who do not have experience of advising on
data protection matters or managing rights requests, only experience of
complying with legal and regulatory requirements on these themes, will not be
selected for interview.
Working in a fast paced and responsive environment,
you will possess good time management and problem-solving skills. Good
communication skills are a must as you will be engaging with colleagues at all
levels across the Society. With your strong attention to detail, pro-active
nature and ability to build successful relationships, you will quickly
establish yourself as a key member of our team.
Industry recognised qualifications such as Practitioner
Certificates in Data Protection (such as IAPP CIPP/E, CIPP/T or CIPM) or
Records Management are preferable but not essential.
Interviews
will be held w/c 17 August and will include an assessment. Information about
the assessment will be sent to candidates with the invitation to interview.