This role sits within the Information Governance team, in the Practice and Compliance division. It is a home based role (12 months fixed term) with occasional travael to a Society office for wider departmental meetings.
The role being advertised is a full time (35 hours per week) but applicants seeking a part-time role that can work a minimum of 21 hours per week, who have suitable data protection experience in a second line advisory role, may also apply.
The Information Governance team are the champions of Data Protection and Information Governance within Alzheimer's Society. The team’s key objective is to enable all areas to use information appropriately whilst achieving the Society’s overall aim of creating a world without dementia. The Senior Information Governance Officer will support the wider Information Governance team in achieving this objective.
They will be the first point of contact in the Society for data protection, information governance and records management questions, providing advice and guidance as appropriate to ensure the safe and legal processing of information. These queries will be from across the Society and could be in relation to service delivery, fundraising, campaigns, IT, volunteering or employment matters.
The Senior IG and Records Management Officer will also handle personal data breaches and identify remedial actions, compile relevant management information and reports on Information Governance matters for senior management audiences, manage rights requests, review data protection elements in contracts, conduct Data Protection Impact Assessments and support the Information Governance Manager to develop, deliver and maintain learning resources and opportunities for Society colleagues to help ensure information is processed safely and legally whilst enabling the Society to operate effectively.
The Senior Information Governance and Records Management Officer will also help the IG team to continue to develop and implement a process framework, standards and procedures for the management of organisational records (hard copy and electronic) in compliance with applicable legislation and standards - helping the Information Governance team to establish a culture of effective records management and support the Society in measuring and maintaining the quality of its records.
About you
We are looking for a motivated individual with experience in a second line data protection role looking for a fresh challenge and wishing to make a real difference to the lives of people affected by dementia.
You must have expert knowledge of privacy legislation and regulations (including the UK General Data Protection regulation (GDPR) and Data Protection Act 2018 (DPA)) AND have experience of applying that expert knowledge within a data protection or information governance role to advise colleagues across an organisation on how to comply with privacy requirements across a range of situations:
- experience of working in an information governance / data protection advisory role providing expert data protection advice across multiple elements including personal data breaches
- experience of working in an information governance / data protection or privacy rights role managing GDPR rights requests including subject access requests, including review, redaction and response to requestors
- experience of creating records management procedures and processes and how to successfully embed them into working practices.
Applicants who do not have experience of advising on data protection matters or managing rights requests, only experience of complying with legal and regulatory requirements on these themes, will not be selected for interview.
Working in a fast paced and responsive environment, you will possess good time management and problem-solving skills. Good communication skills are a must as you will be engaging with colleagues at all levels across the Society. With your strong attention to detail, pro-active nature and ability to build successful relationships, you will quickly establish yourself as a key member of our team.
Industry recognised qualifications such as Practitioner Certificates in Data Protection (such as IAPP CIPP/E, CIPP/T or CIPM) or Records Management are preferable but not essential.
Interviews will be held w/c 17 August and will include an assessment. Information about the assessment will be sent to candidates with the invitation to interview.