Data Governance Manager
Location: Pocklington Head Office, East Yorkshire
Salary: £37,500–£42,500 per annum, dependent on experience
Job Type: Full-Time, Permanent
Monday - Friday 09:00 - 17:30 40 hours per week
Working Arrangement: Office Based Only
Bond International is a major distributor of tyres in the UK, operating a nationwide B2B tyre distribution service and acting as a dedicated third-party logistics provider to some of the world’s leading tyre brands.
We are looking to appoint a Data Governance Manager based at our Head Office in Pocklington.
The role is responsible for developing and maintaining our approach to data governance, data protection and information management. The successful candidate will help establish and maintain the policies, controls and culture required to ensure company, customer, supplier and employee data is appropriately protected and managed throughout the organisation.
The role will also take responsibility for our data protection framework and, where appropriate, fulfil the responsibilities of the company’s Data Protection Officer (DPO).
Key Responsibilities
As Data Governance Manager, your responsibilities will include:
- Acting as the principal point of contact within the business for data protection and data governance matters.
- Managing and coordinating Subject Access Requests (SARs) and other data subject rights requests.
- Monitoring compliance with UK GDPR, the Data Protection Act 2018 and other applicable data protection requirements.
- Providing advice and guidance to management and employees regarding their data protection responsibilities.
- Supporting and advising the business on Data Protection Impact Assessments (DPIAs) and data-related risk assessments.
- Maintaining, auditing and developing the company’s Data Governance Policies.
- Supporting and maintaining the company’s ISO 27001 compliance framework.
- Working closely with IT, HR, Legal and operational departments to identify and manage data risks.
- Reviewing how data is collected, stored, accessed, retained, transferred and shared across the business.
- Promoting a strong culture of data security, compliance and responsible data use throughout the organisation.
Data Access, Security & Loss Prevention
A key part of the role will be ensuring that access to company information is appropriate, controlled and regularly reviewed.
Working closely with IT and departmental management, responsibilities will include:
- Establishing and maintaining a formal process for reviewing user access rights and security groups across company systems.
- Ensuring employees only have access to the information, reports, applications and systems required for their role.
- Conducting regular reviews of access to reporting platforms, shared folders, SharePoint, OneDrive, shared mailboxes and other company systems.
- Reviewing access arrangements across individual departments and ensuring appropriate controls are applied consistently throughout the business.
- Establishing controls to reduce the risk of unauthorised extraction, transfer or disclosure of company information.
- Working with IT to develop appropriate Data Loss Prevention (DLP) controls.
- Reviewing and developing controls around the emailing of commercially sensitive information to personal or unauthorised external email addresses.
- Establishing appropriate monitoring and controls for the use of removable storage and memory devices.
- Reviewing controls around access to company systems from personal, unauthorised or unknown devices.
- Supporting the development of appropriate controls for company laptops, mobile devices and other authorised equipment.
- Reviewing printing requirements and implementing appropriate controls, monitoring and traceability where commercially sensitive information may be printed.
- Developing appropriate controls around downloading, exporting, forwarding and printing sensitive business reports.
- Reviewing the use of messaging applications and personal mobile devices where company or customer information may be shared.
- Working with HR to ensure confidentiality requirements and appropriate contractual protections support the company’s wider data governance framework.
- Investigating suspected or attempted breaches of company data governance policies and escalating matters appropriately.
Data Governance Development
A significant part of the role will involve developing Bond International’s data governance framework. Key projects are expected to include:
- Establishing and maintaining a comprehensive Company Data Register.
- Developing a formal Data Classification Framework, categorising information according to sensitivity and business risk.
- Establishing clear ownership of data and identifying who should be authorised to access different categories of information.
- Working with IT to introduce appropriate technical controls for data classification and protection.
- Establishing and implementing data retention and deletion policies.
- Developing processes for regular Data Risk Reviews across departments and business systems.
- Ensuring data governance and data availability are appropriately considered within Business Continuity and Disaster Recovery planning.
- Reviewing how data is stored, accessed, transferred and shared throughout the organisation.
- Establishing appropriate governance controls around third-party systems and cloud-based services.
- Developing a structured process for reviewing data access when employees join, change roles or leave the organisation.
- Monitoring changes in legislation, technology and best practice and recommending improvements where appropriate.
Audit, Monitoring & Reporting
The Data Governance Manager will establish a regular programme of monitoring and audit across the business, including:
- Conducting scheduled audits of data access permissions and governance controls.
- Identifying excessive, inappropriate or unnecessary access to company information.
- Monitoring compliance with data governance policies and agreed security controls.
- Reviewing data-related incidents, attempted breaches and unusual activity.
- Working with IT to ensure appropriate monitoring and reporting is in place for potentially unauthorised access or movement of information.
- Tracking agreed actions and ensuring identified weaknesses are addressed.
- Producing a monthly Data Governance report for senior management and the Board, highlighting key risks, incidents, audit findings, outstanding actions and areas requiring improvement.
- Providing recommendations to senior management regarding improvements to data security and governance arrangements.
Essential Qualifications and Experience
The successful candidate should have:
- A recognised professional qualification in data protection or privacy, such as the BCS Practitioner Certificate in Data Protection, IAPP CIPP/E, or an equivalent recognised professional qualification.
- Strong working knowledge of UK GDPR and the Data Protection Act 2018.
- Previous professional experience in data governance, data protection, information governance, information security or a closely related field.
- Practical experience of managing data protection compliance, including SARs, DPIAs, privacy risks and data governance policies.
- Experience of conducting data access reviews, governance audits, compliance reviews or risk assessments.
- An understanding of role-based access controls, security groups and the principle of least privilege.
- An understanding of Data Loss Prevention, information classification and data leakage risks.
- Experience of working with or supporting an ISO 27001 Information Security Management System.
- Strong written and verbal communication skills, with the ability to explain regulatory and technical matters to both employees and senior management.
- Strong organisational and project management skills.
- The ability to work independently and confidently challenge practices where they create data protection, security or compliance risks.
Desirable Qualifications and Experience
The following would be advantageous:
- An ISO/IEC 27001 qualification, such as Internal Auditor, Lead Implementer, Lead Auditor or equivalent.
- A relevant degree or professional qualification in data protection, information governance, information security, cyber security, law, risk or compliance.
- Experience of the ISO 27001 framework and providing operational support to achieving and maintaining certification.
- Previous experience acting as, or supporting, a Data Protection Officer.
- Experience implementing data classification, retention management or Data Loss Prevention controls.
- Experience with role-based access controls and periodic user-access reviews.
- Experience within a large, multi-site organisation.
- Familiarity with Microsoft 365 security, compliance and data governance tools, including areas such as SharePoint, OneDrive and Microsoft Purview.
About You
We are looking for someone who can combine strong regulatory knowledge with a practical and commercial approach.
You will be confident working across different departments, comfortable engaging with senior management and able to balance regulatory and security requirements with the needs of a fast-moving commercial business.
You will need to be naturally inquisitive and comfortable challenging why individuals or departments have access to particular information, rather than simply accepting historic access arrangements.
You will be proactive, organised and capable of taking ownership of data governance activity across the organisation.
The Opportunity
This is an opportunity to take ownership of an increasingly important area within a large and growing UK business.
The successful candidate will have the opportunity to shape Bond International’s future data governance strategy, working across the organisation to establish and improve processes and controls as our systems and data requirements continue to develop.
The position will have exposure to senior management and work closely with IT, HR, Legal and operational teams across the business.
Salary: £37,500–£42,500 per annum, dependent on experience.
This role is based at Bond International’s Head Office in Pocklington and is an office-based position. Remote or hybrid working is not available.
Pay: £37,500.00-£42,500.00 per year
Benefits:
Application question(s):
- Do you have practical experience of working with UK GDPR and the Data Protection Act 2018?
- Have you personally managed or coordinated Subject Access Requests (SARs)?
- Do you have experience completing or advising on Data Protection Impact Assessments (DPIAs)?
- Do you have experience carrying out data access reviews, governance audits, compliance reviews or risk assessments?
- Do you hold an ISO/IEC 27001 qualification, such as Internal Auditor, Lead Implementer or Lead Auditor?
- Do you have experience using Microsoft 365 security and compliance tools, particularly SharePoint, OneDrive or Microsoft Purview?
- Have you worked with an ISO 27001 Information Security Management System (ISMS)? (desirable but not essential)
Experience:
- Data protection: 1 year (required)
Licence/Certification:
- IAPP CIPP/E or equivalent? (preferred)
Work Location: In person