Package Description
At Avery Healthcare, our commitment to exceptional care begins with the people who deliver it. We champion our teams, invest in their growth, and create an environment where professionalism, respect, and purpose guide everything we do. We are now seeking an experienced Subject Access Request Administrator to join our central support team based in Northampton. Working in close partnership with our National Data Protection Officer, you will play a vital role in safeguarding the rights, privacy, and dignity of our residents, colleagues, and families.
Main duties of the job
As a Subject Access Request Administrator at Avery Healthcare, the role focuses on managing and coordinating SARs ensuring compliance with UK GDPR and the Data Protection Act 2018. It involves close collaboration with Avery's National Data Protection Officer and various stakeholders, including care homes, regional teams, and external requestors.
Job responsibilities
Key responsibilities include gathering and reviewing information, applying redactions, maintaining audit trails, and supporting stakeholders with guidance.
- SAR Coordination – Receive, log, and acknowledge SARs and data rights requests; manage the end‑to‑end process in collaboration with the National DPO; ensure statutory deadlines are met.
- Information Gathering – Work closely with care homes, regional teams, and support functions to obtain all relevant documentation.
- Document Review & Redaction – Review care records, HR files, incident reports, and other sensitive materials; apply precise redaction to protect third‑party and confidential information; ensure disclosures are proportionate and compliant.
- Compliance & Governance – Maintain accurate audit trails; ensure all activity aligns with UK GDPR, the Data Protection Act 2018, and Avery policies; elevate complex or high‑risk cases appropriately.
- Stakeholder Support – Provide clear guidance to care home teams on documentation standards and information provision; respond professionally to requestors, families, and external bodies.
- Continuous Improvement – Support enhancements to SAR processes, templates, and tracking systems; contribute to internal audits and compliance reporting; promote data‑protection best practice across the organisation.
About You
You’ll be someone who naturally lives our values: caring, supportive, honest, respectful, and accountable, and brings them into everything you do.
Skills & Experience
- Experience managing SARs or working within data protection / information governance.
- Strong understanding of UK GDPR and the Data Protection Act 2018.
- Experience handling sensitive personal data, ideally within a healthcare or carehome environment.
- Excellent attention to detail, particularly in document review and redaction.
- Strong organisational skills with the ability to manage competing deadlines.
- Confident communicator with the ability to engage professionally at all levels.
Personal Attributes
- Professional, discreet, and trustworthy.
- Methodical and highly organised.
- Able to work independently and prioritise effectively.
- Calm and resilient when managing complex or sensitive cases.
Desirable
- Experience in a healthcare or carehome setting.
- Awareness of CQC expectations relating to record‑keeping and data protection.
About Avery
Avery Healthcare is one of the UK's leading providers of luxury elderly care, with over 100 homes nationwide. Guided by our vision of creating meaningful lives together, we foster a culture where colleagues feel supported, empowered, and valued. We believe in delivering care with dignity, purpose, and compassion and in creating a workplace where people genuinely enjoy being part of the team.
Additional Information
- A DBS Disclosure is required (funded by Avery Healthcare).
- Proof of eligibility to work in the UK is essential.
- Occasional travel to care homes or other Avery sites may be required.
- This advert may close early depending on application volume.
Person Specification
Experience managing SARs or working within data protection/information governance. Strong understanding of UK GDPR and the Data Protection Act 2018. Experience handling sensitive personal data, ideally within a healthcare or care‑home environment.
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.