Data Protection & Governance Officer Location: Belfast Salary: £54,090 Contract: Interim - up to 12 months Working Pattern: Hybrid About the Opportunity A respected public sector organisation is seeking an experienced Data Protection & Governance professional to provide expert support across data protection, information standards, FOI, and corporate governance functions. This is a senior interim appointment offering a high-impact role within a complex and high-profile environment. Main Duties Data Protection Inform and advise staff about the requirements of the UK GDPR and the Data Protection Act 2018 and help them to understand the practical implications for their business areas and the risks associated with data processing operations, taking into account the nature, scope, context and purposes of the processing. Monitor and ensure on-going compliance with the requirements of the UK GDPR and the Data Protection Act 2018, through for example, conducting data protection audits and requiring records of all data processing activities to be maintained. Assist and advise business areas and Information Asset Owners ('IAOs') in relation to the management of internal data protection activities. Raise awareness of data protection issues and promote a positive data protection culture. Assist business areas in deciding if a Data Protection Impact Assessment (DPIA) should be undertaken and assist with conducting DPIAs. Review and update the data protection, governance and information assurance policies and provide training to staff as required. Develop and maintain relationships with other DPOs across the wider public sector to share knowledge and best practices. Advise upon investigations and notifications once a data breach or other data incident has occurred. Information Standards and FOI Take forward an information management systems review and the implementation of a new system. Manage and quality assure the administration of responses to and disclosure of all FOI/DP requests in accordance with statutory deadlines and advise on more complex requests. Oversee the administration of FOI/DP appeals and provide advice to panels. Manage the Retention and Disposal Schedule and liaise with PRONI. Attend the Information Security Group and advise on appropriate information security measures. Governance Provide/manage administrative support to the Audit and Risk Committee (ACARC). Draft the ACARC Annual Report and assist with the self-assessment of ACARC. Facilitate the quarterly review and update of the Corporate Risk Register, in conjunction with SMT. Assist Directorate Management Teams with risk register updates. Facilitate SMT reviews and identify emerging "risk clusters". Update and develop the Corporate Governance Framework and Risk Management Strategy. Complete fraud, cyber security, information risk and other relevant checklists, monitoring action plans. Monitor new or updated corporate governance guidance and identify potential policy updates. General Duties Fulfil the role in an independent manner. Lead, manage and develop a small team. Develop and deliver training on data protection, UK GDPR, information management, governance and risk management. Implement continuous improvement programmes. Comply with all staff policies and procedures. Carry out other reasonable duties as required. Essential Criteria A thorough knowledge and understanding of the relevant law, regulations and guidance relating to data protection and freedom of information. AND An understanding of organisational governance and risk management policies and procedures. AND A primary degree, minimum 2:2 classification, in any subject and a relevant qualification in data protection, for example, Certified Information Privacy Professional ('CIPP'), BCS in Data Protection to Practitioner level, EU GDPR Practitioner or equivalent. AND At least two years' experience of the following: Successfully leading a data protection and information management service and the effective and efficient delivery of specific outcomes; Advising at a senior level* on either: information standards and data protection policies and procedures or governance and risk management policies and procedures. Using the standards that underpin good information management, ensuring that organisational standards and legislative requirements are met and that a robust information system and supporting policies are maintained. *Senior level is defined as a Project Board, Director, Head of Business, NICS Grade 7 or company board member or equivalent. OR A thorough knowledge and understanding of the relevant law, regulations and guidance relating to data protection and freedom of information. AND A comprehensive understanding of organisational governance and risk management policies and procedures. AND A relevant qualification in data protection for example Certified Information Privacy Professional ('CIPP'), BCS in Data Protection to Practitioner level, EU GDPR Practitioner or equivalent. AND At least four years' experience as listed at points a) - c) above. For more information, please contact Ethan Boylan today. IND04 Skills: Data Protection Governance Legislation GDPR Benefits: Work From Home