Head of Information Governance and Data Protection

6 days ago


Cardiff, Cardiff, United Kingdom Veezu Full time
Job Description

SUMMARY

The Head of Information Governance and Data Protection Officer (DPO) role is the professional lead for Information Governance at Veezu Group. The role will provide expert Information Governance advice and guidance to the Veezu management team and key partners; to ensure that all parties are processing information in accordance with legislation, guidance, while meeting their legal and regulatory obligations.

The Data Protection Officer is an essential role in facilitating 'accountability' and the organisations' ability to demonstrate ongoing compliance with GDPR, where the DPO performs another role or roles there must be no conflict of interest. While this role reports to the IT Director, direct access to the Veezu Executive Board is assured in the fulfilment of their DPO duties. Ensuring that the DPO can effectively carry out their responsibilities and have their concerns and recommendations heard at the highest level of the organisation.

ROLE DUTIES AND EXPERIENCE REQUIRED

  • Act as the appointed statutory Data Protection Officer as defined by the General Data
  • Protection Regulation 2016 for Veezu Group.
  • Be the lead source of information and expertise on information governance and data protection, including but not limited to: The Data Protection Act 1998, The UK and EU General Data Protection Regulation, ISO27001 Information Security Standard, PCI-DSS Card Payment regulation, The Freedom of Information Act 2000, Environmental Information Regulations 2004, The Common Law Duty of Confidence, The Computer Misuse Act, The Office of the Information Commissioner and its associated powers, Information Commissioner Directives/Guidance
  • Lead the development of strategies, policies, and guidelines that ensure organisational compliance with information governance and data protection regulations across all departments. This will require making decisions in unprecedented situations.
  • Co-operate with and be the first point of contact for the Information Commissioner.
  • Be available to be contacted directly by data subjects.
  • Develop Information Governance policies that address: Organisational accountability, DPO reporting arrangements, Timely involvement of the DPO in all data protection issues, Compliance assurance: privacy by design/default, When and where data protection impact assessments are required and subsequent reporting on performance, The DPO's role in incident management
  • Have sufficient understanding of the processing operations carried out, as well as the information systems and data security and data protection needs of the organisation.
  • Monitor the effectiveness of policies and procedures and the organisations' compliance with them through a proactive program of audit and review, in conjunction with all functions across the operating model and other stakeholders and bodies.
  • Have senior responsibility for the development of a robust Information Risk Assurance function which includes Cyber Security, System Failure and GDPR.
  • Provide a single point of knowledge to senior management and staff with clear policies and procedures that ensure Veezu meets both its statutory and legal obligations.
  • Maintain an awareness of evolving legislation and national guidance relating to all areas of responsibilities.
  • Promote an effective information governance and risk culture that embeds information governance across the Veezu organisation.
  • Lead on the development of training, awareness and communications programmes aimed at
  • informing and advising Veezu staff (at all levels) to promote understanding of their obligations to comply with information governance requirements.
  • Proactively disseminate complex and contentious information governance principles to a wide audience through regular communications briefings using e-mail, intranet and bulletins and other communications media, where there may be resistance to compliance.
  • Ensure the Data Security and Protection Toolkit (DSPT) and other IG related audit submissions are made correctly, within timescales and are signed off by the Veezu Exec/Board where applicable and that evidence is available to support the attainment levels submitted. This includes overseeing the delivery of action plans and improvement programmes to support compliance with legislation and national Information Governance requirements. This will require liaison with senior managers throughout the organisation.
  • Develop/enforce organisational trigger-points for mandatory input from the DPO providing advice on Data Protection Impact Assessments (DPIA) to offer a balanced independent review of activities such as business improvements, system requests for change, large scale business development and introduction of new systems and services, to: Give consideration of the business needs against GDPR and other information governance / security requirements, Provision of advice and guidance on changes required to meet/maintain GDPR/IG compliance, Identification of system change requirements to support GDPR/IG compliance, Consult with the Information Commissioner's Office (ICO) where proposed processing poses a high risk in the absence of proposed mitigations, Provide expert input for commercial contracts, invitations to tender, etc, whilst ensuring robust information security and governance is maintained.
  • Lead and support specific groups such as Information Asset Owners, System Administrators through effective networking structures sharing of relevant experience and provision of appropriate advice.
  • Ensure information breaches (e.g., security, confidentiality) including serious incidents and breaches are investigated and where necessary escalated in a professional manner and reported on in accordance with process and procedure.
  • Provide guidance on operational and procedural improvements arising from lessons learned.
  • Be organisations expert on information sharing, ensuring organisations approaches are compliant with law and best practice.
  • Proactively and strategically ensure organisations are able to share information effectively and appropriately where multi agency or partnership working exists.
  • Take the lead in developing, managing and reviewing information sharing protocols and third-party access and Data Processing Agreements with other organisations including local authorities and voluntary organisations.

PERSONAL COMPETENCIES

  • Planning; exhibit exceptional organisational acumen.
  • Communication Proficiency; possess the ability to articulate thoughts with clarity, at all levels of the organisation.
  • Proactive Adaptability; embody a proactive ethos, taking initiative when appropriate, pinpointing areas for improvement or transformation.
  • Collaborative Spirit; commit to the broader organisations vision, actively collaborating to achieve overarching goals.
  • Approach; take a calm and collegial approach when working with the team and wider business.
  • Result-Oriented Approach; Display intrinsic motivation and an aptitude to autonomously define, manage, and achieve key milestones and objectives.


  • Cardiff, Cardiff, United Kingdom Veezu Full time

    SUMMARYThe Head of Information Governance and Data Protection Officer (DPO) role is the professional lead for Information Governance at Veezu Group. The role will provide expert Information Governance advice and guidance to the Veezu management team and key partners; to ensure that all parties are processing information in accordance with legislation,...


  • Cardiff, Cardiff, United Kingdom Cardiff Council Full time

    About The ServiceAn exciting opportunity has become available within the Council's Information Governance Team supporting the delivery of the Council's Information Governance practices and helping us build ready for the next phase of our response to delivering services to the citizens we are here to help.Come and join a growing team and enhance your...


  • Cardiff, Cardiff, United Kingdom Cardiff Council Full time

    About The ServiceThe Resources Directorate is responsible for a wide range of corporate services, serving the whole council, and plays a vital role in supporting the operational Directorates in the delivery of their services.The Information Governance Section is based within the Resources Directorate and supports the Council's services, externally contracted...


  • Cardiff, Cardiff, United Kingdom Admiral Insurance Plc Full time

    Data Protection Executive Position at Admiral Group PlcThe Data Protection and Privacy (DPP) Department, under the leadership of the Head of Group Privacy, is seeking a curious and inquisitive Data Protection Executive to provide guidance and assurance to ensure compliance with Data Protection responsibilities.Joining our experienced team during the...


  • Cardiff, Cardiff, United Kingdom Identify Solutions Full time

    Information Security Manager (Data Assurance & Protection)Largely remote (ideally 1 day a month in office) - CardiffUp to £75,000 annual salary + a competitive benefits packageAre you an Information security professional who is interested in the next step up? Are you looking to have a positive impact and are interested in working for a flexible company...


  • Cardiff, Cardiff, United Kingdom Cardiff and Vale University Health Board Full time

    The Head of Corporate Governance is a critical role in the organisation and is responsible for leading on and coordinating the development of strategies and policies to support governance of the University Health Board (UHB), in particular;Risk management, compliance with legislation and other mandatory requirements, so that the UHB meets the highest...


  • Cardiff, Cardiff, United Kingdom Yolk Recruitment Ltd Full time

    Location:Cardiff Sector:Technology & Digital Job type:Permanent Salary:Up to £ per annum Contact:Jack Brewster Job ref:BBBH31690_ Published:7 minutes ago Expiry date:15 March 2023Data Governance Lead | Hybrid | Cardiff | Up to £65,000Yolk Recruitment is working with a long-standing financial institution who are looking to hire an experienced and motivated...


  • Cardiff, Cardiff, United Kingdom Principality Building Society Full time

    Data Governance Lead:We're looking for an experienced and ambitious Data Governance professional with proven leadership experience to lead a team in the development and delivery of data management and governance policies, frameworks and services to business stakeholders and projects. You will ensure that Principality's data is owned, understood, and cared...


  • Cardiff, Cardiff, United Kingdom Cyngor CaerdyddCardiff Council Full time

    An exciting opportunity has become available within the Council's Information Governance Team supporting the delivery of the Council's Information Governance practices and helping us build ready for the next phase of our response to delivering services to the citizens we are here to help. Come and join a growing team and enhance your development by working...


  • Cardiff, Cardiff, United Kingdom Admiral Full time

    Closing date20/06/2024The Data Protection and Privacy (DPP) Department led by the Head of Group Privacy are keen to recruit an inquisitive and curious Data Protection Executive to help provide guidance and assurance to the business on compliance with its Data Protection responsibilities.This is an exciting time to join our experienced and supportive team...


  • Cardiff, Cardiff, United Kingdom Admiral Full time

    Closing date07/06/2024An exciting opportunity has arisen in our Privacy & Data Protection Team. We're looking for a highly analytical and creative individual who enjoys thinking outside the box, with a passion to learn new skillsAt Admiral Group we have to ensure that we keep valuing, retaining, developing and supporting our Privacy & Data Protection...

  • Data Protection Lead

    2 months ago


    Cardiff, Cardiff, United Kingdom Heat Recruitment Ltd Full time

    Compliance opportunity as a Date Protection Lead working for a law firm based in central Manchester. Working within the Risk & Compliance team you will be primarily responsible for data protection and privacy law. Role duties:Maintaining data protection, information security, cyber security policies, information asset register, and records of processing....

  • Data Protection Lead

    3 weeks ago


    Cardiff, Cardiff, United Kingdom Heat Recruitment Ltd Full time

    Compliance opportunity as a Date Protection Lead working for a law firm based in central Manchester. Working within the Risk & Compliance team you will be primarily responsible for data protection and privacy law. Role duties:Maintaining data protection, information security, cyber security policies, information asset register, and records of processing....


  • Cardiff, Cardiff, United Kingdom Admiral Insurance Plc Full time

    An exciting opportunity has arisen in our Privacy & Data Protection Team. We're looking for a highly analytical and creative individual who enjoys thinking outside the box, with a passion to learn new skills At Admiral Group we have to ensure that we keep valuing, retaining, developing and supporting our Privacy & Data Protection governance, policies,...


  • Cardiff, Cardiff, United Kingdom Perrett Laver Full time

    Cardiff University was established in 1883. Our motto, Gwirionedd, Undod a Chytgord - 'Truth, Unity and Concord' - sets out our founding commitment to work together to make a positive and lasting difference to our communities and continues to express our commitment today. We are one of the largest universities in the UK and a member of the Russell Group. Our...

  • Data Architect

    6 days ago


    Cardiff, Cardiff, United Kingdom Legal & General Full time

    Company Description Life can sometimes be unpredictable, and it pays to plan ahead. Our aim at Legal & General Retail is to help our customers plan for the unexpected, achieve financial security for their tomorrow, and protect everything that's important to them. To better understand our customers and meet their needs, we've brought our protection,...

  • Data Architect

    6 days ago


    Cardiff, Cardiff, United Kingdom Legal & General Resources Limited Full time

    We are looking for an experienced Data Architect who will own, and be responsible for the data architecture for analytical solutions within the Retail Division. The role holder will be working with strategic stakeholders, business representatives and subject matter experts, to develop and evolve the Retail Data Strategy in line the Business Strategy. The...

  • Data Architect

    6 days ago


    Cardiff, Cardiff, United Kingdom Legal & General Full time

    Job Description Life can sometimes be unpredictable, and it pays to plan ahead. Our aim at Legal & General Retail is to help our customers plan for the unexpected, achieve financial security for their tomorrow, and protect everything that's important to them. To better understand our customers and meet their needs, we've brought our protection, retirement...


  • Cardiff, Cardiff, United Kingdom Ministry of Justice Full time £54,358 - £61,585

    Building/Site LAA William Morgan House FLR11, CF10 1EP, WALES OFFICE LONDON, SW1A 2NP Post Type Permanent Working Pattern Full Time Role Type Policy Office of the Secretary of State for Wales Job Description for Head of Energy and Transport Job Title: Head of Energy and Transport Contract: Permanent About the Office of the Secretary of State for Wales...

  • Head of Data

    6 days ago


    Cardiff, Cardiff, United Kingdom Harnham Full time

    INFO SALARY:- £ £115000LOCATIONCardiff JOB TYPE PermanentTitle: Head of Data - CardiffLocation: Cardiff (2/3 days per week)Salary: Up to £115,000 per annumTHE ORGANISATION:Join an exciting and well-funded tech organisation based in Cardiff, poised to disrupt the transportation industry with a customer-centric approach. Having recently received significant...