Level 4 -
Provide regulatory and technical advice providing assurance to key stakeholders and regulators.
Reference: OCC0967
Status:
SOC 2020 sub unit groups:
Greater Manchester Combined Authority Transport for Greater Manchester Magairports Royal London Provident Europcar Education Wise Cygnet Health Cheshire Police Royal Mail Bolton Council Istorm solutions Rentokil Train with premier The Medicines and Healthcare products Regulatory Agency Royal Wolverhampton NHS Trust Luton Borough Council Virgin Health Care The Specialist Hub BJM Consultancy
This occupation is found in organisations of all sizes across all sectors where personal and commercial data is processed. Data protection and information governance practitioners work in varied environments including in an office, onsite, or remotely.
The broad purpose of the occupation is to provide regulatory and technical advice and guidance providing assurance to key stakeholders and regulators of compliance with information governance (IG) and data protection (DP) requirements. Organisations must comply with information governance legislation to protect the confidentiality, integrity and availability of its information assets. The data protection and information governance practitioner (DP&IGP) will contribute to the annual work plan and assist in the planning and organisation of IG, ethics and DP activities. The DP&IGP will also provide advice and training with regard to improving data management and will support the senior team in the development and delivery of operational and strategic information requirements. The role requires work to be undertaken under explicit and legally defined timeframes (for example, data breaches must be reported within 72 hours and Data Subject Access Requests must be fulfilled within one calendar month).
In their daily work, an employee in this occupation interacts with a range of internal stakeholders including members of their own team, other departments such as IT, legal, HR, marketing, senior management and the board of directors. They also interact with external stakeholders such as members of the public, customers, Supervisory Authorities, The Information Commissioner’s Office (ICO), technology vendors, academics, industry bodies, external legal departments, human rights organisations, consumer rights organisations and law enforcement.
An employee in this occupation will be responsible for assisting the organisation in its compliance with information governance and data protection best practice and associated laws and regulations. They will oversee and manage the day-to-day coordination of information requests such as data subject rights, freedom of information and environmental information regulations. In addition, they will oversee compliance with Information and Records Management for example the development and maintenance of retention schedules. They assist in the maintenance and administration of the organisations’ information and governance framework such as corporate information management, records of processing activity, developing privacy notices, conducting information audits and data breach investigations. On occasion the DP&IGP supports projects through ensuring privacy by design and default. They may also conduct a data protection impact assessment (DPIA) and third-party supplier due diligence. They analyse data and develop briefings for senior leadership on data protection and information governance controls. They may investigate information governance complaints and incidents from internal or external stakeholders. This role will work on their own and in a range of team settings. They work within agreed budgets and available resources. The DP&IGP work without high levels of supervision, usually reporting to senior stakeholders. They may occasionally be responsible for decision making, but more often will guide or influence the decisions of others.
Greater Manchester Combined Authority Transport for Greater Manchester Magairports Royal London Provident Europcar Education Wise Cygnet Health Cheshire Police Royal Mail Bolton Council Istorm solutions Rentokil Train with premier The Medicines and Healthcare products Regulatory Agency Royal Wolverhampton NHS Trust Luton Borough Council Virgin Health Care The Specialist Hub BJM Consultancy
Support senior management by contributing to the development of policies and guidance to ensure the organisation complies with its statutory and regulatory information governance (IG) and data protection (DP) responsibilities.
Work with internal stakeholders to review and maintain retention schedules, providing specialist support, advice and guidance to ensure appropriate disposal of data in compliance with legislation, regulation and good practice.
Develop and deliver in-house IG and DP training and awareness packages for all internal stakeholders such as IT, legal, HR, marketing, senior management and the board of directors.
Co-ordinate and support the organisation’s formal and documented record of processing activities in line with legislation, regulation and good practice.
Analyse data and present the outcomes to their key stakeholders on key risk, trend and performance indicators such as training, information requests, data breaches and records management.
Manage, co-ordinate and respond to information requests such as Freedom of Information (FOI), Individual Rights (IR), Environmental Information Regulation (EIR) and Data Protection (DP), within the statutory deadlines.
Undertake or assist in the completion of data protection impact assessments (DPIA) in order to identify and mitigate any potential risks to the organisation and continue to monitor the status of the risk.
Investigate reported personal data breaches providing advice and guidance to the organisation. Determine the need to escalate, as appropriate, to the Supervisory Authority.
Undertake routine and ad-hoc data protection audit and testing controls for both internal functions and third-party suppliers, producing audit reports for senior managers.
Provide day to day support and specialist advice across the organisation for all matters regarding IG and DP such as compliance with data protection principles.
Contribute to continuous improvement of systems and processes to ensure procedures, policies and guidance are updated in line with technology advancements, legislative and social changes.
Provide support for the completion and submission of industry or regulatory toolkits and control frameworks or standards.
This occupational progression map shows technical occupations that have transferable knowledge and skills.
In this map, the focused occupation is highlighted in yellow. The arrows indicate where transferable knowledge and skills exist between two occupations. This map shows some of the strongest progression links between the focused occupation and other occupations.
It is anticipated that individuals would be required to undertake further learning or training to progress to and from occupations. To find out more about an occupation featured in the progression map, including the learning options available, click the occupation.
Progression decisions have been reached by comparing the knowledge and skills statements between occupational standards, combined with individualised learner movement data.
Business and administration