Job summary
An exciting opportunity has arisen at University Hospitals of Northamptonshire (UHN) for a proactive and passionate Data Security & Protection (DSP) Team Leader to join our dynamic and fast-paced Data, Security & Protection Team.This is a pivotal role supporting both Northampton General Hospital and Kettering General Hospital as part of our Group approach to ensuring we meet our legal, statutory and regulatory obligations relating to the security and protection of personal data.
As our DSP Team Leader, you will play a key part in completion of the Group's DSP Toolkits and managing the DSP Team to ensure all areas of the DSP Toolkit framework are delivered.
Main duties of the job
Key responsibilities include:
- Leading the delivery of DSP workstreams and ensuring evidence is maintained for DSP Toolkit standards.
- Managing, triaging, and supporting investigation of DSP incidents via Datix.
- Delivering DSP training (classroom, small groups and virtual).
- Overseeing the completion and quality of Data Protection Impact Assessments (DPIAs).
- Supporting information sharing governance using the Information Sharing Gateway.
- Raising awareness of data security issues across the Group and promoting best practice.
- Acting as a key point of contact for colleagues seeking specialist DSP support.
About us
Please submit your application as soon as possible as we reserve the right to close adverts once we have received sufficient applications
Kettering General Hospital NHS Foundation Trust is on an exciting journey with all of our divisions committed to doing things better, with more efficiency as we update, modernise, and advance. We have also entered a Group Model with neighbouring Northampton General Hospital NHS Trust and become University Hospitals of Northamptonshire (UHN). As part of this collaborative approach, there may be a requirement for you to work across both the Kettering and Northampton hospital sites, depending on the needs of the service.
Our Excellence Values
- Compassion
- Accountability
- Respect
- Integrity
- Courage
We want to recruit the best people to deliver our services across UHN and help to unleash everyone's full potential.
UHN encourages applications from people who identify from all protected groups. We understand that we need to work with colleagues from diverse backgrounds and make sure the environment they work in is inclusive and collaborative.
We recognise the valuable contribution that the Armed Forces community make to our organisation. We have signed the Armed Forces Covenant and achieved Silver Award under the Armed Forces Employer Recognition Scheme.
We have active Networks that promote and support colleagues from all backgrounds. This ensures everyone feels supported and has a sense of belonging working for UHN.
Job description
Job responsibilities
The post holder will be the Data Security & ProtectionTeam Leader. In particular, the post holder will:
-
lead a range of audits which will check compliance with the DSP toolkit, research and development and incident management activities, developing improved systems and processes for data quality, data security and protection, dataintegrityand availability.
-
implement andmaintaincompliancewith relevant legislation, particularly the common law duty of confidentiality, the Data Protection Act 2018, the General Data Protection Regulation, the Computer Misuse Act 1990, the Human Rights Act 1998;
-
Implement the DSP training strategy forthe delivery of the Trusts IG training needs, ensuring that theGroupmeets the NHSD target for mandatory training, working in partnership with the Trusts Learning & Development service
-
Lead the collationofrelevant reports and information for complianceand performancereporting, inspections and internal assuranceensuring presentations articulate statistical,analyticaland complex reportingto Groupand Boardmandated meetings
-
Coordinate the Data Governance Group and Information Governance Group meetings, ensuring relevant reports, minutes actions and decisions are recorded, delegating tasks to the DSP administrator as appropriate
-
Ensure that the Information Sharing Gatewayis administeredasappropriateinrespect ofmaintainingsignificant assurance status across the group, being the lead and expert for use of the ISG, proposing recommendations for improvements to the national system for process,analyticsand reporting.
-
coordinatethe effective investigation ofany and allIG related incidents, working with the relevant manager in whose service the incident occurred, where necessary, to ensureappropriate actionhas been taken in relation to the incident;
-
To speak to staff,patientsand family members on the telephone as an escalation point for the DSP analyst,demonstratingunderstanding,compassionand knowledge in difficult,challengingand emotional circumstances.
-
maintaintheGroupInformation Asset register and data flow maps and, also, whereappropriate, provide training to Information Asset Owners and Administrators
-
tomaintaintheirspecialistknowledgein Data Protection Law and UK GDPR
-
update the Internet and Intranet pages for DSPasappropriate, ensuring it is up to date with pertinent adviceandguidance,includingapplicable FAQs and relevant legislation
Workforce
The Data Security & ProtectionTeam Leaderwill have line management responsibility for theDSP Team, ensuring that all staff have annual performance reviews, objectives andappraisalsin line withthe Groupobjectives, ensuringthey have the equipment necessary to fulfil their roles and the HR management tools are managed effectively.They will be an active role in recruitment,inductionand local training.
- Ensure anadequate skill mix andthat the office is appropriately managed
- To be the lead contact for HR queries relating to the team
Job description
Job responsibilities
The post holder will be the Data Security & ProtectionTeam Leader. In particular, the post holder will:
-
lead a range of audits which will check compliance with the DSP toolkit, research and development and incident management activities, developing improved systems and processes for data quality, data security and protection, dataintegrityand availability.
-
implement andmaintaincompliancewith relevant legislation, particularly the common law duty of confidentiality, the Data Protection Act 2018, the General Data Protection Regulation, the Computer Misuse Act 1990, the Human Rights Act 1998;
-
Implement the DSP training strategy forthe delivery of the Trusts IG training needs, ensuring that theGroupmeets the NHSD target for mandatory training, working in partnership with the Trusts Learning & Development service
-
Lead the collationofrelevant reports and information for complianceand performancereporting, inspections and internal assuranceensuring presentations articulate statistical,analyticaland complex reportingto Groupand Boardmandated meetings
-
Coordinate the Data Governance Group and Information Governance Group meetings, ensuring relevant reports, minutes actions and decisions are recorded, delegating tasks to the DSP administrator as appropriate
-
Ensure that the Information Sharing Gatewayis administeredasappropriateinrespect ofmaintainingsignificant assurance status across the group, being the lead and expert for use of the ISG, proposing recommendations for improvements to the national system for process,analyticsand reporting.
-
coordinatethe effective investigation ofany and allIG related incidents, working with the relevant manager in whose service the incident occurred, where necessary, to ensureappropriate actionhas been taken in relation to the incident;
-
To speak to staff,patientsand family members on the telephone as an escalation point for the DSP analyst,demonstratingunderstanding,compassionand knowledge in difficult,challengingand emotional circumstances.
-
maintaintheGroupInformation Asset register and data flow maps and, also, whereappropriate, provide training to Information Asset Owners and Administrators
-
tomaintaintheirspecialistknowledgein Data Protection Law and UK GDPR
-
update the Internet and Intranet pages for DSPasappropriate, ensuring it is up to date with pertinent adviceandguidance,includingapplicable FAQs and relevant legislation
Workforce
The Data Security & ProtectionTeam Leaderwill have line management responsibility for theDSP Team, ensuring that all staff have annual performance reviews, objectives andappraisalsin line withthe Groupobjectives, ensuringthey have the equipment necessary to fulfil their roles and the HR management tools are managed effectively.They will be an active role in recruitment,inductionand local training.
- Ensure anadequate skill mix andthat the office is appropriately managed
- To be the lead contact for HR queries relating to the team
Person Specification
Education, Training & Qualifications
Essential
- Educated to Degree level or equivalent level of education, training or experience.
- Significant experience in IG/DSP related activities across a Health and Care setting, or to have significant experience of working at a senior level in a public sector body
- Practitioner Qualification on Data Protection Act or the General Data Protection Regulation
Desirable
- ISO 17024- accredited GDPR Foundation and Practitioner certificate or evidence of further education in the application of ISO/IEC 27002:2013 and other associated standards.
- Evidence of continuing professional development.
Knowledge & Experience
Essential
- Working knowledge and understanding of the Data Security and Protection toolkit
- Substantial experience of practical implementation of the Data Protection Act
- Experience of working within NHS or similar large multi-disciplinary organisation in a similar role.
- Experience of staff / team leadership
- Experience of delivering awareness and training programmes for staff at ranging levels
Desirable
- Experience of working with internal and external auditors
- Experience of working with or supporting the implementation of security systems
Skills
Essential
- Developed interpersonal skills within groups and on a one-to-one basis
- Ability to mentor, teach and coach
- Ability to analyse and interpret situations where there are conflicting legal / ethical standards and service requirements, and develop an appropriate and justified response on behalf of the Trust.
- Ability to solve problems and use initiative to secure desired outcomes
- Ability to prioritise between competing demands and allocate resources accordingly
- Ability to manage time effectively and efficiently
Desirable
- Proven ability to undertake communication campaigns
- Negotiating and influencing skills
Key Competencies/ Personal Qualities & Attributes
Essential
- Passionate and committed to bring our Dedicated to Excellence values to life, improving the way we work with each other, particularly focusing on empowerment, equality diversity and inclusion of our staff, patients and service users
- High level of drive and determination
- Self-motivated to work on own initiative.
- Developed attention to detail and accuracy
Desirable
- Must be able to understand the needs of patients and deal with all contacts in a sensitive manner
Person Specification
Education, Training & Qualifications
Essential
- Educated to Degree level or equivalent level of education, training or experience.
- Significant experience in IG/DSP related activities across a Health and Care setting, or to have significant experience of working at a senior level in a public sector body
- Practitioner Qualification on Data Protection Act or the General Data Protection Regulation
Desirable
- ISO 17024- accredited GDPR Foundation and Practitioner certificate or evidence of further education in the application of ISO/IEC 27002:2013 and other associated standards.
- Evidence of continuing professional development.
Knowledge & Experience
Essential
- Working knowledge and understanding of the Data Security and Protection toolkit
- Substantial experience of practical implementation of the Data Protection Act
- Experience of working within NHS or similar large multi-disciplinary organisation in a similar role.
- Experience of staff / team leadership
- Experience of delivering awareness and training programmes for staff at ranging levels
Desirable
- Experience of working with internal and external auditors
- Experience of working with or supporting the implementation of security systems
Skills
Essential
- Developed interpersonal skills within groups and on a one-to-one basis
- Ability to mentor, teach and coach
- Ability to analyse and interpret situations where there are conflicting legal / ethical standards and service requirements, and develop an appropriate and justified response on behalf of the Trust.
- Ability to solve problems and use initiative to secure desired outcomes
- Ability to prioritise between competing demands and allocate resources accordingly
- Ability to manage time effectively and efficiently
Desirable
- Proven ability to undertake communication campaigns
- Negotiating and influencing skills
Key Competencies/ Personal Qualities & Attributes
Essential
- Passionate and committed to bring our Dedicated to Excellence values to life, improving the way we work with each other, particularly focusing on empowerment, equality diversity and inclusion of our staff, patients and service users
- High level of drive and determination
- Self-motivated to work on own initiative.
- Developed attention to detail and accuracy
Desirable
- Must be able to understand the needs of patients and deal with all contacts in a sensitive manner
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).
From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).
Additional information
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Applications from job seekers who require current Skilled worker sponsorship to work in the UK are welcome and will be considered alongside all other applications. For further information visit the UK Visas and Immigration website (Opens in a new tab).
From 6 April 2017, skilled worker applicants, applying for entry clearance into the UK, have had to present a criminal record certificate from each country they have resided continuously or cumulatively for 12 months or more in the past 10 years. Adult dependants (over 18 years old) are also subject to this requirement. Guidance can be found here Criminal records checks for overseas applicants (Opens in a new tab).