Job responsibilities
Expertise and Advice
To act as a source of expertise on Information Governance issues to all relevant areas of the Trust including but not limited to: Executive Board, Business Centres and the Information Services Team
Advise on Information Governance issues, and in particular Information Security, Data Protection and Freedom of Information, that arise with transformation or systems development to ensure best practice is adhered to
To provide advice and support in the investigation and management of Information Governance incidents including national reporting and incident-management for more serious cases as appropriate
To work with and support the Trust leads for other aspects of Information Governance ensuring the Trust works towards the highest possible attainment level for data security and protection governance standards as evidenced by the Data Security and Protection Toolkit
Work proactively with operational managers and other stakeholders to ensure that the Trusts information governance processes meet the business requirements of the organisation
Responsibility for developing Trust procedures and processes relating to all areas of Information Governance, in particular those covering record keeping, records transfer, information security and information sharing
In collaboration with the Head of Digital Infrastructure and Cyber security colleagues , to examine and advise on all aspects of computer security policies including logon procedures, password setting and ageing and all other relevant matters covered in Best Practice Guides
To maintain an up to date knowledge of new developments in Data Protection legislation and related provisions
Continue to maintain specialist knowledge in the field of Information Governance, keeping up to date with any changes and recommended good practice and to be responsible for keeping abreast of new government initiatives and requirements relating to IG
To provide advice and guidance on rights for data subjects and ensure that the Trusts privacy notice is regularly reviewed and updated
To manage Data Subject Access Requests for information outside the medical record eg. Police, Department of Health & Social Care, Coroners, Surrey County Council, Social Services, Safeguarding, staff members / ex-staff members, patient complaints, ICO complaints, solicitors etc
Leadership and Managerial
To assume the role of the Data Protection Officer (DPO), reporting directly to the Trust Board in matters relating to data protection assurance and compliance. The DPO acts under contract to the Trust and must not receive specific direction from any other staff member. Their responsibilities are:
o To provide support, advice, and assurance of compliance across the Trust
o To maintain expert knowledge of data protection law and practices and how they apply to the business of the Trust
o To be the first point of contact within the Trust for all data protection matters
o To support programmes and initiatives that involve the development of new or innovative information processes on the need for data protection impact assessments (DPIAs), data sharing agreements (DSAs), and data processing agreements (DPAs)
o To support and advise programmes and initiatives in conducting data protection impact assessments, and to assure the proposed mitigations
o To consult with the Information Commissioners Office (ICO) where proposed processing poses a high risk in the absence of proposed mitigations
o To ensure that the IG team operates effectively in supporting these functions
o To take account of the risks associated with processing in the performance of his or her tasks
o Provision of specialist advice to the organisation on compliance obligations
o Provision of advice to projects and business change initiatives on when data protection impact assessment is required
o Development of materials to support staff in conducting data protection impact assessment, and system implementations
o To be the first point of contact for the ICO
o To cooperate with the ICO in any matters relating to data protection compliance including provision of evidence of compliance, and in relation to breach management
To be the Privacy Officer (PO) receiving and investigating SCR notifications
To be the Trusts lead for Data Protection, working closely with the Trusts Caldicott Guardian
Lead on the Trusts Caldicott Assurance Plan
To ensure that Information Governance responsibilities and accountabilities are defined, communicated and acted upon
Lead on the Information Security Assurance Plan
Develop and maintain currency of the Trusts Freedom of Information (FOI) publication scheme
Manage the FOI administrator ensuring they are appraised on a regular basis, including weekly 1-2-1 meetings.
To be responsible for all FOI requests received by the Trust, signing off before responses are sent out and advising on use of legal exemptions
Manage appeals and internal reviews against decisions to refuse FOI requests
Reporting
Responsible for managing the Data Security and Protection Toolkit within the Trust, controlling user access, reminding contributors of deadlines, providing relevant training, advising on suitability of evidence and signing off evidence before submission, working with the auditor to ensure compliance with a subset of DSPT requirements. Report risks, issues and incidents to the Information Governance Steering Group
Attend meetings of the Trust Information Governance Steering Group and deliver progress reports on improvement to the Information Governance service
To co-ordinate all statutory and external audits of Information Governance
To act as Privacy Officer for the Trust conducting proactive and reactive audits for user access to Evolve, Cerner EPR, BadgerNet, TVS Surrey Care Record (SyCR), National Care Records Service (NCRS)etc.
To carry out quarterly unannounced spot checks in order to measure the Trusts compliance with national and local Information Governance standards.
In conjunction with IT colleagues to investigate, manage and report cyber incidents
Responsibility for maintaining the Trusts notification registration with the Information Commissioner and inform all relevant locations of the details of registration and what the responsibilities are within it
Liaise directly with the Information Commissioners Office as required
Produce an annual report and action plan on Information Governance in the Trust for the Trusts Audit Committee
Service Improvement and Training
To be responsible for delivery of the Information Governance Improvement/Action Plan and co-ordinate the annual audit to confirm and score compliance
To co-ordinate and ensure delivery of an improvement plan to ensure compliance with data security and protection standards and relevant legislation
Lead the development and roll out of training programmes to managers and staff to support Information Governance, ensuring all members of the organisation are aware of and appreciate the importance of information governance and accept their responsibility for its delivery
Lead on the development of Information Governance documentation, including templates, document formats used, e.g. word documents versus Webforms
Lead on the continuous improvement of Information Governance processes and SOPs, to deliver earlier thought of IG within change initiatives and procurements and faster turnaround of high quality documents from clinical and operational colleagues.
Communications and Engagement
To work closely with colleagues in similar posts in partner organisations across the Local Health economy to ensure the delivery of Information Governance across all organisations
Maintain the Trust Information Governance section of the intranet and internet
To manage the Information Governance mailbox, the Caldicott mailbox and the Police Liaison mailbox
General responsibilities
To support the department and organisation by carrying out any other duties that reasonably fit within the broad scope of a job of this grade and type of work