Job summary
Band 5: £32,073- £39,043 per annum (effective from
01/04/2026)
Full time hours: 37.5 per week
Location: St Mary's Hospital, Parkhurst Road, Newport,
Isle of Wight, PO30 5TG
Contract Type: Permanent
Are you passionate about data protection, Freedom of
Information, records management, and making a real impact in healthcare? Were
looking for a detail-oriented Records and Information Governance Officer to
join our proactive Information Governance team, supporting both Portsmouth
Hospitals University NHS Trust and Isle of Wight NHS Trust.
As part of our Single Corporate Services, youll play a
vital role in ensuring both Trusts meet our legal and regulatory obligations
around data protection and information governance. Youll be instrumental in
maintaining high standards of compliance, transparency, and accountability
across both organisations.
Youll be at the heart of records management, managing
Freedom of Information (FOI) requests, and records management across the
Trusts. Youll work closely with colleagues across departments, providing
expert advice and guidance on legislation such as the UK GDPR, Data Protection
Act 2018, and Freedom of Information Act 2000. Your work will directly support
the Trusts commitment to being well-led, safe, and patient-focused
organisations.
This is a multi-site role, however based at St Marys, Isle
of Wight, offering variety and the opportunity to work across two leading NHS
organisations. Travel between sites may be required.
Main duties of the job
Your key responsibilities will include:
- Oversee FOI requests across both Trusts.
- Provide expert advice on GDPR, FOIA, DPA 2018, and other Information Governance legislation.
- Provide direct leadership and line management of the IG administrators.
- Maintain and update the records inventory excel spreadsheets.
- Ensure the records disposal process is followed as per Trust policy and actioned in accordance with the Records Management Code of Practice.
- Provide support to clinical and corporate services for archiving as required.
- Re-calling boxes from Off-site storage suppliers when required.
- Creating inventories for boxes in Off-Site storage.
- Collaborating with services to ensure that retention dates of electronic information is adhered to.
- Collaborating with services to ensure that records management practices and standards, with regards to electronic information is adhered to.
- Support the IG officers in post with Subject Access Requests when demand requires it.
- To support the delivery of all functions associated with information governance (IG) and data protection, relating to UK General Data Protection Regulations (GDPR), Data Protection Act 2018 (DPA 2018), Access to Health Records Act 1990 (AHRA), Freedom of Information Act 2000 (FOIA) Environmental Information Regulations (EIR) and all associated Information Governance work streams including the annual Data Security Protection Toolkit.
About us
Our vision for Single Corporate Services Isle of Wight NHS
Trust (IWT) and Portsmouth Hospitals University NHS Trust (PHU) have a shared
vision of a single corporate service across our two organisations, supported by
a single set of identical systems and processes, under joint leadership, to
drive significant efficiencies, improve employee experience, and return time to
patient care.
Why are we changing the way we deliver Corporate
Services?
Working as a partnership, both IWT and PHU have a shared
vision for excellence in care for our patients and communities; with a set of
strategic aims underpinning how we will achieve this. The creation of a single
corporate service is essential for us to support our clinical and operational
services, and our wider transformation programme.
The single corporate service is delivered across both
organisation. You may be based at either IWT or PHU and individuals may be
required to undertake business travel between sites. For leaders managing staff
across multi-site locations, you will need to be visible and provide in person
leadership. The arrangements and frequency will be agreed locally.
Job description
Job responsibilities
As the single corporate service will be delivered across both organisations, individuals may be required to undertake business travel between sites. The frequency and arrangements will be discussed on an individual basis and the staff mobility local agreement will apply.
For our leaders managing staff across multi-site locations, they will need to be visible and provide in person leadership. The arrangements and frequency will be agreed locally.
Job purpose
To ensure both Trusts meet their legal and regulatory obligations associated with information governance and data protection management including records management and to ensure that there are robust arrangements in place to continue to be well led organisations. This includes assurance and escalation as necessary.
Job summary
To ensure retention schedules are adhered to in accordance with the Records Management Code of Practice and Trust Records Management Policy.
Manage the Trusts paper archiving accounts, ensuring appropriate access and retention periods are adhered.
To ensure that all data protection and freedom of information request for information are processed, in line with legal timeframes and as per the Groups policies, and procedures.
To be an integral part of the Information Governance Team ensuring high standards of Information Governance are implemented and maintained across the Group.
Specific Core Functions
- Provide direct leadership and line management of the IG administrators.
- Maintain and update the records inventory excel spreadsheets.
- Ensure the records disposal process is followed as per Trust policy and actioned in accordance with the Records Management Code of Practice.
- Provide support to clinical and corporate services for archiving as required.
- Re-calling boxes from Off-site storage suppliers when required.
Planning and organising
Planning and organisation of a number of complex activities or programmes, which require the formulation and adjustment of plans.
Physical Skills
The post requires developed physical skills to fulfil duties where there is a specific requirement for speed or accuracy. This level of skill may be required for advanced or high-speed driving; advanced keyboard use; advanced sensory skills or manipulation of objects or people with narrow margins for error, or the post requires highly developed physical skills, where accuracy is important, but there is no specific requirement for speed. This level of skill may be required for manipulation of fine tools or materials.
Patient Client Care
Provides general non-clinical advice, information, guidance or ancillary services directly to patients, clients, relatives or carers.
Policy and Service Development
The post holder is responsible for implementing policies within a team/department and proposes changes to working practices or procedures for own work area.
Financial Management
The post holder will be an authorised signatory for small cash/financial payments.
For further details please refer to attached job description.
Job description
Job responsibilities
As the single corporate service will be delivered across both organisations, individuals may be required to undertake business travel between sites. The frequency and arrangements will be discussed on an individual basis and the staff mobility local agreement will apply.
For our leaders managing staff across multi-site locations, they will need to be visible and provide in person leadership. The arrangements and frequency will be agreed locally.
Job purpose
To ensure both Trusts meet their legal and regulatory obligations associated with information governance and data protection management including records management and to ensure that there are robust arrangements in place to continue to be well led organisations. This includes assurance and escalation as necessary.
Job summary
To ensure retention schedules are adhered to in accordance with the Records Management Code of Practice and Trust Records Management Policy.
Manage the Trusts paper archiving accounts, ensuring appropriate access and retention periods are adhered.
To ensure that all data protection and freedom of information request for information are processed, in line with legal timeframes and as per the Groups policies, and procedures.
To be an integral part of the Information Governance Team ensuring high standards of Information Governance are implemented and maintained across the Group.
Specific Core Functions
- Provide direct leadership and line management of the IG administrators.
- Maintain and update the records inventory excel spreadsheets.
- Ensure the records disposal process is followed as per Trust policy and actioned in accordance with the Records Management Code of Practice.
- Provide support to clinical and corporate services for archiving as required.
- Re-calling boxes from Off-site storage suppliers when required.
Planning and organising
Planning and organisation of a number of complex activities or programmes, which require the formulation and adjustment of plans.
Physical Skills
The post requires developed physical skills to fulfil duties where there is a specific requirement for speed or accuracy. This level of skill may be required for advanced or high-speed driving; advanced keyboard use; advanced sensory skills or manipulation of objects or people with narrow margins for error, or the post requires highly developed physical skills, where accuracy is important, but there is no specific requirement for speed. This level of skill may be required for manipulation of fine tools or materials.
Patient Client Care
Provides general non-clinical advice, information, guidance or ancillary services directly to patients, clients, relatives or carers.
Policy and Service Development
The post holder is responsible for implementing policies within a team/department and proposes changes to working practices or procedures for own work area.
Financial Management
The post holder will be an authorised signatory for small cash/financial payments.
For further details please refer to attached job description.
Person Specification
Qualifications
Essential
- Degree level (or equivalent).
Desirable
- Accredited Courses associated with Information Governance, Freedom of Information Act, Subject Access or Records Management.
Experience
Essential
- Evidence of significant experience in system administration.
- Advanced skills for keyboard use for producing reports, spreadsheets and correspondence.
- Excellent verbal, telephone and written communication skills.
- Ability to use own initiative and deal with competing priorities.
- Works autonomously but can seek advice when necessary/manages a discrete area of work.
Desirable
- Expertise within specialism, underpinned by practical experience.
- Management of team and line management responsibilities.
Additional criteria
Essential
- Detailed knowledge of UK GDPR the Data Protection Act and Freedom of Information Act.
- Significant experience of information handling and analysis gained in a work environment.
Desirable
- Have a good understanding of the requirements of the Caldicott recommendations for handling data with the NHS.
Person Specification
Qualifications
Essential
- Degree level (or equivalent).
Desirable
- Accredited Courses associated with Information Governance, Freedom of Information Act, Subject Access or Records Management.
Experience
Essential
- Evidence of significant experience in system administration.
- Advanced skills for keyboard use for producing reports, spreadsheets and correspondence.
- Excellent verbal, telephone and written communication skills.
- Ability to use own initiative and deal with competing priorities.
- Works autonomously but can seek advice when necessary/manages a discrete area of work.
Desirable
- Expertise within specialism, underpinned by practical experience.
- Management of team and line management responsibilities.
Additional criteria
Essential
- Detailed knowledge of UK GDPR the Data Protection Act and Freedom of Information Act.
- Significant experience of information handling and analysis gained in a work environment.
Desirable
- Have a good understanding of the requirements of the Caldicott recommendations for handling data with the NHS.