Information Governance Assurance Officer
Job Purpose The post holder will assist and deputise for the Information Governance Assurance Manager with activities related to the delivery and coordination of the Data Security and Protection Toolkit (DSPT), CQC, and general information governance assurance across the NHS organisation. The role involves working alongside multidisciplinary teams to maintain compliance with legislative, statutory, and regulatory requirements.
Location: Norwich
Job Type: Temporary
Duration of booking: Expected to last 3 months with possible extension
Proposed start date: ASAP
Pay Rates: Up to £25 per hour Umbrella or £22 per hour PAYE inclusive of holiday pay
Hours / Working Days: 37.5 hours per week / Monday to Friday, 9am – 5pm
Sector: Healthcare
Based: Office / Hospital
Key Responsibilities
- Governance Framework: Assist in implementing, managing, and assuring an information governance framework compliant with relevant IG legislation, standards, and guidelines.
- Risk Assessments: Complete Data Protection Impact Assessments (DPIAs) and identify privacy risks associated with new projects, systems, or policies.
- Audit & Asset Management: Develop and manage the internal IG audit schedule, participate in spot-check audits, and support data flow mapping and Information Asset Register activities.
- Reporting & Escalation: Collate, analyze, and present IG risk and assurance data for senior bodies, including the Caldicott and Information Governance Assurance Committee and Hospital Management Board.
- Incident Management: Process and monitor responses to IG incidents and data breaches using Datix, ensuring actions are completed and potential patient harm is escalated.
- Training & Awareness: Develop, maintain, and deliver face-to-face and e-learning IG training programs (data quality, confidentiality, security) for all staff levels.
- Data Sharing & Rights: Monitor compliance with data protection laws regarding external data sharing agreements and handle data subject rights (e.g., Subject Access Requests and complaints).
- Deputising: Represent the Information Governance Assurance Manager at key committee meetings, including the Serious Incident Group and Divisional Governance Committees.
Person Specification
Qualifications & Training / Experience / Skills, Knowledge & Abilities
- Educated to degree level in a relevant subject or equivalent experience
- Formal qualification in Information Governance/Data Protection, such as ISEB or Data Protection/GDPR Practitioner
- Evidence of continuing professional development
- Significant experience with data handling, manipulation, and analysis related to governance metrics (Essential, Application/Interview)
- Experience working with sensitive and confidential information in a healthcare environment
- Understanding of NHS Information Governance statutory guidance and DSPT requirements
- Proven experience writing board-level and committee reports
- Proficient in Microsoft Office applications including Word, Excel, PowerPoint, Outlook, and Teams
- Understanding of risk-based IG principles and governance structures
- Excellent written and verbal communication skills, with the ability to influence and present to groups
- Strong analytical, problem-solving, and time-management skills
- Ability to work independently with minimal supervision and use initiative