Data Protection Officer and FOI Information Rights Officer
hace 3 días
Stirling
\n This is an exciting role combining Data Protection and FOI work across different organisations. The role is rewarding and offers variety and flexibility of work. \n Around half of your time will be at DPO level delivering DPO-level data protection expertise and project work and/or as DPO for a client organisation. You will be expected to work autonomously and provide excellent DPO advice. \n The remaining half of your time will be as an Information Rights Officer primarily completing FOI work, with some data protection work as time allows. The work will be as part of a supportive team, with expert DPO and FOI colleagues supporting your work. \n \n Background \n \n Hefestis is a not-for-profit shared service organisation, jointly owned by member institutions across the University and College sector. It provides shared services to institutions and where applicable to sector owned bodies and support services. Our core vision is "to be the shared service partner of choice for sustainably delivering information services across the Further and Higher Education sector". \n Hefestis has established a successful Data Protection & Governance share service, currently comprising nine Data Protection Officers (DPO’s) and two Information Rights Officers (IRO’s), who serve a large proportion of Further and Higher Education institutions. The DPO-share service is provided as part of this wider offering, in addition to IRO-share and FOI-share services. Each DPO fulfils the statutory obligations of the role for one or more institutions and/or associated bodies. The DPO’s work virtually as a team with the IRO’s providing a peer network of support, with many years of experience across a variety of backgrounds. This allows individuals to grow professionally as well as providing an effective and resilient resource for our members. \n \n The Role \n \n We have a requirement for an experienced data protection expert who can work at DPO as DPO for client organisations and/or undertake consultancy and project work. You may be the named DPO for a client organisation, with a reporting line to an appropriate member of the senior management team at each institution as well as to a supportive Hefestis DPO line manager. You will be expected to work remotely with occasional on-site visits if required and as agreed with clients. \n This role will provide the opportunity to guide institutions so that data protection is well-managed, supporting compliance and best practice to protect the rights of data subjects. This role offers the independence and responsibility of a DPO as outlined under UK GDPR, with the benefits of being part of a knowledgeable, experienced, and well-respected team. \n We require a flexible staff member who can also operate at Information Rights Officer level, primarily undertaking FOI work for a client organisation, with some data protection work as time allows. The FOI work will be undertaken as part of a supportive team, and full FOI training can be provided. You will report to the client FOI lead, and a Hefestis FOI line manager. This is an excellent development role for somebody seeking to expand their compliance knowledge and experience into FOI. \n You will work directly with client organisations but also be part of Hefestis’ excellent and supportive team of passionate DPOs and IROs. This includes regular meetings to share best practice and discuss developments in the sector. \n \n The key aspects of this role include but are not limited to: \n \n • Act as a Data Protection Officer for client organisation(s) and provide DPO-level expertise in project and consultancy work. \n • Provide experience, expertise and guidance in data protection law including the UK GDPR and the Data Protection Act 2018. \n • To review and periodically update each institution’s data protection policy and supporting procedures/guidance. \n • To have knowledge of case law and ICO regulatory action and disseminate this through recommending actions and issuing guidance. \n • To provide reports to senior management teams, compliance checks and audits. \n • To achieve a fundamental understanding of the sector, ensuring delivery of pragmatic, proportionate and workable guidance and support. \n • Participation in operational meetings and advising on the impact of regulations on institutions. \n • Raise awareness of data protection and provide training to institutional staff as required. \n • Tailor service delivery by considering each institution’s environment/circumstances. \n • Contextualise guidance in different functional areas within institutions, ensuring advice is consistent with that provided to other shared service members. \n • Support and develop data protection tools and templates and share them across DPO-share service and/or utilise tools and templates developed by other DPOs in the Team to maximise efficiency across the service. \n • Undertake data security incident/breach investigations and report matters to senior management. \n • Cooperate with and act as a single point of contact for the ICO where appropriate. \n • Provide a central/single point of contact during an investigation (should an incident/breach impact more than one Member institution). \n • Available by phone for urgent enquiries (e.g. data incidents/breaches). \n • Use balanced judgement to prioritise and deal with competing demands. \n • Provide consistency of advice across institutions as part of the Service team. \n • Learning about FOI, PECR, and records management to contribute to the HEFESTIS service and client work, including FOI work as required (with appropriate training). \n \n The Person \n \n The post holder(s) must be able to work as part of the DPO-share service, engaging with and supporting the team to develop the service. In addition to this, you must be able to cooperate and gain the trust and respect of staff at all levels across your institutions as well as other stakeholders. \n As such, candidates will be required to demonstrate capability and experience in a significant number of the following areas: \n \n Experience and Skills \n \n • A detailed knowledge of data protection legislation, including UKGDPR and the Data Protection Act 2018, is essential. \n • A strong background in data protection, information governance, legislation and/or policy development is essential, preferably with a recognised qualification. \n • A genuine passion for data protection. \n • Experience of conducting compliance audits would be beneficial. \n • An understanding of the Higher and Further Education sector would be beneficial although not essential. \n • Experience of working in or with the public sector. \n • Experience, or knowledge, applying FOI law (English or Scottish) is desired, but not essential – full training can be provided for the FOI part of the role \n \n Personal \n \n • Excellent verbal and written communication and presentation skills. \n • Analytical background with attention to detail. \n • Openness, transparency, and the ability to engender trust. \n • Self-assured and capable. \n • Skills in negotiating and influencing, with the ability to identify common ground and solutions. \n • Demonstrable commitment to Equality and Diversity in all aspects of the company’s operation. \n \n Terms \n \n · Closing date 9th September 2026 \n · Full time, permanent role. \n · 9.5 day fortnight working pattern as standard, every second Friday afternoon off \n · Competitive Salary: circa £31K - £38K per annum, dependent on knowledge and experience \n · 40 days holiday which consists of both annual leave entitlement and fixed leave entitlement \n · Membership of the company pension scheme, access to the company benefits suite including cycle-to-work scheme, and gym discounts \n \n How to Apply \n \n Applications should be made by forwarding your CV and covering letter outlining why you would like to work for Hefestis. Interviews will likely be held week commencing 14th September 2026 virtually via Microsoft Teams. \n