Norther Ireland Assembly logo

Data Protection and Governance Officer
Oifigeach Cosanta Sonraí agus Rialachais

Ready to support the work of the Northern Ireland Assembly?

Assembly colleagues in a meeting

The Data Protection and Governance Officer has a key role in ensuring compliance with the Data Protection Act 2018 and the UK General Data Protection Regulation and will fulfil a management role in relation to Information Standards, Freedom of Information and Governance in the Assembly Commission.

Data Protection and Governance Officer
Oifigeach Cosanta Sonraí agus Rialachais

What we're looking for

The main duties and responsibilities of the job:

Data Protection

  • Inform and advise staff about the requirements of the UK GDPR and the Data Protection Act 2018 and help them to understand the practical implications for their business areas and the risks associated with data processing operations, taking into account the nature, scope, context and purposes of the processing.
  • Monitor and ensure on-going compliance with the requirements of the UK GDPR and the Data Protection Act 2018, through for example, conducting data protection audits and requiring records of all data processing activities to be maintained.
  • Assist and advise business areas and Information Asset Owners (‘IAOs’) in relation to the management of internal data protection activities.
  • Raise awareness of data protection issues and promote a positive data protection culture.
  • Assist business areas in deciding if a Data Protection Impact Assessment (DPIA) should be undertaken and assist with conducting DPIAs.
  • Review and update the data protection, governance and information assurance policies and provide training to staff as required.
  • Develop and maintain relationships with other DPOs across the wider public sector to share knowledge and best practices.
  • Advise upon investigations and notifications once a data breach or other data incident has occurred.

 

Information Standards and FOI

  • Lead an information management systems review and the implementation of a new system.
  • Manage and quality assure the administration of responses to and disclosure of all FOI/DP requests in accordance with statutory deadlines and advise on more complex requests.
  • Oversee the administration of FOI/DP appeals and provide advice to panels.
  • Manage the Retention and Disposal Schedule and liaise with the Public Record Office of Northern Ireland (‘PRONI’).
  • Attend the Information Security Group and advise on appropriate information security measures.

 

Governance

  • Manage the secretarial support to the Secretariat Audit and Risk Committee (‘SARC’).
  • Draft the SARC Annual Report and assist with the self-assessment of SARC.
  • Facilitate the quarterly review and update of the Corporate Risk Register, in conjunction with the Secretariat Management Group (‘SMG’).
  • Assist Directorate Management Teams with the monthly review and update of Directorate Risk Registers.
  • Facilitate the 6-monthly review of Directorate Risk Registers by SMG and identify emerging “risk clusters”.
  • Update and develop the Corporate Governance Framework in conjunction with SMG.
  • Update and develop the Assembly Commission’s Risk Management Strategy in conjunction with SMG.
  • Complete (with input from SMG and Heads of Business) Fraud and Bribery, Cyber Security and Information Risk, Risk Management and other relevant checklists and monitor subsequent action plans.
  • Monitor new or updated relevant corporate governance guidance and identify potential changes or updates to the corporate governance policies or procedures.

 

General duties

  • Fulfil the role in an independent manner.
  • Lead, manage and develop a small team of staff.
  • Develop and provide training for staff on data protection, UK GDPR, information management, governance and risk management.
  • Develop and implement a continuous improvement programme for the office.
  • Comply with all of the Assembly Commission’s staff policies and procedures including Equal Opportunities and Dignity at Work policies and procedures; and
  • Carry out other duties that the Assembly Commission reasonably requires of you.
What we're offering
Essential Criteria

Applicants for the post must possess, by the closing date for applications:

1. A thorough knowledge and understanding of the relevant law, regulations and guidance relating to data protection and freedom of information.

AND

2. A comprehensive understanding of organisational governance and risk management policies and procedures.

AND

3. A primary degree, minimum 2:2 classification, in any subject and a relevant qualification in data protection, for example, Certified Information Privacy Professional (‘CIPP’), BCS in Data Protection to Practitioner level, EU GDPR Practitioner or equivalent.

AND

4. At least two years’ experience of the following:

(a) Successfully leading a data protection and information management service and the effective and efficient delivery of specific outcomes;

(b) Advising at a senior level* on either:

  • information standards and data protection policies and procedures or
  • governance and risk management policies and procedures.

 

(c) Using the standards that underpin good information management, ensuring that organisational standards and legislative requirements are met and that a robust information system and supporting policies are maintained.

*Senior level is defined as a Project Board, Director, Head of Business, NICS Grade 7 or company board member or equivalent.        

OR

1. A thorough knowledge and understanding of the relevant law, regulations and guidance relating to data protection and freedom of information.

AND

2. A comprehensive understanding of organisational governance and risk management policies and procedures.

AND

3. A relevant qualification in data protection for example Certified Information Privacy Professional (‘CIPP’), BCS in Data Protection to Practitioner level, EU GDPR Practitioner or equivalent.

AND

4. At least four years’ experience as listed at points a) – c) above.

The successful applicant will be expected to complete Prince 2 in project management and CIPFA Governance certificate or equivalent within 12 months of appointment, if not previously completed.

Quick Q&A for this job...​

The salary range is £45,940 – £47,326. This is an Assembly Grade 5 position. 

This post sits within the Information Standards Office in the Directorate of Legal, Governance and Research Services. This is a key post within the organisation and the post holder will undertake duties as Data Protection Officer in addition to fulfilling a management role in relation to Information Standards, FOI and Governance.

The successful candidate will be accountable to the Director of Legal, Governance and Research Services.

The successful applicant will be based in Parliament Buildings, Belfast.

Completed application forms must be submitted by 12 noon on Monday 5 July 2021.

The Selection Process

There are five elements within the Recruitment and Selection Framework:

Experience – the knowledge or mastery of an activity or subject gained through involvement in or exposure to it.

Abilitythe aptitude or potential to perform to the required standard.

Technical – the demonstration of specific professional skills, knowledge or qualifications.

Assembly Skills and Behaviours –the actions and activities that people do which result in effective performance in a job.

Strengths – the things we do regularly, do well and that motivate us.

The elements which will be assessed for this role will be Experience, Technical, Assembly Skills and Behaviours and Strengths and the selection method(s) that will be used are detailed below. Further information on the Recruitment and Selection Framework are included in the Guidance on Recruitment and Selection for Applicants.

The essential criteria reflect the experience and knowledge that an applicant must possess in order to be able to undertake the role. An eligibility sift will be carried out on the basis of the information contained in the essential criteria section of the application form. You must therefore demonstrate clearly in your form how, and to what extent, you meet with the essential criteria for the post. 

The selection panel reserve the right to use shortlisting as part of the selection process for this post. Should shortlisting be used, the shortlisting criterion listed in the Job Specification will be applied. The selection panel reserve the right to set a minimum standard for the shortlisting criterion which applicants must achieve in order to be invited to the interview stage of the selection process. If shortlisting is not necessary, all applicants who have demonstrated the essential criteria will proceed to the next stage of the selection process.

As part of this stage of the selection process, applicants will be required to complete a written assessment exercise.  There will also be an interview, which will address the information contained in the Job Specification and will assess elements of the Recruitment and Selection Framework. The interview will also include the delivery of a presentation. The subject of the presentation will be advised to the applicant on the day of the interview and the applicant will be expected to present information to the selection panel.

Written assessment exercises are planned for 11 August 2021

Interviews are planned for 24 and 25 August 2021

The selection panel reserves the right to hold a further interview stage if deemed necessary.

Further information on the Recruitment and Selection process is available in the Recruitment and Selection Framework and Guidance on the Recruitment and Selection for Applicants.

Data Protection and Governance Officer
Oifigeach Cosanta Sonraí agus Rialachais

Below you will find everything you need to apply for the position.

Read all the information about the job and the associated guidance related to working in the Assembly:

You are now ready to complete the online application:

Please note the application form will be unavailable on Saturday 21st November between 00:00 – 09:00 due to maintenance on the system.

If you are unable to access the form during this time please try again later.

The deadline for applications expired at 12 noon on Monday 5 July 2021.

Further Information

If you require more information on the recruitment process, please contact the Human Resources Office on 02890 520327 or 02890 521869 or email recruitment@niassembly.gov.uk.

Visit our website for further information about the Assembly.

Good Luck

Please note the application form will be unavailable on Saturday 21st November between 00:00 – 09:00 due to maintenance on the system.

If you are unable to access the form during this time please try again later.