Data Security and Protection Team LeaderNHS
Job summary
An exciting opportunity has arisen at University Hospitals of Northamptonshire (UHN) for a proactive and passionate Data Security & Protection (DSP) Team Leader to join our dynamic and fast-paced Data, Security & Protection Team.
This is a pivotal role supporting both Northampton General Hospital and Kettering General Hospital as part of our Group approach to ensuring we meet our legal, statutory and regulatory obligations relating to the security and protection of personal data.
As our DSP Team Leader, you will play a key part in completion of the Group's DSP Toolkits and managing the DSP Team to ensure all areas of the DSP Toolkit framework are delivered.
The Role is Not Eligible for Sponsorship
Main duties of the job
Key responsibilities include:
- Leading the delivery of DSP workstreams and ensuring evidence is maintained for DSP Toolkit standards.
- Managing, triaging, and supporting investigation of DSP incidents via Datix.
- Delivering DSP training (classroom, small groups and virtual).
- Overseeing the completion and quality of Data Protection Impact Assessments (DPIAs).
- Supporting information sharing governance using the Information Sharing Gateway.
- Raising awareness of data security issues across the Group and promoting best practice.
- Acting as a key point of contact for colleagues seeking specialist DSP support.
Job description
The post holder will be the Data Security & ProtectionTeam Leader. In particular, the post holder will:
- act as the expert source of advice andexpertisein DSP for theGroup;
- supportthe development for clinical administration functions within the organisation identifyinginformation governance risks and issues and providing recommendations for change
- increase the profileof Data Security and Protectionwithin the organisation andactively supporta culture change so that staff are aware of their responsibilities and duties towards confidentiality,integrityand availability of information;
- ensure processes are in place formonitoringthe secure disposal of IT and hardware assets;
- initiate and plan aprogramme of workthat ensures theGroupcomplies withthe requirements of the Data Security & Protection Toolkit;
- completion of the annual Data Security & Protection Toolkit submission and the collation of supporting evidencewhich is analysed and updated to ensure compliance;
- lead a range of audits which will check compliance with the DSP toolkit, research and development and incident management activities, developing improved systems and processes for data quality, data security and protection, dataintegrityand availability.
- work in partnership with theGroupsCyber SecurityLeadto ensure that all Cyber related toolkit assertions are met within the NHSD deadlineand any gaps in assurance are identified with a plan in place for compliance
- implement andmaintaincompliancewith relevant legislation, particularly the common law duty of confidentiality, the Data Protection Act 2018, the General Data Protection Regulation, the Computer Misuse Act 1990, the Human Rights Act 1998;
- investigate and resolveinformation securityissues andprocessesforsystems which are process personal and/or trust sensitive data.
- Implement the DSP training strategy forthe delivery of the Trusts IG training needs, ensuring that theGroupmeets the NHSD target for mandatory training, working in partnership with the Trusts Learning & Development service
- Deliver information governance trainingif and whennecessary
- Implement policies and propose changes toGroupDSP policies asappropriate,conductingmonitoring compliance with those policies and protocolsand ensuring they are compliant with Data Protection Act and GDPR legislation
- conduct data protectionimpact assessments (DPIA) where necessary and ensure theGroupadheres to thedataprivacy by designand default asset outin Article 25 GDPR
- act as theUHNinformation security expert to ensure any identified risks are communicated to the Head of Technology and Head of Clinical Systems to enable new systems to be implemented safely
- assign DPIAs to relevant team members and ensure cross partnership working with relevant project and transformation leads
- ensure that allGroupDPIAs, Assets, Flows and third parties are appropriately recorded on the Information Sharing Gateway and signed off by the relevantDPO and SIROs
- Be an escalation point for the DSP analysts to ensure DPIAs are in line with GDPR legislation, redesigning systems,processesand procedures to meet the Data Security by Design and Defaultcriteria
- communicate complex information to a range of audiences and be able to influence and persuade staff of the importance of excellent DSP standards
- Lead the collationofrelevant reports and information for complianceand performancereporting, inspections and internal assuranceensuring presentations articulate statistical,analyticaland complex reportingto Groupand Boardmandated meetings
- Coordinate the Data Governance Group and Information Governance Group meetings, ensuring relevant reports, minutes actions and decisions are recorded, delegating tasks to the DSP administrator as appropriate
- Attend group,Trustand project meetings to provide expert Data Security and Protection advice and guidance to enable the effective adoption of expectations and policy
- Coordinate reported incidents on Datix to ensure they are appropriately managed and actions are taken
- Escalate incidents to the relevant DPO when they meet the criteria for a Serious Incident / reportable to the ICO
- Manage the DSP Toolkit Incident reporting mechanism, ensuring all SeriousIncidentsare reported with 72 hours
- Provide IG input,advice, guidance forResearch&Developmentprogrammes
- Deputise for the DSPManagerwhenrequired
- Ensure that the Information Sharing Gatewayis administeredasappropriateinrespect ofmaintainingsignificant assurance status across the group, being the lead and expert for use of the ISG, proposing recommendations for improvements to the national system for process,analyticsand reporting.
- coordinatethe effective investigation ofany and allIG related incidents, working with the relevant manager in whose service the incident occurred, where necessary, to ensureappropriate actionhas been taken in relation to the incident;
- To speak to staff,patientsand family members on the telephone as an escalation point for the DSP analyst,demonstratingunderstanding,compassionand knowledge in difficult,challengingand emotional circumstances.
- attendserious investigation panels anddraftreports to the CCG which give assurance that due diligence has been carried outregardingall serious incidents
- ensure that a root cause analysis is performed on all serious incidents with relevant actions recorded, and acted upon to ensure such incidents do not re-occur
- work with the complaints team and directly with members of the public to communicate appropriatelyregardingany DSP grievances and queries
- maintaintheGroupInformation Asset register and data flow maps and, also, whereappropriate, provide training to Information Asset Owners and Administrators
- be afirstpoint of contact for Data Subjectswith regard toall issues related to processing of their personal data and to the exercise of their rights underthe UK GDPR
- tomaintaintheirspecialistknowledgein Data Protection Law and UK GDPR
- update the Internet and Intranet pages for DSPasappropriate, ensuring it is up to date with pertinent adviceandguidance,includingapplicable FAQs and relevant legislation
Workforce
The Data Security & ProtectionTeam Leaderwill have line management responsibility for theDSP Team, ensuring that all staff have annual performance reviews, objectives andappraisalsin line withthe Groupobjectives, ensuringthey have the equipment necessary to fulfil their roles and the HR management tools are managed effectively.They will be an active role in recruitment,inductionand local training.
- Ensure anadequate skill mix andthat the office is appropriately managed
- To provide specialised training,adviceand guidance to DSPTeam members as and whenrequired
- To manage the team in ensuring all members adhere to Trust Values and lead by example
- ToleadDSPTeam recruitment;
- Toensure thee-rostering systemis signed off on a weekly basis
- To carry out appraisals, team performancemanagementand disciplinary processes
- To be the lead contact for HR queries relating to the team
About us
Please submit your application as soon as possible, as we reserve the right to close adverts once sufficient applications have been received.
We recognise that AI tools can support application writing; however, candidates are asked to keep their use to a minimum. Responses should reflect your own experience, skills and knowledge, as over-reliance on AI-generated content may result in generic answers that do not accurately represent your abilities.
University Hospitals of Northamptonshire (UHN) brings together Kettering General Hospital NHS Foundation Trust and Northampton General Hospital NHS Trust. As a group, we are committed to improving services for our communities through collaboration, modernising care delivery and striving for excellence. Working together enables us to share expertise, strengthen services and create greater opportunities, and there may be a requirement to work across sites depending on service needs.
Our Excellence Values are Compassion, Accountability, Respect, Integrity and Courage. UHN welcomes applications from all backgrounds and is committed to an inclusive working environment. We are proud signatories of the Armed Forces Covenant and hold the Gold Award under the Employer Recognition Scheme. Candidates who identify as members of the Armed Forces community and meet the essential criteria will be guaranteed an interview.