Data Governance Lead

Kids Planet Day Nurseries Limited
Altrincham, UK
19 days ago
Apply on www.jobs.service.gov.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
Ā£50,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security Data Dictionary Data Discovery Data Governance Information Leak Prevention Information Management Pattern Recognition Data Streaming Data Processing Data Classification Data Management
+1 more
Data Generation

Job description

Kids Planet Day Nurseries is seeking an experienced Data Governance Lead to design, implement, and embed a robust data governance framework across the organisation.

This is a newly defined role created to address identified gaps in data governance capability - distinct from IT Security, which is owned by the Head of IT. The Data Governance Lead will work collaboratively across nursery operations, People, finance, and digital teams to ensure every member of staff understands their responsibility for the data they handle, and that Kids Planet meets all obligations and sector-specific regulatory requirements.

The role will be central to evaluating, procuring, and operationalising specialised data governance tooling, including Data Loss Prevention (DLP) platforms, to give the organisation real-time visibility and control over its sensitive data estate.

Kids Planet Day Nurseries Central Support Office will be relocating to Altrincham in the coming months.

Key Responsibilities

Data Governance Framework

Develop, own, and continuously improve the Kids Planet Data Governance Framework, including data classification schemes, data dictionaries, and data quality standards.

Define and enforce policies covering data creation, storage, sharing, retention, archiving, and secure deletion across all business functions.

Establish and chair a Data Governance Working Group, bringing together representatives from operations, People, finance, and IT to embed a culture of data stewardship.

Maintain a comprehensive data asset register and ensure all critical data flows are mapped and documented.

Data Protection & GDPR Compliance

Act as the organisation’s subject matter expert for UK GDPR and the Data Protection Act 2018, providing guidance to all departments on compliant data handling.

Manage and coordinate responses to Data Subject Access Requests (DSARs), erasure requests, and other data subject rights in line with statutory timescales.

Conduct and maintain Data Protection Impact Assessments (DPIAs) for new systems, processes, and third-party relationships.

Maintain and test the organisation’s data breach response procedures, coordinating with the IT Security team and, where required, the ICO.

Ensure Records of Processing Activities (RoPA) are kept accurate and up to date.

Data Loss Prevention (DLP) & Tooling

Lead the evaluation, procurement, and implementation of the organisation’s DLP platform

Define DLP policies and rules that reflect Kids Planet’s data classification framework, ensuring sensitive data - including children’s personal data - cannot leave the organisation inappropriately.

Monitor DLP dashboards and reporting, investigating alerts, identifying patterns, and driving remediation actions.

Oversee the AI data usage governance programme, ensuring that staff use of AI tools is controlled, audited, and compliant with the organisation’s acceptable use policy.

Act as the business owner for all data governance tooling, managing vendor relationships and licence renewals.

Third-Party & Supplier Data Governance

Lead the data governance aspects of supplier onboarding, ensuring Data Processing Agreements (DPAs) are in place and proportionate data-sharing controls are enforced.

Conduct periodic reviews of third-party data processors to confirm ongoing compliance with contractual and regulatory obligations.

Maintain the organisation’s supplier data risk register and escalate material risks to the CTO.

Training, Awareness & Culture

Design and deliver data governance and data protection training programmes for all staff, tailored to role-specific responsibilities

Produce clear, accessible data governance guidance materials and maintain a staff-facing knowledge base.

Champion a ā€˜data-responsible’ culture across Kids Planet, ensuring data is treated as a strategic asset.

Reporting & Assurance

Produce regular governance reports for the CTO and Senior Management Team covering data quality metrics, compliance status, DLP incidents, and open risks.

Support internal and external audit processes relating to data governance and data protection.

Track and report on the closure of data governance-related audit findings and recommendations.

Requirements

Demonstrable experience in a data governance, data protection, or information management role, ideally within the education, childcare, social care, or regulated services sector.

Strong working knowledge of UK GDPR, the Data Protection Act 2018, and practical application of data subject rights processes.

Proven experience designing and implementing data governance frameworks, policies, and data classification schemes.

Experience managing DSARs, DPIAs, and Records of Processing Activities.

Excellent communication skills, with the ability to translate complex governance requirements into plain-language guidance for non-specialist audiences.

Highly organised with strong attention to detail and the ability to manage multiple workstreams simultaneously.

Desirable

Professional qualifications in data protection or information governance (e.g. BCS Certificate in Data Protection, CIPM, ISEB/IAPP, GDPR Practitioner).

Practical experience evaluating or operating DLP, data discovery, or data classification platforms.

Familiarity with AI data governance considerations and acceptable use frameworks for AI tools.

Experience producing governance reporting for senior leadership or board-level audiences.

Knowledge of the childcare regulatory environment (Ofsted, DfE safeguarding requirements) and how this intersects with data protection obligations.

Knowledge of, or experience working within, recognised information security, privacy and quality management standards, particularly ISO/IEC 27001, ISO/IEC 27701 and ISO 9001, including supporting certification, surveillance audits and continuous improvement activities.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobs.service.gov.uk
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:11 min

Addressing security audits and regional data compliance legislation

4:11 min

Introduction to cloud-native application developer security

Micah Silverman Ā· World Congress 2022

2:36 min

Implementing on-premise deep research agentic workflows

Anshul Jindal Anshul Jindal +1 Ā· World Congress 2026 Europe

1:50 min

Lowering pipeline latency with data streaming

Nathaniel Okenwa Nathaniel Okenwa Ā· World Congress 2024

4:07 min

Establishing data literacy and governance as prerequisites for adoption

Marin Niehues Marin Niehues Ā· LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger Ā· LIVE

Videos

See all

Related articles

See all