Head of Data Protection & Information Management
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Head of Data Protection and Information Management role forms part of a Department wide Data Protection Unit led by the DfT Departmental Data Protection Officer, and locally reports into the DVSA Chief Data & Security Officer. The role is responsible for carrying out the delegated statutory tasks of the Departmental Data Protection Officer in accordance with the DfT DPO Governance Framework. They also act as the principal point of contact for the ICO and for Data Subjects for the DVSA within the DfT controllership., The Head of Data Protection and Information Management role forms part of a Department wide Data Protection Unit led by the DfT Departmental Data Protection Officer, and locally reports into the DVSA Chief Data & Security Officer. The role is responsible for carrying out the delegated statutory tasks of the Departmental Data Protection Officer in accordance with the DfT DPO Governance Framework. They also act as the principal point of contact for the ICO and for Data Subjects for the DVSA within the DfT controllership.
The role manages the information and records management function as part of the Government Knowledge and Information (KIM) Profession and ensures that management of both electronic and physical records is compliant with GDPR and other regulations. The team also works with the DVSA Corporate Reputation team to help DVSA meet statutory obligations originating from GDPR and Freedom of Information legislation assuring processes and also leading Internal Reviews or complaints under data protection.
Your responsibilities will include, but arenÂ’t limited to:
- To act as the Data Protection Manager for the DVSA, carrying out the statutory tasks delegated to the role and DVSA by the DepartmentÂ’s DPO (as set out in the DfT Data Protection Governance Policy)
- Leading the records management function ensuring alignment with DfT and wider Government.
- Providing assurance to the Digital & Technology Leadership Team that the organisation’s systems are designed in accordance with the data protection policies and regulations.
- Lead FOI internal reviews, ensuring our response is fair and robust, and when necessary challenging senior managers on decisions to disclose or withhold.
Great line management is important to us as an organisation, and we will equip and support line managers to develop the skills they need. We aim to empower line managers to create teams where people can flourish and deliver excellent outcomes for the public., Regular travel to other offices will be required, which may involve overnight stays.
This role is suitable for hybrid working, which is a non-contractual arrangement where a combination of workplace and home-based working can be accommodated subject to business requirements.
The expectation at present is a minimum of 60% of your working time a month will be spent at either your designated workplace (one of the locations cited in the advert) or, when required for business reasons, in another office/work location. There may be occasions where you are required to attend above the minimum expectation.
If you have a question about hybrid working, part time/job share hours, flexible working, travelling for work, or require a reasonable adjustment, please contact the Vacancy Holder during the recruitment process to avoid possible disappointment later in the process should your working arrangements not be compatible with the requirements of the role (see below for contact details).
Please note that we do not hold a UK Visa & Immigration (UKVI) Skilled Worker Licence sponsor and are unable to sponsor any individuals for Skilled Worker Sponsorship. Candidates must ensure they have the appropriate rights to work in the UK before application.
The role requires DV clearance however candidates can onboard with SC Clearance and undergo DV whilst in post. Should the successful candidate not obtain DV then there will be a requirement to be re-deployed to an alternative post should a position be available., As a Disability Confident Leader employer, we are committed to ensuring that the recruitment process is fair, accessible and allows all candidates to perform at their best. If a person with a visible or non-visible disability is substantially disadvantaged, we have a duty to make reasonable changes to our processes., All external applicants and current employees of accredited non-departmental public bodies (NDPBs) will be required to undergo a Social Media Check. A Social Media Check is a review of your publicly available online activity, typically across platforms like LinkedIn, Facebook, X (formerly Twitter), Instagram, and others. The purpose is to identify any public posts or content that could raise concerns for employers, such as:
- Hate speech or discriminatory behaviour
- Threats or acts of violence
- Illegal activity or substance misuse
- Sexually explicit material
- Extremist views or affiliations
Importantly, this check does not involve hacking into your accounts or accessing private messages. It only considers content you have chosen to make public. Employers use this kind of screening to help ensure their workplace remains safe, inclusive, and aligned with company values. ItÂ’s not about judging your personality or lifestyle - itÂ’s about checking for potential red flags that might affect the role or company culture. If you have questions or concerns about the social media check, we would be happy to explain in more detail whatÂ’s being looked at and how your data is handled securely and fairly.
Feedback Feedback will only be provided if you attend an interview or assessment.
Security
Successful candidates must undergo a criminal record check. Successful candidates must meet the security requirements before they can be appointed. The level of security needed is security check .
See our vetting charter . People working with government assets must complete baseline personnel security standard (opens in new window) checks., * UK nationals
- nationals of the Republic of Ireland
- nationals of Commonwealth countries who have the right to work in the UK
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities with settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- nationals of the EU, Switzerland, Norway, Iceland or Liechtenstein and family members of those nationalities who have made a valid application for settled or pre-settled status under the European Union Settlement Scheme (EUSS)
- individuals with limited leave to remain or indefinite leave to remain who were eligible to apply for EUSS on or before 31 December 2020
- Turkish nationals, and certain family members of Turkish nationals, who have accrued the right to work in the Civil Service
Requirements
Do you have experience in Presentation skills?, * You must have an industry-recognised practitioner-level qualification in data protection.
- You will either have a qualification in FOI or a security qualification such as CISMP or ISO27001. For these area (FoI and security) where no qualification is held, you should be willing to acquire them within 9 months of joining us.
To be successful in this role you will need to have the following experience:
- A history of being involved in incident management and forming part of a wider incident management team.
- A history of working collaboratively and inclusively with external organisations and other stakeholders, sharing information and knowledge to achieve common aims.
- Experience of information and records management function and be able to advice on Freedom of Information legislation and supporting the business with any training
- Experience in assessing and improving compliance and reporting on this to all levels.
- Experience of risk management and working with cyber security colleagues, You must have an industry-recognised practitioner-level qualification in data protection., * Leadership
- Communicating and Influencing
- Developing Self and Others, * A history of being involved in incident management and forming part of a wider incident management team.
- Experience of information and records management function and be able to advice on Freedom of Information legislation and supporting the business with any training
- Experience in assessing and improving compliance and reporting on this to all levels.
- Experience of risk management and working with cyber security colleagues.
The sift will take place week commencing 6th July 2026.
Stage 2: Interview/presentation task
At interview stage, you will be assessed against the following Success Profile elements:
Behaviours:
- Leadership
- Communicating and Influencing
- Developing Self and Others
Experience:
- A history of working collaboratively and inclusively with external organisations and other stakeholders, sharing information and knowledge to achieve common aims.
Benefits & conditions
Pulled from the full job description
- Annual leave
- Employee discount
- Employee assistance programme
- Company pension, Alongside your salary of £57,515, Driver and Vehicle Standards Agency contributes £16,662 towards you being a member of the Civil Service Defined Benefit Pension scheme. Find out what benefits a Civil Service Pension provides .
Being part of our brilliant Civil Service means you will have access to a wide range of fantastic benefits:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave).
- 8 Bank Holidays plus an additional Privilege Day to mark the KingÂ’s birthday.
- Access to the staff discount portal.
- Excellent career development opportunities and the potential to undertake professional qualifications relevant to your role paid for by the department, such as CIPD, Prince2, apprenticeships, etc.
- 24-hour Employee Assistance Programme providing free confidential help and advice for staff.
Find out more about the benefits of working at DfT and its agencies .
About the company
Swansea, Bristol, Birmingham (Garretts Green), Nottingham, Yeading (Hayes), Oldham (Chadderton), Leeds, Newcastle, The role manages the information and records management function as part of the Government Knowledge and Information (KIM) Profession and ensures that management of both electronic and physical records is compliant with GDPR and other regulations. The team also works with the DVSA Corporate Reputation team to help DVSA meet statutory obligations originating from GDPR and Freedom of Information legislation assuring processes, and also leading Internal Reviews or information rights requests under data protection legislation.
Joining our department comes with many benefits, including:
- Employer pension contribution of 28.97% of your salary. Read more about Civil Service Pensions here
- 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the KingÂ’s birthday
- Flexible working options where we encourage a great work-life balance.
Read more in the Benefits section below!
Find out more about what it’s like working at Driver and Vehicle Standards Agency - Department for Transport Careers
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Data Analyst Salary in the UK
Data Engineer Salary UK
How to Write a CV and Interview if You Don't Fully Qualify For The Job