Head of Data Protection & Information Management

DVSA
Hayes, UK
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Part-time / full-time
Experience level
Expert
Compensation
£57,515.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Data Security Information Management

Job description

The Head of Data Protection and Information Management role forms part of a Department wide Data Protection Unit led by the DfT Departmental Data Protection Officer, and locally reports into the DVSA Chief Data & Security Officer. The role is responsible for carrying out the delegated statutory tasks of the Departmental Data Protection Officer in accordance with the DfT DPO Governance Framework. They also act as the principal point of contact for the ICO and for Data Subjects for the DVSA within the DfT controllership.

The role manages the information and records management function as part of the Government Knowledge and Information (KIM) Profession and ensures that management of both electronic and physical records is compliant with GDPR and other regulations. The team also works with the DVSA Corporate Reputation team to help DVSA meet statutory obligations originating from GDPR and Freedom of Information legislation assuring processes, and also leading Internal Reviews or information rights requests under data protection legislation.

Joining our department comes with many benefits, including:

· Employer pension contribution of 28.97% of your salary.

· 25 days annual leave, increasing by 1 day each year of service (up to a maximum of 30 days annual leave), plus 8 bank holidays a privilege day for the King’s birthday, The Head of Data Protection and Information Management role forms part of a Department wide Data Protection Unit led by the DfT Departmental Data Protection Officer, and locally reports into the DVSA Chief Data & Security Officer. The role is responsible for carrying out the delegated statutory tasks of the Departmental Data Protection Officer in accordance with the DfT DPO Governance Framework. They also act as the principal point of contact for the ICO and for Data Subjects for the DVSA within the DfT controllership.

The role manages the information and records management function as part of the Government Knowledge and Information (KIM) Profession and ensures that management of both electronic and physical records is compliant with GDPR and other regulations. The team also works with the DVSA Corporate Reputation team to help DVSA meet statutory obligations originating from GDPR and Freedom of Information legislation assuring processes and also leading Internal Reviews or complaints under data protection.

Your responsibilities will include, but aren’t limited to:

  1. To act as the Data Protection Manager for the DVSA, carrying out the statutory tasks delegated to the role and DVSA by the Department’s DPO (as set out in the DfT Data Protection Governance Policy)

  2. Leading the records management function ensuring alignment with DfT and wider Government.

  3. Providing assurance to the Digital & Technology Leadership Team that the organisation’s systems are designed in accordance with the data protection policies and regulations.

  4. Lead FOI internal reviews, ensuring our response is fair and robust, and when necessary challenging senior managers on decisions to disclose or withhold.

Requirements

Do you have experience in Quality assurance?, Do you have a Bachelor’s degree?, * You must have an industry-recognised practitioner-level qualification in data protection.

  • You will either have a qualification in FOI or a security qualification such as CISMP or ISO27001. For these area (FoI and security) where no qualification is held, you should be willing to acquire them within 9 months of joining us.

To be successful in this role you will need to have the following experience:

  • A history of being involved in incident management and forming part of a wider incident management team.
  • A history of working collaboratively and inclusively with external organisations and other stakeholders, sharing information and knowledge to achieve common aims.
  • Experience of information and records management function and be able to advice on Freedom of Information legislation and supporting the business with any training
  • Experience in assessing and improving compliance and reporting on this to all levels.
  • Experience of risk management and working with cyber security colleagues

Benefits & conditions

Pulled from the full job description

  • Annual leave
  • Company pension, Job Types: Full-time, Part-time, Permanent

Pay: £57,515.00 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · WWC 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

55 sec

Managing information overload during complex production system incidents

Anthony Alaribe Anthony Alaribe · WWC 2025

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all