Data Security and Protection Adviser
| Posting date: | 11 February 2026 |
|---|---|
| Salary: | £31,049.00 to £37,796.00 per year |
| Additional salary information: | £31049.00 - £37796.00 a year |
| Hours: | Full time |
| Closing date: | 25 February 2026 |
| Location: | Northampton, NN1 5BD |
| Company: | NHS Jobs |
| Job type: | Permanent |
| Job reference: | C9265-26-0098 |
Summary
Data Security and Protection (DSP) Provide specialist advice andassistanceto staff whererequiredon areas of complex information governance legislation, such as UK GDPR, Data Protection Act 2018 and the NHS Code of Practice on Confidentiality To work closely with department colleagues, support services, clinical services,operational and strategic Data Security and Protection leads and internal and external DSP colleagues to promote excellent Information Governance, Data Security and Data Protection practice, by advising and supporting them in their understanding and delivery of these requirements. To be aware of Data Security and Protection incidents and whereappropriate supportin the investigation process, ensuring relevant actions are taken and lessons learnt to prevent reoccurrence Provide support for a programme of Data Security and Protection related work managed by the Head of DSP and locally directed by the DSP Team Leader Log Serious Information Governance incidents on Data Security and Protection Toolkit incident reporting tool Conduct Data Security and Protection user satisfaction surveys in line with Data Security and Protection Toolkit requirements. Deputise for theDSP Team Leader, attending relevant meetings when necessary. Provide support to other areas of the Data Security and Protection Team as directed by the Head of Data Security and Protection. Be the first line of response for data security and protection queries providing support,adviceand guidance to key areas of the Trust including Research and Innovation, Complaints,Governanceand IT. Develop andmaintainstandard operating procedures for all routine tasks carried out within the role. Support the development,reviewand roll-out ofappropriate DSPrelated policies and procedures. Manage DSP records, both paper and electronic, updating reports,maintainingaction plans,policiesand procedures etc. Take a proactive role in the collation of the evidencerequiredfor the annual Data Security and Protection Toolkit submission andparticipatein improvement plans. Maintain a register of Information Governance related incidents and produce regular reports from Datix, liaising with all departments and Risk Management asappropriate, leading on incident investigations where appropriate. Maintain the Trusts Information Asset Register and undertake reviews in coordination with Information Asset Owners and Information Asset Administrators. Supporting internal colleagues with the completion of Data Protection Impact Assessments, including highlighting data protection and security risks. Update andmaintainthe Trusts Privacy Notice to ensure compliance with UK GDPR standards and internal policies. Understand andmonitorcompliance with relevant legislation, particularly the common law duty of confidentiality, the Data Protection Act 2018, the General Data Protection Regulation, the Computer Misuse Act 1990, the Human Rights Act 1998; Manage Information Sharing Agreements and flows via the Information Sharing Gateway, working with internal and external stakeholders to make sure these are appropriately documented. Liaise with relevant internal and external stakeholders to ensure Information Sharing Agreements are completed and reviewed in line with GDPR. Establish good working relationships with key staff in all departments across the Trust. Implement policies and propose changes to Group DSP policies asappropriate, conducting monitoring compliance with those policies and protocols conduct data protection impact assessments (DPIA) where necessary and ensure the Group adheres to the data privacy by design and default as set out in Article 25 GDPR complete DPIAs to relevant team members and ensure cross partnership working with relevant project and transformation leads Assist the DSP Team Leader in the collation of relevant reports and information for compliance reporting,inspectionsand internal assurance Escalate incidents to the Team Leader immediate when they may meet the criteria for a Serious Incident / reportable to the ICO Deputise for the DSP Team Leader whenrequired work with the complaints team and directly with members of the public to communicate appropriatelyregardingany DSP grievances and queries tomaintaintheir specialist knowledge in Data Protection Law and UK GDPR update the Internet and Intranet pages for DSP asappropriate, ensuring it is up to date with pertinent advice and guidance, including applicable FAQs and relevant legislation Training & Audit Tobe responsible forthe Data Security and Protection training programme, including planning and liaison with the Learning and Development Team for the regular delivery of DSP training sessions TomonitorData Security and Protection training compliance and to take all reasonable action to ensure that compliance levels aremaintainedat above 90% at all timesand take allpossible stepsto ensure 95% compliance is achieved annually for the DSP Toolkit assertion. To ensure that this specialist knowledge is kept up to date and changes in legislation or national and local policy are communicated effectively to staff at all levels within the organisation To input into and to support the Data Security and Protection communication strategy. To undertake Data Security and Protection assurance check audits in clinical and non-clinical areas, to report findings and work with relevant teams to develop and monitoraction plans for improvement. To review the Information Asset Register against the Information Sharing Gateway toidentifyassets and data flows which have not been documented. Ensure that learning from Data Security and Protection incidents is incorporated into DSP training and awareness. Training colleagues on the use of the Information Sharing Gateway and Information Asset Register. Training colleagues on the practice of completing Data Protection ImpactAssessments. Developing training and awareness materials and guidelines.