Senior Information Management and Governance Officer
Data Protection and Information Rights lead (Grade E3)
FTC until August 2025 (Maternity cover)
Edinburgh/Hybrid
£46,392 – 54,003 per annum
Everything we do at the Scottish Funding Council (SFC) aims to create the right environment for colleges and universities to thrive.
The Scottish Funding Council is Scotland’s tertiary education and research authority. Our ambition is to make Scotland an outstanding place to learn, educate, research, and innovate – now and for the future. We have a clear focus on recruiting the best people and developing them throughout their career.
We’re looking for individuals who connect with our guiding principles, which include working in partnership, championing diversity, and supporting sustainability for future generations. We are proud of the inclusive working environment we have created and are committed to attracting people of all backgrounds.
Job Summary
Reporting to the Assistant Director, Information Governance, you will lead on responding to information rights requests and fulfill the role of the Data Protection Officer - a key role within SFC. You will work closely with senior leaders, including the Senior Information Risk Officer and Chief Information Officer, supporting the Assistant Director to deliver the Information Governance Framework and leading on associated activities.
As an experienced Information Rights and Data Protection practitioner, you will be skilled in dealing with sensitive, complex information, building trusted relationships with colleagues across SFC, and exercising good judgment in responding to information rights requests.
You will be expected to work flexibly across the responsibilities of the information governance team, stepping in to provide cover and support when required to ensure deadlines are met. A keen understanding of the strategic context within which the SFC is working will be key to success in this role.
Key Responsibilities
1. Leading the response to information rights requests, providing advice to colleagues across SFC, ensuring legal compliance with relevant legislation.
2. Provide an efficient and effective senior contact point for queries regarding information rights and data protection.
3. Ensure staff fully understand their responsibilities within data protection legislation and information rights.
4. Promote an information governance culture and understanding of data protection compliance throughout the organization.
5. Inform and advise SFC staff, including senior leaders, about their obligations to comply with the UK GDPR and other relevant data protection laws.
6. Develop and maintain effective coordination and liaison with our stakeholders and external partners.
7. Identify opportunities to improve ways of working within Information Governance and implement positive change.
8. Manage and advise on internal data protection activities, supporting colleagues to deliver Data Protection Impact Assessments and Data Sharing Agreements.
9. Develop and maintain SFC’s Records of Processing Activities (RoPA) to ensure accuracy and regular review.
10. Coordinate with Information Governance colleagues to assess and respond to personal data breaches.
11. Identify and implement improvements to data protection and information rights compliance based on user requirements and best practices.
12. Contribute, make recommendations, and report to the Information Governance Oversight Group on data protection and information rights development and compliance.
13. Monitor SFC’s compliance with the UK GDPR and other data protection laws and with our data protection policies.
14. Be the first point of contact for the ICO and for internal and external stakeholders.
15. Support the formulation, implementation, and regular review of policy and guidance to ensure compliance with relevant legislation.
Person Specification
Essential Requirements:
1. Experience of leading and working within data protection and information rights.
2. An excellent understanding of the legal and regulatory landscape of information governance.
3. Evidence of personal commitment to continuous professional development.
4. Ability to demonstrate good judgment when analyzing and responding to complex issues.
5. Excellent oral and written communication skills.
6. Excellent interpersonal skills.
7. Ability to work autonomously and prioritize tasks appropriately.
8. Excellent organizational and planning skills.
9. Qualified to SCQF Level 9 (Degree) or equivalent experience.
Desirable Criteria:
1. Experience of performing the Data Protection Officer role, preferably in a public sector context.
2. Experience of enhancing the information governance culture in an organization.
Additional Information
Location
SFC offers hybrid working for its employees. This means that while the role is based at our Edinburgh office, there is substantial opportunity to work from home. A minimum of one day a month in the office is expected, but the balance between home and workplace working is determined by business need.
Key Rewards and Benefits
1. Normal full-time hours of work are 35 per week.
2. Annual leave entitlement of 26.5 days pro-rata, rising to 30 days after 4 years’ continuous service.
3. A flexible approach to hybrid working.
4. Annual pay review.
5. Eligibility to join the Civil Service Pension Scheme.
6. Support for continuous professional development.
7. Support for health and wellbeing.
8. Support for travel to and from work.
The Selection Process
How to Apply
To apply, please send your CV and cover letter. The selection panel will assess your application against the selection criteria in the Person Specification section above.
Pre-Employment Checks
As part of our pre-employment process, we will ask you to provide relevant documentation to show that you are eligible to work in the UK.
Disability Confident
If you need any adjustments to support your application, please contact us.
#J-18808-Ljbffr