Data Security Compliance Advisor (12 months FTC)
Job overview
Title: Data Security Compliance Advisor (12 months FTC)
Job type: 12 month fixed term contract
Reporting to: Data Protection Officer (DPO)
About the job: For 12 months, the successful candidate will become a member of the small, friendly Data Security Compliance Team and play an important role in keeping data protection and data security compliance activities in focus and on track throughout the Club.
Key Tasks / Accountabilities:
* Be primarily responsible for the end to end process of fulfilling data subject requests made under the UK General Data Protection Regulation (UK GDPR), such as subject access requests and erasure requests, as well as requests for information from other organisations, such as law firms, law enforcement or government departments.
* Build on existing internal documentation and communications regarding the data subject request process so that:
o Other departments are clear about their responsibilities, and
o The Data Security Compliance Team handles requests in the most structured, efficient and cost effective manner possible, while complying with UK data protection legislation and meeting legal deadlines.
* Work with members of the team on the development and integration of tools involved in the data subject request process, such as the OneTrust Privacy Rights Automation module and other internal platforms.
* Share the responsibility to conduct reviews of existing assessment and accountability processes and work with business stakeholders to create new ones where required. Assist with the recommendation of improvements to achieve compliance and reduce risk and help to ensure the delivery of agreed recommendations. Examples of processes are:
o Data Protection Impact Assessments (DPIAs)
o Legitimate Interest Assessments (LIAs)
o Legal Basis for Processing Checklists
o Records of Processing Activities (ROPA)
o Assist with the optimisation of the above record, list and assessment processes and the continual improvement of associated documentation.
o Contribute to the application of Club wide processes such as Data Protection by Default and by Design, working with business teams and the IS department as necessary.
o Assist in the refresh and communication of the Club's Data Security Policy set.
o Contribute to the development and execution of data protection and data security training, awareness campaigns and eLearning training rollouts.
o Support the DPO in ensuring the importance of data security compliance is appropriately communicated across the Club by assisting with the production of Club communications as well as articles and guidance for the team’s intranet presence.
o Assist with the production of well written and carefully considered advice and guidance in response to data protection and data security enquiries, both internal and external.
o Be willing to take on ad hoc challenges and find solutions for implementation.
o Represent the team in meetings and for projects and initiatives, where required.
o Attend industry events, conferences and seminars to keep up to date with the threat landscape and any upcoming legislative change.
Essential Skills & Experience Required:
* Strong knowledge and experience of current and upcoming UK data protection law, e.g. the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018, Privacy and Electronic Communication Regulations (PECR) and familiarity with guidance published by the Information Commissioner’s Office.
* One or more recognised data protection qualifications, e.g. UK GDPR Practitioner, CIPP/E, CIPM.
* Extensive experience of fulfilling data subject requests made under the UK GDPR.
* Experience of working in a team where providing guidance and advice about UK data protection law to internal and external stakeholders is a primary focus.
* Proven experience in handling confidential and sensitive information.
* First rate planning and organisation skills with the ability to manage conflicting priorities while meeting tight deadlines.
* Must have the ability to work well under pressure while maintaining discretion.
* Ability to work with minimum supervision, as well as collaboratively and flexibly with others to achieve team objectives.
* Excellent written English coupled with clear and articulate verbal communication skills.
* Methodical, with a high attention to detail and accuracy.
* Highly motivated and focused with a desire to help, use initiative and add value.
* Confident general IT skills, ideally primarily with use of Google Workspace and Adobe Acrobat Pro, but as a minimum, with Microsoft Office / O365 software suites.
* Highly proficient use of Google Workspace (Gmail, Drive etc), Microsoft Office (Outlook, Word and Excel in particular) and use of the redaction tools and other key features in Adobe Acrobat Pro.
* Familiar with information security best practice, e.g. ISO 27001, Cyber Essentials.
* Awareness of payment card industry standards and requirements, i.e. Payment Card Data Security Standard (PCI DSS).
The Caravan and Motorhome Club is committed to employing a diverse workforce. All applications are treated equally and we recruit purely on the basis of skills and experience. We know our greatest strength is our people, so differences are celebrated, and we strive to create an environment where colleagues feel respected and valued for their unique potential.
Apply now
To apply for this role just send your up-to-date CV and a covering letter to our Head Office recruitment team.
You'll enjoy lots of benefits working at our head office. Check out why it's great to work at the Club.
Call our HR team for more information about working for the Club.
01342 778 304 (Head office vacancies)
01342 336 788 (Sites vacancies - Monday, Tuesday or Friday only)
#J-18808-Ljbffr