Overview
A Vacancy at North Tees and Hartlepool NHS Foundation Trust.
This is a senior position reporting to the Deputy CIO and accountable to the SIRO. The Head of Information Governance and Data Protection Officer (DPO) provides strategic leadership for the organisation’s Information Governance (IG) framework, ensuring compliance with statutory and regulatory requirements across data protection, confidentiality, records management, information rights (including FOI and SAR) and information security.
The post holder acts as the Group’s statutory DPO under the UK GDPR and the Data Protection Act 2018, offering independent oversight of compliance, advising on high‑risk processing and DPIAs, and serving as the primary contact for the Information Commissioner’s Office (ICO) and data subjects.
The role leads the IG function, develops and maintains policies, oversees the DSP Toolkit, coordinates training and awareness, and ensures effective incident management and risk assurance to the SIRO, Caldicott Guardian and Trust Board.
Key Relationships
- Chief Information Officer, Deputy Chief Information Officer, Caldicott Guardian, Senior Information Risk Owner, Executive Directors, CSU leads and Information Asset Owners
- Management teams and boards of the Group’s Limited Liability Partnerships (LLPs) in the role of DPO
- Clinical staff, corporate staff, digital / cyber teams, and information governance colleagues both within the Group and regionally and nationally including NHS England
Responsibilities
- Developing and maintaining policies, ensuring compliance with data protection laws, managing information risks, leading staff training, and overseeing audits and incident investigations
- Monitors compliance with data protection legislation, advises on privacy matters, manages data breaches, FOI and subject access requests, liaises with the ICO, and promotes staff awareness and training
- Prepare regular reports to the SIRO and Group Boards on Information Governance, data protection and FOIA compliance and assurance
- Leads IG strategy, policy and compliance across the Trust
- Advises senior leaders on data protection, confidentiality and security
- Manages IG audits, training and incident investigations
- Oversees secure storage and access to records
- Ensures compliance with legal and clinical documentation standards
- Independently monitors GDPR compliance and advises on data risks
- Manages data breaches, FOI, subject access requests and DPIAs
- Act as Asset Owner (IAO) for Information Governance departments
- Reports to senior leadership and liaises with the ICO when needed
- Liaise with partner organisations, suppliers and researchers to establish compliant data flows and agreements (e.g., DSAs, IGAs, DTAs)
- This is a non‑clinical role with no direct contact with patients
Benefits and Support
We will support staff through inclusive and supportive workplace with health and well‑being initiatives, staff benefits and opportunities for personal and professional development.
We support the ‘Making Every Contact Count’ approach to behaviour change in the promotion of health and wellbeing of individuals and communities.
Delivery of the Group values and behaviours when communicating or dealing with members of the public.
Support patients, members of the public and staff regarding their right to information under the Data Protection Act 2018, General Data Protection Regulation (GDPR), FOI Act 2000 and the Environmental Information Regulations 2004.
Location and Working Conditions
South Tees Hospitals NHS Foundation Trust and North Tees and Hartlepool NHS Foundation Trust now form University Hospitals Tees, and you may be required to work at any site across both Trusts.
The role is non‑clinical and does not involve direct contact with patients.
Closing Date
This advert closes on Monday 30 Mar 2026.
#J-18808-Ljbffr…
