Job description
Summary of the role:
This role involves working a minimum of 3 days from the office.
- Inform and advise the company, contractors and employees who carry out processing of its' obligations under the GDPR, DPA and other Union / Member State DP provisions; ensuring the controllers and data subjects are well informed about their data protection rights, obligations and responsibilities
- Draw the business attention to any non-compliance or failures to comply with the applicable data protection rules or risk management practices and give advice / provide corrective action / recommendations to the business about the interpretation or application of data protection regulations
- Monitor compliance with the DP regulation and with the policies of the controller or processor in relation to the protection of personal data, including the assignment of responsibilities, awareness-raising and training of staff involved in processing operations, and the related audits;
- Provide advice where requested as regards the DP impact assessment and monitor its performance pursuant to Article 35;
- Act as the primary contact point for the supervisory authority and for individuals whose data is processed (employees, customers etc) on issues relating to processing, including the prior consultation referred to in Article 36, and to consult, where appropriate, about any other matter;
- Production and maintenance of data maps and record of processing activities;
- Management and evaluation of third-party relationships with suppliers and processors ensuring appropriate due diligence has been carried out, correct decisions made and contracts in place;
- Complete/co-ordinate the completion of all Subject Access Requests (SAR) and the exercising of other rights available to individuals;
- To ensure that the DP laws are embedded across the organisation and that both actions and remedial work in line with the legislation and guidance is achieved and that organisational risk is identified and action taken
- Ensure Risk Registers, Business Continuity Plans and Crisis Management Plans understood, owned, updated and tested by the business
- To develop forward plans that will set out yearly and three yearly objectives matched against the business objectives
- Ensure that the information governance framework meets and remains effective in meeting current and evolving data protection standards.
- Identify any gaps or potential improvements, developing strategies, managing any plans and actions agreed, effectively and efficiently.
- All other tasks required within the role
- must have previous experience as a data protection officer with a clear understanding of the major privacy frameworks
- demonstrable experience in managing data incidents and breaches
- ability to make good judgements regarding data privacy risks and to prioritise resources and activity around managing those risks
- experience in developing policy and compliance training
- detail-orientated approach needed to recommend and implement strategic improvements to data privacy, data protection and risk management issues
- be able to organise, plan and manage multiple tasks and projects at any given time
- must have excellent written and verbal communication skills
- be flexible, pro-active and respond positively to change
- good IT skills
- values of making a positive impact, working on own initiative as well as being a team player
- experience / understanding of ISO 27001 and ISO 9001 compliance is desirable
- ideally to hold one of the following certifications: Certified EU GDPR Practitioner (C GDPR P), Certified Information Privacy Professional (CIPP), BCS Practitioner Certificate in Data Protection (CDPO), Certified Data Protection Officer (C-DPO)
About apetito
CEO: Paul Freeston
Revenue: Unknown / Non-Applicable
Size: 1001 to 5000 Employees
Type: Company - Private
Website: www.apetito.co.uk
Year Founded: 1950