Data Protection and Governance Manager
Job summary
The post holder will lead and coordinate the Federations corporate governance, data protection, complaints, incidents and consultancy functions, while driving the development and growth of ARC management and consultancy services. They will provide expert internal and external advice across outsourced data protection, governance, policy development, audits, compliance reviews and improvement activity. The role ensures statutory, regulatory and contractual obligations are met, delivering high quality policies, reviews, formal responses and actionable learning that results in measurable improvement. A key element of the position is building trusted relationships with external clients, identifying new opportunities and supporting the sustainable expansion of the ARC Management and Consultancy portfolio.
Main duties of the job
The role will oversee the integration of corporate governance, information governance, risk management, complaints handling and incident management into a coherent and effective framework. The post holder will ensure statutory, regulatory and contractual obligations are consistently met, and that governance systems support robust decision making and organisational accountability. They will lead the creation, review and implementation of governance, data protection, confidentiality, complaints, incident and related policies for both the Federation and external clients, ensuring these remain current, legally compliant and aligned with best practice. They will maintain governance registers and assurance processes, including risk registers, declarations of interest and standards of business conduct, ensuring that documentation is accurate, timely and appropriately quality assured.
A key responsibility will be providing expert advice on UK GDPR, the Data Protection Act 2018, confidentiality, data sharing, records management, data subject rights, subject access requests and data protection impact assessments.
About us
Barnsley Healthcare Federation (BHF) is a collaborative, GPled organisation that supports primary care across Barnsley by providing highquality clinical services, governance expertise and operational support to local practices and system partners. It delivers a wide range of services including extended access, urgent care, specialist clinics, workforce development, digital innovation and practice support, all designed to strengthen general practice and improve patient outcomes. BHF works closely with PCNs, the ICB and wider health and care partners to ensure resilient, safe and effective primary care provision. Alongside its operational services, the Federation also provides specialist governance, dataprotection and consultancy support through ARC Management and Consultancy Services, helping practices and external organisations meet regulatory requirements, improve compliance and enhance organisational performance. BHF is recognised for its strong governance standards, collaborative approach and commitment to improving healthcare for the Barnsley population.
Job description
Job responsibilities
Job Statement
The post holder will lead and coordinate the Federations corporate governance, data protection, complaints, incidents and consultancy arrangements, while developing and growing ARC management and consultancy services. The role will provide expert advice internally and to external clients, including outsourced data protection, governance, policy development, audits, compliance reviews and improvement support.
The role will ensure statutory, regulatory and contractual requirements are met, provide high-quality policies, audits, reviews, advice and formal responses, and translate learning into measurable improvement. The post holder will build trusted external client relationships, identify new opportunities and support sustainable growth of ARC Management and Consultancy portfolio.
Key Responsibilities
Lead the Corporate Governance and Data Protection Framework, integrating corporate, information, risk, complaints and incident governance.
Provide expert governance and data protection advice to the Board, Executive Team, senior managers and external clients.
Develop and grow ARC Management and Consultancy Services, identifying opportunities for governance, data protection, compliance, audit, policy and management support.
Deliver outsourced data protection services to external clients, including advice, compliance reviews, policy development, audits, training, action plans and ongoing assurance.
Manage external client relationships, agree deliverables, manage expectations and ensure high-quality, timely service delivery.
Support business development through service propositions, proposals, tenders, scopes of work and commercial discussions within delegated authority.
Create, review and implement governance, data protection, confidentiality, complaints, incident and policies for the Federation and external clients.
Plan and undertake data protection, governance, information governance and compliance audits, producing findings, recommendations, action plans and follow-up assurance.
Advise on UK GDPR, Data Protection Act 2018, confidentiality, data sharing, records management, data subject rights, subject access requests and data protection impact assessments.
Lead and support the development and submission of tenders, bids and proposals, including researching client requirements, developing service solutions, coordinating contributions, preparing high-quality tender documentation, pricing and scopes of work, ensuring submissions meet specification and deadlines, and supporting successful contract mobilisation and ongoing client relationship management.
Manage complaints and incidents, including triage, investigation oversight, correspondence, responses, escalation, action tracking, learning and closure.
Coordinate responses to information requests, data protection queries, subject access requests, complaints, incidents and governance enquiries, ensuring appropriate investigation and quality assurance.
Maintain systems for recording, monitoring and reporting complaints, incidents, breaches and governance events, producing trend analysis, dashboards and reports for Boards, committees and clients.
Monitor compliance with legislation, regulation, NHS requirements, contracts and policies, identifying gaps and coordinating remedial action.
Maintain governance registers and assurance processes, including risk, declarations of interest and standards of business conduct.
Lead or support audits, investigations and assurance exercises, translating findings into practical recommendations and improvement plans.
Ensure appropriate confidentiality, information security and records-management arrangements for the Federation and client organisations.
Identify governance and data protection risks and support managers and clients to implement and monitor mitigating actions.
Develop and deliver governance, data protection, complaints, incident and confidentiality training and consultancy support.
Maintain client/service records, monitor agreed deliverables and support service performance and reporting.
Identify themes across complaints, incidents, data protection matters and audits and use these to drive improvement.
Represent ARC and BHF professionally with external organisations, partners, regulators and other stakeholders, enhancing its reputation for governance and data protection expertise.
Provide effective governance and meeting support to the Board, Board Committees, management and other relevant meetings, including coordinating meeting dates, preparing and circulating agendas and papers, ensuring papers are complete and appropriately quality assured, attending meetings, taking accurate minutes and maintaining action logs to ensure decisions and actions are followed through to completion.
Coordinate the preparation, collation and distribution of governance papers, reports, briefings and supporting documentation, ensuring appropriate deadlines, document control, confidentiality and quality standards are maintained.
Develop and maintain a strong professional network across governance, data protection, information governance, healthcare, compliance and related sectors, attending relevant networking events, forums, conferences and stakeholder meetings to promote BHF and ARC services, identify opportunities, share good practice and develop potential client relationships.
Represent BHF and ARC professionally at external meetings, networking events, conferences, client meetings and sector forums, promoting the organisations management, governance and outsourced data protection services and building relationships that support business development and service growth.
Knowledge, Training & Experience
Degree-level qualification or equivalent experience in governance, data protection, information governance, compliance, risk or a related discipline, with relevant continuing professional development.
Substantial knowledge of NHS governance, complaints, incident management, risk, assurance and regulatory compliance.
Working knowledge of UK GDPR, the Data Protection Act 2018, confidentiality and information governance requirements.
Experience providing outsourced governance, data protection, compliance or consultancy services to external organisations.
Experience developing and implementing policies, procedures, governance frameworks and compliance documentation.
Experience planning and delivering governance, data protection or compliance audits and producing action-focused reports.
Experience managing complaints, incidents, investigations and formal responses.
Experience producing reports, dashboards and analysis for senior leaders, Boards, committees or clients.
Experience supporting business development, proposals, tenders, scopes of work and client relationship management.
Ability to interpret legislation, contracts, policies and governance data and convert these into clear advice and recommendations.
Experience of coordinating formal governance meetings and providing effective meeting secretariat support, including agenda planning, preparation and collation of papers, minute taking, action tracking and follow-up reporting.
Experience of developing and maintaining professional networks and representing an organisation at external meetings, forums, conferences, networking events or stakeholder groups.
Skills & Competencies
Excellent written and verbal communication, including drafting policies, audit reports, formal responses, proposals and client briefings.
Strong analytical and judgement skills, including assessment of risk and complex evidence.
Strong organisational and project-management skills across competing internal and external client priorities.
Strong consultancy and client-management skills, building trusted relationships and delivering practical solutions.
Confident business development, influencing and facilitation skills.
High standards of confidentiality, discretion, professional integrity and information security.
Ability to present complex governance, data protection, complaints, incident and audit information clearly to senior leaders and clients.
Proficient in digital systems and Microsoft Office for registers, analysis, reports, policies and controlled documentation.
Commercially aware, proactive and able to balance client service, quality, risk, deadlines and agreed scope.
Excellent organisational and meeting-management skills, with the ability to coordinate agendas, compile complex papers, take accurate minutes, maintain action logs and ensure actions and decisions are followed up within agreed timescales.
Ability to build and maintain a strong professional network, represent BHF and ARC confidently in external forums and networking environments, identify potential business opportunities and develop productive relationships with prospective and existing clients.
Person Specification
Qualifications
- Criteria- Essential
- Qualifications:
- Degree level qualification or equivalent demonstrable experience in governance, data protection, information governance, compliance, risk or a related discipline.
- Professional development:
- Evidence of continuing professional development relevant to governance, data protection, complaints, incidents or compliance.
- NHS / regulated environment:
- Relevant experience in an NHS, healthcare or other regulated organisation.
- Driving / travel:
- Ability to travel between organisational sites when required.
- Desirable:
- Relevant professional qualification in governance, data protection, information governance, risk or compliance.
- Formal specialist training or accreditation in data protection/information governance.
- Experience within primary care or an integrated care environment.
- Car driver/owner.
Experience
- Governance
- Experience of developing, implementing and monitoring corporate governance frameworks, policies, registers and assurance processes.
- Data protection
- Practical experience of applying UK GDPR, Data Protection Act 2018, confidentiality and information governance requirements.
- Complaints & incidents
- Experience managing or coordinating complaints and incidents, including investigation, responses, escalation, action tracking and reporting.
- Risk & assurance
- Experience of risk identification, assessment, mitigation, audit, assurance and monitoring of actions to completion.
- Reporting
- Experience producing accurate, concise reports and analysis for senior leaders, committees or boards.
- Policy & process
- Experience writing, reviewing, implementing and embedding policies, procedures and controlled documents.
- Regulatory compliance
- Experience interpreting and applying legislation, regulation, contractual requirements and national guidance.
- Confidential information
- Experience handling sensitive personal, patient, workforce and corporate information with appropriate confidentiality and discretion.
- Experience supporting Board/committee governance in an NHS organisation.
- Experience supporting data protection impact assessments, data sharing arrangements or data subject rights.
- Experience of serious incident reviews or complex multi-agency complaints.
- Experience developing governance dashboards or assurance frameworks.
- Experience presenting directly to a Board or formal committee.
- Experience leading organisation-wide process improvement.
- Experience liaising with external regulators, commissioners or partner organisations.
- Experience of information security or records-management improvement programmes.
Personal Qualities
- High integrity, discretion and professional judgement.
- Proactive, resilient and committed to organisational improvement and service growth.
- Commercially aware and confident identifying opportunities to develop BHF and ARC
- Able to build trusted, professional external client relationships with a strong customer-service focus.
- Confident, professional and approachable, with the interpersonal skills to build relationships, network effectively and represent ARC positively with clients, partners and external stakeholders.
- Able to challenge constructively where governance, data protection, complaints or risk requirements are not met.
- Compassionate and respectful with complainants, patients, carers, staff, clients and stakeholders.
- Flexible and calm when responding to urgent, high-risk or client-sensitive matters.
- Committed to equality, diversity, inclusion, dignity and confidentiality.
Knowledge and Skills
- Knowledge
- Strong understanding of NHS governance, complaints, incident management, risk, assurance and quality requirements.
- Knowledge of primary care governance and local/regional NHS frameworks.
- Data protection knowledge
- Good working knowledge of UK GDPR, Data Protection Act 2018, confidentiality, information security and records management.
- Knowledge of current NHS data protection and information governance guidance.
- Analytical skills
- Able to analyse complex, sensitive and conflicting information and reach sound, evidence-based judgements.Advanced reporting, data visualisation or trend-analysis skills.
- Communication
- Excellent written and verbal communication; able to draft sensitive responses and present complex issues clearly.
- Experience of delivering governance or data protection training.
- Planning
- Able to prioritise competing demands, work independently and meet statutory, regulatory and organisational deadlines.Formal project or programme management training.
Disclosure and Barring Service Check
This post is subject to the Rehabilitation of Offenders Act (Exceptions Order) 1975 and as such it will be necessary for a submission for Disclosure to be made to the Disclosure and Barring Service (formerly known as CRB) to check for any previous criminal convictions.
Employer details
Employer name
Barnsley Healthcare Federation
Address
Barnsley Healthcare Federation CIC
BHF Priory Centre
Pontefract Road, Lundwood
Barnsley
South Yorkshire
S71 5PN
United Kingdom
Employer's website
https://barnsleyhealthcarefederation.co.uk/