Skip to main content

This site is independent of the NHS and the Department of Health.

Please wait, loading

Job summary

Main area
Information Governance
Grade
Band 6
Contract
Permanent
Hours
Full time - 37.5 hours per week
Job ref
100-AC307-1025
Employer
Hywel Dda University Health Board
Employer type
NHS
Site
to be confirmed
Town
to be confirmed
Salary
£39,263 - £47,280 per annum
Salary period
Yearly
Closing
05/11/2025 23:59
Interview date
14/11/2025

Employer heading

Hywel Dda University Health Board logo

Senior Information Governance Officer

Band 6

Our Hywel Dda values reflect who we are and how we behave. We continuously work together to be the best we can be as we strive to develop and deliver excellent services, putting people at the heart of everything we do. Throughout our recruitment process you will be asked to think about how you would demonstrate these values in the way that you work with us.

If you are registered Health Care professional considering relocating to the Hywel Dda area in West Wales please don’t hesitate to contact our recruitment campaigns team directly via [email protected]

To keep up to date with our latest recruitment activity follow us on Facebook (Swyddi Hywel Dda Jobs), LinkedIn or on Twitter @SwyddiHDdaJobs

Hywel Dda University Health Board reserve the right to close vacancies after 24 hours if a large number of suitable applications are received. We encourage early applications to ensure consideration for a post.


 

Job overview

Senior Information Governance Officer (Band 6):

  • Supports the Head of Information Governance and IG Managers to ensure the Health Board complies with data protection laws and good IG practice.
  • Provides expert advice, delivers training, and helps with policies, records management, and Subject Access Requests.
  • Requires strong knowledge of data protection, excellent communication, analytical skills, and experience in IG.

Main duties of the job

The main duties of the Senior Information Governance Officer (Band 6):

  • Lead on managing and investigating information governance (IG) breaches.
  • Support and approve Data Protection Impact Assessments (DPIAs).
  • Conduct and follow up on IG audits and report findings.
  • Provide expert IG advice and operational support to staff at all levels.
  • Identify and report on breach trends, and create improvement plans.
  • Support the implementation of IG incident management procedures.
  • Review and maintain IG systems for compliance.
  • Assist in reporting data breaches to the ICO and informing data subjects.
  • Deliver IG training and draft guidance documents.
  • Oversee Access to Health Records requests and ensure statutory compliance.
  • Line manage IG Officers and Access to Health Records Clerks.
  • Communicate with staff, the public, and external organisations on IG matters.

The ability to speak Welsh is desirable for this post; English and/or Welsh speakers are equally welcome to apply.

Working for our organisation

Hywel Dda University Health Board plans and provides NHS healthcare services for people living in Carmarthenshire, Ceredigion, Pembrokeshire, and bordering counties.

We have over 13,000 staff and together we provide primary, community, in-hospital, mental health and learning disabilities services.

We work in partnership with the three local authorities, as well as public, private and third sector colleagues, including our valued team of volunteers.

Our services are provided in:

  • Four main hospitals: Bronglais Hospital in Aberystwyth; Glangwili Hospital in Carmarthen; Prince Philip Hospital in Llanelli; and Withybush Hospital in Haverfordwest
  • Five community hospitals: Amman Valley and Llandovery hospitals in Carmarthenshire; Tregaron Hospital in Ceredigion; and Tenby and South Pembrokeshire hospitals in Pembrokeshire
  • Two integrated care centres: Aberaeron and Cardigan in Ceredigion, and several other community settings
  • 47 general practices (six of which are health board managed practices); dental practices (including four orthodontic); 97 community pharmacies; 43 general ophthalmic practices; and 8 ophthalmic domiciliary providers
  • Numerous mental health and learning disabilities services

Detailed job description and main responsibilities

Key Responsibilities

  • IG Breach Management: Lead on IG breaches, managing incidents from initial report to closure, including advice on recovery, containment, and lessons learned. Support the IG Breach Lead with high-level breaches.
  • Data Protection Impact Assessments: Support and approve DPIAs, identify risks, and advise on mitigation, escalating when necessary.
  • Auditing: Lead on audits related to IG breaches, report findings, and support the IG Team in raising awareness of responsibilities under Data Protection legislation.
  • Expert Advice: Provide IG advice to staff at all levels, draft reports, and support operational IG tasks (e.g., data sharing agreements, privacy notices, Subject Access Requests).
  • Trend Analysis: Identify and report on breach trends, produce statistics, and create improvement plans.
  • Incident Management: Support implementation of IG incident management procedures and assist staff in reporting incidents.
  • Compliance Monitoring: Review and maintain IG systems, ensure compliance with legislation, and take action on non-compliance.
  • Training & Communication: Deliver training, draft guidance, and communicate complex IG issues to staff and external stakeholders.
  • Records Management: Oversee Access to Health Records requests, ensure statutory compliance, and adapt systems as needed.
  • Audit Support: Participate in internal and external audits, produce reports, and maintain accurate records.
  • Redaction & Guidance: Redact sensitive information for disclosures and provide guidance on retention periods and IG policies.
  • Resource Management: Ensure efficient use of resources and support the department’s operational needs.
  • Line Management: Manage IG Officers and Access to Health Records Clerks, ensuring training and performance objectives are met.

You will be able to find a full job description and person specification attached within the supporting documents.

The Health Board is committed to supporting its staff to fully embrace the need for bilingualism thereby enhancing patient and service user experiences.  In our commitment to increase the number of staff who are able to communicate in Welsh with patients and professionals, we welcome applications from Welsh speakers.

The ability to communicate in Welsh is desirable for this post. If you do not meet the Welsh Language requirements specified, the Health Board offers a variety of learning options and staff support to help you meet these minimal desirable requirements during the course of your employment with us.

Interviews will be held on  14/11/2025

Person specification

Qualifications and Knowledge

Essential criteria
  • Degree level or equivalent management experience
  • Further knowledge to postgraduate diploma level e.g: - Data Protection professional qualification e.g. BCS Foundation Certificate / Practitioner Certificate in Data Protection - Expert knowledge and understanding in the principles of the DPA, GDPR, FOIA and NHS Code of Confidentiality, - Expert knowledge in the areas of Caldicott, patient confidentiality, WASPI and information sharing, privacy notices, Data Protection Impact Assessments and information security.
  • Evidence of continuous professional development
Desirable criteria
  • Knowledge of risk management processes
  • Knowledge of Health and Care Standards

Experience

Essential criteria
  • Previous information governance experience
  • Previous breach/complaint management experience
  • Previous Data Protection Impact Assessment support & approval experience
  • Previous experience of report preparation and delivery
  • Previous experience of dealing with complex and confidential issues
Desirable criteria
  • Previous information/ IT security experience
  • Previous auditing experience
  • Previous project management experience
  • Previous experience of working within the NHS or other healthcare setting
  • Successful change management and negotiation experience
  • Previous experience of risk assessment
  • Experience of using Datix system

Other

Essential criteria
  • Ability to work in a busy, sometimes stressful environment, and to deal with interruptions and changing priorities
  • Professional and confident manner
  • Self-motivated, dynamic and proactive
  • Adaptable and flexible to meet any changing service needs with enthusiasm
  • Highly confidential always
  • Ability to deal positively with difficult situations e.g. verbal abuse from patients / staff on an occasional basis
  • Commitment to embedding excellent information governance practices into all levels of staff and the organisation as a whole
  • Ability to work effectively at home or away from agreed base but still within HDUHB’s region
  • Ability to travel within HDUHB’s geographical area
Desirable criteria
  • Welsh Speaker (Level 1)

Employer certification / accreditation badges

Veteran AwareNo smoking policyCymraegDisability confident employerStep into healthCarer Confident (With Welsh translation)Defence Employer Recognition Scheme (ERS) - GoldCore principlesStonewall 2023 Bronze

Applicant requirements

Welsh language skills are desirable

Documents to download

Apply online now

Further details / informal visits contact

Name
Patrycja Duszynska
Job title
Head of Information Governance
Email address
[email protected]
Telephone number
07790 890773
Apply online nowAlert me to similar vacancies