Job summary
- Main area
- Digital
- Grade
- Band 6
- Contract
- Permanent: The postholder will be required to travel across MIAA footprint and will be expected to work from client/office sites as and when required to meet the service needs of the organisation
- Hours
- Full time
- Flexible working
- Job ref
- 287-MIAA-12-26
- Employer
- Liverpool University Hospitals NHS Foundation Trust
- Employer type
- NHS
- Site
- MIAA Regatta Place
- Town
- Liverpool
- Salary
- £39,959 - £48,117 per annum
- Salary period
- Yearly
- Closing
- 01/10/2026 23:59
Employer heading
Information Governance Officer
Band 6
Job overview
We are looking for and experienced and enthusiastic Information Governance Officer to join our successful Information Governance Team working with clients across the Northwest and beyond.
In your role you will provide support to existing NHS and Public Sector MIAA clients, individually, at place and at system level, to ensure that they meet highly complex legal and regulatory obligations in relation to Information Governance including confidentiality, information security, Data Protection, Freedom of Information and GDPR.
Working with clients, the successful applicant will:-
- support clients to ensure that they meet highly complex legal and regulatory obligations in relation to Information Governance including confidentiality, information security, Data Protection, Freedom of Information and GDPR.
- act as a trusted advisor and subject matter expert on data protection and information governance to cross community programmes
- support clients to develop a robust information governance framework
- design and monitor technical policies, systems, and processes to ensure effective compliance with relevant regulatory and legal obligations.
- deliver and maintain certification to relevant Data Protection and Privacy standards and ensure compliance with highly complex, technical standards and certifications.
Main duties of the job
The Information Governance Officer will provide efficient and effective support to the clients and will assist in all aspects to maintain and achieve IG frameworks which support clients to meet their statutory, regulatory and performance obligations in relation to the Data Protection Act 2018 and the General Data Protection Regulations, confidentiality, information sharing, incident, and risk management.
To assist colleagues and clients, and to work towards agreed objectives to establish a proactive and integrated approach to IG through developing and maintaining robust and effective policies, systems and processes that ensure the IG function is supported throughout clients.
To be first point of contact to investigate and make recommendations on highly sensitive or contentious information supplied from patients, their relatives, staff colleagues and ex-ternal organisations which may result (often covertly) in identification of performance is-sues, leading to complex analysis resulting in formal Trust action being recommended.
To support clients by assisting in the co-ordination of the Data Security Protection Toolkit (DSPT) and to independently develop and implement improvement plans in areas where required to ensure continued compliance and improvements are achieved, often acting without reference to manager
Working for our organisation
MIAA is an NHS Shared service, hosted by Liverpool University Hospitals NHS Foundation Trust. MIAA is the predominant provider of internal audit services to over 60+ NHS and public sector organisations in the Northwest and beyond. MIAA offer clients a number of services in addition to internal audit including Solutions: Information Governance, Anti-Fraud, Technical Risk Assurance, Clinical Coding and Healthcare Quality.
MIAA’s budgeted turnover is 16 million, which is demonstrative of the organisation’s ambitious and strategic goals.
We are committed to equity, equality, diversity and inclusion, welcoming applications from people of all backgrounds, identities and lived experiences.
Staff benefit from flexible/hybrid working, a generous pension scheme, protected learning time and opportunities for development and career progression.
We promote a respectful, supportive and flexible working environment and operate zero tolerance to bullying, harassment and discrimination.
We particularly welcome applications from Black, Asian and minority ethnic communities, LGBTQ+ individuals, disabled people, carers, returners and other under‑represented groups.
Applicants with a disability who meet the essential criteria will be offered an interview, and reasonable adjustments will be made throughout recruitment and employment.
Detailed job description and main responsibilities
To interpret routine and complex facts associated with the Data Protection Act 2018, the General Data Protection Regulations, Caldicott Guidance, Codes of Confidentiality, and any other relevant guidance and legislation as part of the IG agenda.
To proactively support and promote the IG culture at client organisations.
To assist the senior colleagues and often lead in the development of policies, procedures, and guidance in all areas of IG and to propose amendments to improve organisational practice, policy, or plans.
To assist the team to produce and gather evidence for the timely completion of the client DSPT submissions.
To undertake and analyse the information governance risks and provide guidance and support to clients to manage information governance related risks in a way that ensures data protection compliance.
Lead and support the Information Asset Owners/Administrators within the clients to complete necessary reviews, encouraging them to complete risk assessment to ensure any identified risks are escalated as appropriate.
Support the population of client DSPT (and other IG work) action plans and follow up on out-standing actions via email, telephone and on occasion face to face with the toolkit’s assertion owners.
Supervise colleagues to provide administrative support for the training and maintenance of client information asset register.
Supervise colleagues to provide administrative support for the training and maintenance of client data flow mapping activity to ensure all the flows are recorded accurately within clients, and between partner organisations.
Supervise colleagues for any other related IG tasks to encourage an increase in knowledge to support the wider client staff.
Provide support and assistance to the Data Protection Officer for the completion of Data Protection Impact Assessments, which may, in turn, lead to the completion of the Digital Technology Assessment Criteria with involvement of the Clinical Safety Officer.
To develop bespoke training for areas of information sharing, data flows, and any other related IG subject.
For further information regarding key responsibilities and accountabilities please read the job description and person specification in full.
Person specification
Qualifications
Essential criteria
- Relevant degree or equivalent in information governance or cyber/information security related subjects
Desirable criteria
- Relevant BCS qualification in data protection or cyber/information security and consideration of other courses such as PRINCE Project Management, ITIL, BCS FOI, EIR or other legislative qualification
- Audit qualification or relevant experience
Experience
Essential criteria
- Experience in us of Microsoft products such as Access, Word, Excel, PowerPoint and O365
- Demonstrable experience working with a healthcare governance or assurance role
- Experience of staff supervision
- Experience of providing training sessions
- Ability to produce high quality written material
- Demonstrable advanced knowledge of data protection, GDPR, Caldicott, information security definitions and guidelines with examples of interpretations of legislation in an operational situation
- Awareness of confidentiality issues in NHS including legislative codes and guidance documentations as detailed
Desirable criteria
- Previous office experience
- Understanding risks and vulnerabilities. Understanding of best practices for securing digital systems/tools
- Demonstrable experience in knowledge and understanding of the workings of the NHS
Documents to download
Further details / informal visits contact
- Name
- Paula Fagan
- Job title
- Interim Digital Director
- Email address
- [email protected]
- Telephone number
- 07825592866
If you have problems applying, contact
- Address
-
L9 7AL
- Telephone
- 0151 706 4666
List jobs with Liverpool University Hospitals NHS Foundation Trust in Administrative Services or all sectors









