Description
Job Title: Data Protection Administrator
Department: Information Technology
Based at: Ewood Park stadium, Blackburn, Lancashire, BB2 4JF. Flexibility regarding location is required.
Reports to: I.T. Manager
Responsible for: N/A
Hours of work: 21 hours per week plus any additional hours necessary for the performance of duties. This may include evening and weekend work.
Contractual Status: Permanent
Job Purpose: To work with the established data protection steering committee and liaise with external data protection officer on legal matters. The role requires the individual to carry out day to day administrative duties that relate to data protection.
Duties and Responsibilities:
To be committed to ensuring the safeguarding and welfare of all stakeholders, promoting their well-being whilst maintaining professional boundaries;
To liaise with all departments on data protection matters;
To report to the data protection steering committee;
To liaise with DPO when required;
Monitor the DP inbox and action any requests as and when required;
To understand and lead with document Data Protection Impact Assessment forms with new projects;
To review policies annually and ensure they are up to date;
To make sure privacy policy is kept up to date;
To annually review and audit each department data footprint and ensure data minimisation is employed;
To data flow map common and new processes with personal data;
To take minutes during Monthly data protection meetings;
To collate and distribute agenda points for monthly data protection meetings with DPO steering group;
Handle data requests including subject access and erasure requests and co-ordinate with the relevant departments to facilitate the request within the required timeframe;
To organise and provide training to different departments to ensure they develop further their understanding of data protection and their responsibilities;
To investigate, document and report on any reported data breaches, following the clubs policies;
Manage the clubs information asset register and records of processing;
Ability to evaluate risk and can have a holistic view on processes.
Skills Required:
Strong interpersonal skills with the ability to communicate effectively both orally and in writing;
To have a pleasant and approachable demeanor;
At times, the ability to work with the minimum of supervision;
The ability to work as part of a team, demonstrating a willingness and ability to perform all functions required of team members;
Highly organised with the ability to prioritise;
A willingness to undertake further training and professional development;
A confident and conscientious approach to work;
Be able to document procedures;
Be able to adapt and learn effectively;
Be able to use Microsoft 365 suite and MS Teams for video conferencing;
To be highly motivated and have a keen learning for data protection laws and regulations;
A critical thinker and be able to analyse and evaluate potential projects from a personal data risk perspective; and
To have good clerical skills, to be able to take notes, organise meetings and perform administration tasks related to Data Protection.
Knowledge Required:
Data protection laws and governance (Desirable);
Understanding data flows (Desirable);
Competent when using MS Teams & Office 365.
Qualifications Required:
Five GCSE’s at grade A*-C / 9-4 or equivalent;
DBS Check Required: Yes (Basic)