EPR Programme Information Governance Lead
18 days ago
London
Role Overview Role / Job Title: EPR Programme Information Governance Lead Work Location: Lincolnshire (United Kingdom) Mode of Working: Hybrid Onsite Requirement: To be agreed based on project needs (typically 1 2 days per week onsite) Key Responsibilities and Activities Leading the Delivery Team and play an active role in the management and delivery of clinical digital systems across United Lincolnshire Teaching Hospitals Trust. Enable compliance with NHS Service Standards including DTAC, DSPT, Cyber Security, Clinical Safety, and Accessibility requirements. Provide strong leadership to programme delivery teams, fostering collaboration and accountability to achieve successful outcomes. The Role This role will require ULTH EPR Programme Information Governance Lead who leads IG activity across the design, testing, implementation, and adoption of the EPR, ensuring ULTH continues to meet its statutory obligations regarding Information Governance and Data Protection. As the programme's IG subject-matter expert, the post-holder will interpret national policy and guidance and lead the development and/or revision of IG-related programme collateral, including Data Privacy Impact Assessment documents, Data Sharing/Data Processing agreements, and Data Security & Protection Toolkits (DSPTs). The post-holder will also lead risk mitigation and oversee the management of data risks associated with implementing the EPR across the Trust. Your Responsibilities Provide leadership and guidance to programme delivery teams to ensure success. Serve as the programme's first point of contact for all data protection matters. Foster a strong data protection culture by informing and advising programme leadership on their legal obligations under Data Protection legislation. Provide expert advice to the Trust EPR Programme Senior Responsible Owner (SRO), the Programme Director, and all members of the Trust EPR Programme team responsible for decisions about personal data processing. Ensure the monitoring and reporting of compliance with the law and Trust policies, raising awareness up to Trust EPR Programme Board level (via the Compliance Advisory Group). Lead any required changes to IG training and to policies relating to audit and incident investigation. Co-operate with the Information Commissioner's Office (ICO), the UK regulator of information rights. Act, alongside the Trust DPO, as an additional point of liaison for data subjects-including patients, staff, and others whose information is processed by the Trust within the scope of the EPR Programme. Data Protection and Information Governance Ensure data protection is considered wherever there is a risk to personal data, including: a. In-depth Data Protection Impact Assessments b. Legally binding contracts c. Signed Data Sharing Agreements d. Clear accountability for data within integrated working arrangements e. Representing the ULTH EPR Programme on IG matters Manage any additional Information Governance (IG) resources employed by ULTH to deliver programme-related IG activities. Manage clear proposals and draft documentation for the creation and/or modification of IG policies and procedures. Provide expert IG advice, strategic leadership, and support to the Trust EPR Programme. Exercise overall line management of any additional IG resources employed by the Trust, ensuring efficient, quality-driven service delivery and performance. Support the Trust on the strategic direction of Information Governance as it relates to EPR implementation and adoption. Compliance and Risk Management Maintain up-to-date expert knowledge of Data Protection legislation and NHS practice, and how they apply to the Trust EPR. Ensure data protection is embedded by default and by design in the Trust EPR and associated third-party systems. Support the Trust in responding to direct contact from data subjects relating to the Trust EPR. Ensure appropriate confidentiality is maintained in performing all tasks. Report any potential conflicts of interest to the highest management level. Update, develop, and establish policies, procedures, and other measures to ensure compliance with GDPR as it relates to EPR implementation and adoption. Monitor compliance with these measures and report as required, providing updates to the EPR Board and Trust IG groups. Serve as the EPR Programme's data protection expert on projects involving new or innovative information processes. Data Sharing and DPIA Ensure appropriate data sharing and processing agreements are in place. Ensure all data sharing agreements are formally reviewed at contract review meetings. Lead the development of Data Protection Impact Assessments and manage proposed mitigations. Consult the Information Commissioner's Office (ICO) where required and agreed with the Trust DPO/Head of IG. GDPR and DSPT Assurance At a high level, ensure the EPR Programme can demonstrate compliance with all GDPR requirements via the Data Security and Protection Toolkit, including: Current and comprehensive GDPR policies and procedures. Fit-for-purpose information for patients and data subjects. A database of processing activities as required by GDPR. Evidence of privacy by design and by default. Evidence of appropriate Data Protection Impact Assessments. Strategic Information Governance Lead operational IG for the EPR Programme, advocating IG as a critical activity. Promote transparency in information processing to patients and staff. Support the Trust in establishing a clear IG strategy and improvement plan. Ensure compliance with: UK General Data Protection Regulation (UK GDPR) UK Data Protection Act 2018 Caldicott Report 1997 (and amendments 2013 and 2016) DoH Confidentiality Code of Practice Records Management Code of Practice 2023 Freedom of Information Act 2000 CQC regulations Ensure appropriate escalation of information risks and support SIRO reporting. Liaise with the Trust Caldicott Guardian. Facilitate close liaison between IG, Information Security, and Clinical Safety teams. Your Profile Essential Skills / Knowledge / Experience Making complex IG decisions and acting upon them. Applying information law to healthcare settings. Excellent interpersonal and negotiation skills. Strong written and verbal communication skills, including Board-level reporting. Ability to assimilate new systems and technologies. Flexibility in a rapidly changing Data Protection legislative environment. Ability to analyse legislation and national best practice and apply to organisational processes. Ability to manage own time in line with EPR programme requirements. Must be able to undertake long-term VDI usage. Desirable Skills / Knowledge / Experience Professional Information Governance knowledge through postgraduate qualification or equivalent experience. Further professional qualifications in Information Governance aligned with BCS Practitioner Qualifications in Data Protection. Application Support To be published on job boards from below onwards If you need support in completing the application or require a different format of this document, please contact or call TCS London Office on 02031552100 / +44 204 520 2575 with the subject line: "Application Support Request" . TPBN1_UKTJ