General Data Protection Regulation (GDPR) Strategy

Size: px
Start display at page:

Download "General Data Protection Regulation (GDPR) Strategy"

Transcription

1 General Data Protection Regulation (GDPR) Strategy NHS Digital s Approach to Compliance Published October 2017 Copyright 2017 Health and Social Care Information Centre. The Health and Social Care Information Centre is a non-departmental body created by statute, also known as NHS Digital.

2 Contents Executive Summary 3 Introduction 3 Vision for GDPR Compliance 3 Strategic Approach 4 Discovery 4 Transition 4 Education 5 Assurance 5 Risks 6 Acceptance Criteria 6 Who will deliver the programme? 7 How we will do it? 7 Appoint a Data Protection Officer 7 Setting up of GDPR Work streams 8 GDPR Compliant Information Asset Register 9 Prioritisation of Compliance for Key Information Assets 10 Communication 11 Education 12 Use of Guidance in production of Documentation to support GDPR 13 Problem Solving Process 14 Governance 16 Timescales 16 Copyright 2017 Health and Social Care Information Centre. 2

3 Executive Summary The General Data Protection Regulation (GDPR) will be moved into European Law on 25th May It will be supported by the UK Data Protection Bill (to be moved into statute in 2017/18), which will be used to repeal the Data Protection Act of 1998 and support the implementation of this new European Regulation. This document sets out the Strategic Approach NHS Digital will take in moving towards GDPR Compliance, its Programme Team and proposed Governance Arrangements that will drive through the actions required to fulfil its obligations to its staff, partners and customers with regards to the Regulation. Introduction The General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) is a Regulation by which the European Parliament, the Council of the European Union and the European Commission intend to strengthen and unify data protection for all individuals within the European Union (EU). As the Safe Haven of NHS & Social Care Data, NHS Digital has a responsibility to ensure that its working practices mirror current and future UK and EU Legislation and that a Strategic Approach will be required to ensure that all of its staff are aware of new legislation, its impact and their role in compliance as well as providing assurance to its internal and external stakeholders that the assets, policies and procedures within NHS Digital are identified, examined and changed in order to evidence compliance by 2018/19. It should be noted that NHS Digital already has regard to the Data Protection Act 1998 and the Common Law Duty of Confidence in its working practices and can already demonstrate how it complies with these in its delivery of functions as set out in the Health and Social Care Act Therefore broadly, our NHS Digital programme of work is about tightening up current arrangements and ensuring we meet those parts of the GDPR that have now become mandatory, tackling those new elements of data protection included in GDPR and ensuring we can evidence compliance in all areas post May Vision for GDPR Compliance. By 25th May 2018, NHS Digital as the Safe Haven of NHS & Social Care Data will have examined its current Assets, Policies, Procedures and Processes with regards to its delivery of services and will be GDPR Compliant in all areas of its business Copyright 2017 Health and Social Care Information Centre. 3

4 Strategic Approach The Strategic Approach for NHS Digital is split into 4 distinct phases Discovery Assess current DPA 1998 Compliance across the organisation Comprehensively examine impact of GDPR and DP Bill on current services Redefine definition of an Information Asset with regards to NHS Digital Functionality Assess Current Information Asset Register and ownership of Assets both within NHS Digital and where joint ownership with other ALBs are identified Transition Appointment of a Data Protection Officer Introduction & Management of a Comprehensive, electronic Information Asset Register Changes to working practices (such as SAR Requests) to meet GDPR Compliance Changes to NHS Digital Policies, Procedures and Guidelines to support GDPR Changes to future Contract Management to meet GDPR Requirements Copyright 2017 Health and Social Care Information Centre. 4

5 Education Board and EMT Awareness with regards to the impact of GDPR on the organisation inc. fines for noncompliance Communication Plan to bring GDPR awareness across the organisation GDPR Awareness Mandatory E-Learning Training Package IAO Mandatory Annual E-Learning Package Assurance External Audit Programme from implementation to BAU DPO Led Audit Programme for NHS Digital Compliance Annual declaration by IAO of Assets as compliant DPO Led Audit Programme for Assets (3 year rolling programme) Copyright 2017 Health and Social Care Information Centre. 5

6 Risks A Recent Audit by the Government Internal Audit Agency (GIAA) found that the Programme had sufficient foundation and plans to move the organisation towards GDPR Compliance; but has identified the key risks to the organisation as: Governance arrangements fail to effectively steer and control the department wide activities to deliver GDPR Compliance by May 2018 Risk Management Arrangements fail to identify, evaluate, monitor and mitigate key risks to deliver GDPR compliance by May 2018 Key Activities to Deliver GDPR Compliance by May 2018 are not planned and/or prioritised effectively Therefore, the plans for GDPR Compliance that are overseen by the GDPR Steering Group and Programme Team must ensure that there are work packages in place and that plans are adhered to in order to mitigate these risks as much as possible Acceptance Criteria In scoping the GDPR Programme there have been 3 levels of Acceptance Criteria identified that NHS Digital could find itself in a position against. As the true impact of GDPR within NHS Digital is still in the Discovery Phase it is not clear which criteria the organisation will find itself in on 25 th May Level Acceptance Criteria 1 Optimum 2 Defensible 3 Sub-optimum Minimum Specification Fully GDPR Compliant in all parts of NHS Digital IAOs fully trained and signed up to IAO Charter GDPR Audit Programme in place and staffed appropriately All information Assets are identified All Information Assets, Policies and Processes are DPA 1998 compliant All Critical Assets have been identified and are GDPR Compliant GDPR Awareness across the organisation. All Assets are not identified No examination of NHS Digital Policies and processes against current legislation Lack of GDPR Awareness across the organisation Copyright 2017 Health and Social Care Information Centre. 6

7 However, Level 3 is not acceptable to the Board, and that a comprehensive programme of work is required to deliver Level 2 in the first instance and then Level 3 during 2018/19. Who will deliver the programme? The GDPR Programme will be delivered by existing staff within NHS Digital, in addition to their current role. A GDPR ABR Code within the Central Administrative Service used for staff to allocate their time against will be created for staff to log the work they are undertaking to implement GDPR. The Programme Team are set out below and can be contacted to give guidance and advise in their relevant workstream areas How we will do it? Appoint a Data Protection Officer Section 4; Article 37 of the GDPR Regulation sets out the requirement for the Designation of a Data Protection Officer (DPO). As a Public Authority who processes personal data, it is the responsibility of NHS Digital to ensure a DPO is appointed who can give advice, monitor Copyright 2017 Health and Social Care Information Centre. 7

8 compliance and act as the point of contact for internal and external stakeholders with regards to the organisation s function. The Head of Strategic Information Governance has been identified as the most suitable post holder within NHS Digital to carry out this function. This post holder will be setting up a team to oversee, manage and audit compliance with GDPR and will be setting out the plans for assurance by May Setting up of GDPR Work streams By taking the key changes from DPA 1998 and GDPR, as well as the key departments that will be affected by these changes, 16 Workstreams have been set up to manage individual key areas of GDPR Compliance. Each have a named lead and will produce monthly highlight reports to the GDPR Steering Board, so progress can be monitored and any issues in delivery can be identified early, and mitigations put in place. Workstream Communication Information we hold (Asset Register) Communication of Privacy Notices & PIAs Responsible Person Paul Butler Christina Munns John Varlow Individuals Rights inc. Data Portability/erasure Catherine Nicholson SARS Lawful basis for processing personal data Vanessa Kaliapermall Catherine Nicholson Consent Children (age change to adult) Data Breaches Data Protection by design Data Protection Officers Contracts Training and Education HR Information Security Records Management Catherine Nicholson John Varlow Neil McCrirrick John Varlow Catherine Nicholson Hazel Randall Carole Sheard Alison McTrusty Matt Lutkin Paul Harris Copyright 2017 Health and Social Care Information Centre. 8

9 GDPR Compliant Information Asset Register Within NHS Digital for some time, there has been an Information Asset Register (IAR), but this was maintained manually by the Operational IG Team to ensure compliance with the requirements for the IG Toolkit. The information kept on the register met with current IG Toolkit Requirements, but would not be sufficient to demonstrate compliance with GDPR. There has also been an acknowledgement that Information Asset Owners (IAOs) need to take more accountability and responsibility for the Assets they own, and ensure that they comply with current and future legislation. After a scoping exercise looking at Commercial off the Shelf products (COTS) products and initiatives within NHS Digital, the decision has been made that the Unified Register, already in use for the recording of Data Collections would be the electronic means for collecting and demonstrating evidence of compliance for all Information Assets owned or processed by NHS Digital. Once the product of choice had been identified, by liaising with the IAO Forum from within NHS Digital, the definition of an Information Asset was re-defined: - An Information Asset is Defined as: - A body of information, defined and managed as a single unit so it can be understood, shared, protected and exploited effectively. Information Assets have recognisable and manageable value, risk, content and lifecycles. And an extensive engagement and communication plan is planned to capture all information Assets within NHS Digital by December The Information Asset Register development will be approached in 4 phases: - Copyright 2017 Health and Social Care Information Centre. 9

10 Identification of all Information Assets and their owners (IAO) and their adherence to current DPA 1998 principles Gap Analysis of current Information Asset Register content with regards to GDPR Requirements Identification of Critical/Key Information Assets which MUST adhere to the principles of GDPR by May 2018 and workplans for adherence confirmed with each IAO All Information Assets must adhere to the principles of GDPR by the end of 2018 Prioritisation of Compliance for Key Information Assets Once the Information Asset Register has completed its 1 st iteration to match DPA 1998 and has been assured, there will be a requirement to identify the Key, Critical Assets NHS Digital which will be the priority in assurance that these will adhere to the principles of GDPR by May A Criteria for assessing Key Assets is set out below: - Value Impact of Information Asset on NHS Digital and its customers Very High High Moderate Internal and External Customers rely on this Asset to carry out their basic functions. Loss of this asset would have an adverse impact on the operation of NHS Digital and the Health and Social Care Sector and the delivering of patient care to England. The loss of this Information Asset would cause severe reputational and patient safety risk to the organisation and the NHS as a whole. The Identified Information Asset is one that is relied on to deliver a function within NHS Digital and its stakeholders. The loss of this asset would impact on one or more functions within care delivery for NHS Digital and the Health and Social Care sector. The loss of the Information Asset may cause considerable financial and reputational risk to the organisation and the NHS as a whole. The Information Asset is identified as one that does assist in the delivery of function into NHS Digital and/or Health and Social Care. The loss of this Asset may lead to a reduced capability for some functions within NHS Digital and Health and Social Care, with a possible reduction in patient care delivery, but Copyright 2017 Health and Social Care Information Centre. 10

11 Low Very Low other functions may allow care delivery to continue. The loss of this Asset may lead to a limited adverse effect in that it may reduce functions of an organisation, but that they would still be able to operate effectively The loss of this Asset may have some financial and reputational risk to NHS Digital and the NHS as a whole. The Information Asset is acknowledged in supporting the delivery of function into NHS Digital and/or Health and Social Care. The loss of this Asset may lead to a limited adverse effect in that it may reduce functions of an organisation, but that they would still be able to operate effectively. The loss of this Asset may have minor financial and reputational risk. The Information Asset is identified as not having a major impact on the delivery of services to NHS Digital or the Health and Social Care Sector as a whole. The loss of this Asset would have minimal impact on the delivery of patient care or the delivery of function within NHS Digital This exercise will be carried out by the Information Asset Workstream Lead and the Chair of the IAO Forum and identification is expected to be completed by December 2017 with adherence and evidence of GDPR Principles submitted into the Information Asset Register for Key Assets by March Communication Working with the Media and Communication Teams there are plans for a series of innovative Communication Campaigns in the run up to May Vlogs by Key NHS Digital Staff Use of External Website for customer awareness GDPR "Countdown Clock" to 25th May 2018 Communications Campaign Suggestions Board where staff can "pin" their queries Targeted Campaigns to key staff eg. IAO's GDPR Dedicated page on the intranet Copyright 2017 Health and Social Care Information Centre. 11

12 The Programme Lead for Communications is expected to produce a Comprehensive Communication Plan which will be passed to GDPR Steering Group and EMT for Approval. Education It is proposed that every member of staff within NHS Digital will receive a level of GDPR Training in the 2017/18 Operational Year IAOs Comprehensive GDPR Awareness and Accountability GDPR Workstream Leads GDPR Principles and applications Levels of awareness EMT & Board GDPR Awareness Training NHS Digital - All Staff GDPR Awareness Training The Communication Plan include a programme of campaigns and alerts within to ensure that all staff will have heard of GDPR and how to prepare themselves for it to move into Regulation in May However, it has been recognised that to ensure all staff are fully aware of the implications a more comprehensive education plan is to be developed: - Copyright 2017 Health and Social Care Information Centre. 12

13 Education Package Lunch & Learns and Webinars Aimed at Targeting all Staff within NHS Digital Looking at the Key principles and changes regarding GDPR and how to apply them into working practices within NHS Digital E-Learning Package for GDPR Awareness All staff within NHS Digital Mandatory before May 2018 Board Presentation on GDPR Principles and key changes External GDPR Practitioner - Delivery of key GDPR Principles to GDPR Workstreams Leads E-Learning Package for Information Asset Owners NHS Digital EMT and Board Aimed at awareness of key changes which may impact functions of NHS Digital GDPR Workstream leads to give them insight and documentation to support the delivery of the key changes regarding GDPR to their workstreams All IAOs within NHS Digital To support education and the assurance of Assets meeting GDPR principles Annual Mandatory Training to be supporting by the signing of an IAO Charter for assuring compliance Use of Guidance in production of Documentation to support GDPR When the GDPR Regulation (EU) 2016/679 was released in 2016, it was expected that the EU Article 29 Working Party would be releasing Guidance on how to implement GDPR into organisations. To date it has only released 3 pieces of guidance with the reminder expected in 2018 Guidance on the right to data portability Guidance on Data Protection Officers Guidance on Data Privacy Impact Assessments The UK ICO has been expected to release general guidance on implementation and adherence to the GDPR Regulation, releasing this statement in September 2017 Copyright 2017 Health and Social Care Information Centre. 13

14 We will be working to turn the Overview of the GDPR into a Guide to GDPR, which will be similar to our existing guides to other legislation. We will be filling in gaps in its coverage and expanding the content to make it a comprehensive guide.and all the new content should available by early next year.. Due to the lack of thorough and sector specific guidance within Health and Social Care, an EU Working Party, made up of representatives of key departments, ALBs, Providers and customers was set up in January 2017 in order to discuss and produce guidance that can be used in the Health and Social Care Setting. Their ambitious plan is to have released the following guidance by December CEO Briefing Data protection accountability and governance Privacy by design and default Implications of the GDPR for Health and Social Care Research Health and Social Care Research: legal basis and safeguards Transparency, consent and subject s rights Consent Pseudonymisation Personal data breaches and notification Profiling and risk stratification GDPR overview What's new and what changes NHS Digital will have regard to all guidance published and may change or alter NHS Digital s approach to compliance once the guidance content is understood, accepted and the changes have passed through the GDPR Governance channels. Problem Solving Process It is recognised that all parts of NHS Digital, PHC2020 and individual portfolio areas will require guidance and support throughout the Transition phase of the GDPR Programme. Workstreams will also require support in delivering their objectives and may require specific guidance to an issue. Copyright 2017 Health and Social Care Information Centre. 14

15 In order to address this, a Problem Statement Proforma will be produced which will cover as a minimum: - What the problem or point for consideration is The relevant legislation to support a response Areas within NHS Digital which may need to consider this statement The Position Statement that NHS Digital employees need to regard in their working practices. The Problem Statement proforma will progress through the following governance process, the end being a publication on the Intranet and the NHS Digital Website: - Workstream or Programme Identify an issue and/or clarification required with regards to GDPR Complete a "Problem Statement Proforma" with and area requiring clarification Strategic IG Team Examine all relevant legislation. Legislation added to pro forma with any other information known to assist in clarification Expert Group meet to examine statement and legislation and match to working practices within NHS Digital as well as current available GDPR Guidance Complete Pro-forma with solution to problem Statement GDPR Steering Group Ratify Problem Statement Advise further Action if policy or process change required Inform EMT and/or Board of any key issues identified Publication on Intranet and NHS Digital Website. Policy or Guideline produced by Strategic IG Team if appropriate Copyright 2017 Health and Social Care Information Centre. 15

16 Governance There is a defined process identified for governance of the GDPR Compliance Programme. This runs from workstream to Board; thus, ensuring all levels of the organisation are involved in ensuring GDPR Compliance across NHS Digital. Operational Group 16 Workstreams Examine GDPR and DP Bill and other relevant Regulations Produce Highlight Reports and Statements Expert Group Examine Statements and Products from Operational Group against NHS Digital Practice Ratify Statements or Product as compliant Produce final Supporting Document Steering Group Set GDPR and DP Bill Strategy Horizon Scan for internal and external influences Ratify Supporting Documentati on Produce EMT Paper and Slide deck EMT Receive monthly update from Steering Group Exec Sponsor to deliver update and discuss key findings NHS Digital Board Bi-monthly update on GDPR delivered by Exec Sponsor Timescales Activity Sept Oct Nov Dec Jan Feb March April May June-Dec DPO Assigned Workstreams Finalised Programme plan completed 1st Draft Info Asset Register Identification of Critical Assets 2nd Draft Info Asset Register Education Programme Critical Assets GDPR Compliant Policies and Processes uplifted All Information Assets GDPR Compliant GDPR Assurance Programme Commences Copyright 2017 Health and Social Care Information Centre. 16

Information Governance Management Framework

Information Governance Management Framework Information Governance Management Framework November 2014 Author: Responsibility: Lynda Harris, Head of Information Governance All Staff Effective Date: November 2014 Review Date: November 2015 Reviewing/Endorsing

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Version: 4.0 Ratified by: NHS Bury Clinical Commissioning Group Information Governance Operational Group Date ratified: 19 th September 2017 Name of originator /author (s):

More information

IGPr002 - Information Governance Management Framework

IGPr002 - Information Governance Management Framework IGPr002 - Information Governance Management Framework Page 1 of 10 Table of Contents Information Governance Management Framework... 1 Why we need this Framework... 3 What the Framework is trying to do...

More information

IG01 Information Governance Management Framework

IG01 Information Governance Management Framework IG01 Information Governance Management Framework 1 INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG01 Document Purpose: The document compliments all other Information

More information

Information Governance Strategic Management Framework

Information Governance Strategic Management Framework Information Governance Strategic Management Framework 2016-2018 Susan Meakin Information Governance Manager June 2016 Information Governance DOCUMENT CONTROL: Version: 2 Ratified by: Health Informatics

More information

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER

THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER THE GENERAL DATA PROTECTION REGULATION: GUIDANCE ON THE ROLE OF THE DATA PROTECTION OFFICER Contents 1 Introduction 2 2 Key messages 3 3 The requirement to appoint a Data Protection Officer 4 3.1 Public

More information

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN

INFORMATION GOVERNANCE STRATEGY IMPLEMENTATION PLAN INFORMATION GOVERNANCE STRATEGY & IMPLEMENTATION PLAN 2015-2018 Disclaimer The latest version of this document is located on PTHB intranet. Please check the review date and if there are any doubts contact

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK NHS South West Lincolnshire Clinical Commissioning Group (CCG) INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History: Document Reference: Document Purpose: IG01 Date Ratified: January 2015 Ratified

More information

Data Quality Policy

Data Quality Policy Cambridgeshire and Peterborough Clinical Commissioning Group (CCG) Data Quality Policy 2017-2019 Ratification Process Lead Author(s): Reviewed / Developed by: Approved by: Ratified by: Associate Director

More information

Information Governance Assurance Framework

Information Governance Assurance Framework Document Reference POL008 Document Status Approved Version: V4.0 DOCUMENT CHANGE HISTORY Initiated by Date Author IG Toolkit Requirements November 2010 IG Manager Version Date Comments (i.e. viewed, or

More information

The General Data Protection Regulation: What does it mean for you?

The General Data Protection Regulation: What does it mean for you? The General Data Protection Regulation: What does it mean for you? We are here to help The changes being introduced in the EU General Data Protection Regulation 2016 (GDPR) will be the biggest shake-up

More information

Information Governance Strategy and Management Framework

Information Governance Strategy and Management Framework Information Governance Strategy and Management Framework Summary: This strategy sets out the framework, structure, system and accountabilities for Information Governance Management within NHS Eastbourne,

More information

Preparing for the General Data Protection Regulation (GDPR)

Preparing for the General Data Protection Regulation (GDPR) Preparing for the General Data Protection Regulation (GDPR) 10 Steps For Schools... Introduction The new EU General Data Protection Regulation (GDPR) comes into force in the UK on 25th May 2018. This regulation

More information

Information Governance Policy and Management Framework

Information Governance Policy and Management Framework Putting Barnsley People First Information Governance Policy and Management Framework Version: 2.0 Approved By: Governing Body Date Approved: February 2014 Name of originator / author: Richard Walker Name

More information

Information Governance Management Framework Version 6 December 2017

Information Governance Management Framework Version 6 December 2017 Information Governance Management Framework Version 6 December 2017 Page 1 of 8 Introduction Robust information governance requires clear and effective management and accountability structures, governance

More information

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014

East Riding of Yorkshire Council Data protection audit report. Executive summary March 2014 East Riding of Yorkshire Council Data protection audit report Executive summary March 2014 1. Background The Information Commissioner is responsible for enforcing and promoting compliance with the Data

More information

Guidance on the General Data Protection Regulation: (1) Getting started

Guidance on the General Data Protection Regulation: (1) Getting started Guidance on the General Data Protection Regulation: (1) Getting started Guidance Note IR03/16 20 th February 2017 Gibraltar Regulatory Authority Information Rights Division 2 nd Floor, Eurotowers 4, 1

More information

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013

Minor adjustments from IG Steering Group 0.3 Neil Taylor September 2013 Author(s) Andrew Thomas Version 0.3 Version Date 21 August 2013 Implementation/approval Date Review Date August 2014 Review Body Governing Body Policy Reference Number 014 Version Author Date Reason for

More information

Data protection (GDPR) policy

Data protection (GDPR) policy Data protection (GDPR) policy January 2018 Version: 1.0 NHS fraud. Spot it. Report it. Together we stop it. Version control Version Name Date Comment 1.0 Trevor Duplessis 22/01/18 Review due Dec 2018 OFFICIAL

More information

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR)

Customer Data Protection. Temenos module for the General Data Protection Regulation (GDPR) Customer Data Protection Temenos module for the General Data Protection Regulation (GDPR) Contents Glossary 03 GDPR Geographical Scope 03 GDPR implementation status 03 Overview of GDPR 03 Financial Institutions

More information

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation

EU General Data Protection Regulation (GDPR) Tieto s approach and implementation EU General Data Protection Regulation (GDPR) Tieto s approach and implementation GDPR roles and positions Data subjects Information on processing Consent or other basis for processing Right requests High

More information

Lords Bill Committee on Digital Economy Bill Information Commissioner s briefing

Lords Bill Committee on Digital Economy Bill Information Commissioner s briefing Lords Bill Committee on Digital Economy Bill Information Commissioner s briefing Introduction 1. The Information Commissioner has responsibility in the UK for promoting and enforcing the Data Protection

More information

EU-GDPR and the cloud. Heike Fiedler-Phelps January 13, 2018

EU-GDPR and the cloud. Heike Fiedler-Phelps January 13, 2018 . EU-GDPR and the cloud Heike Fiedler-Phelps January 13, 2018 Disclaimer SAP does not provide legal advice The following presentation is only about a high level discussion about GDPR. 2 EU-GDPR Summary

More information

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE

PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE PRIVACY IMPACT ASSESSMENT (PIA) TEMPLATE Reference No: IG40 Version: 1.2 Purpose of Document: Ratified by: Date ratified: 27 th September 2013 Review Date September 2014 Name of originator/author: Contact

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK Document History Document Reference: IG33 Document Purpose: The document complements all other Information Governance policies and sets out the management arrangements

More information

EU General Data Protection Regulation (GDPR)

EU General Data Protection Regulation (GDPR) A Brief Overview of the EU General Data Protection Regulation (GDPR) November 2017 What is the GDPR? After several years in the making, on 8 April 2016 the European Council finally adopted Regulation

More information

Data Protection Policy

Data Protection Policy Data Protection Policy StCH Data Protection Policy - POL 53 vs1 - July 2016 1 Document Control Table Document Title: Data Protection Policy Document Ref: POL 53 Author (name and job title): Karen Anderson,

More information

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry

GDPR. Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry GDPR Legalities, Policies and Process Part 3 of our series on GDPR and its impact on the recruitment industry Who are we? Dillistone Group Plc, a public company listed on the AIM market of the London stock

More information

NHS Digital Post Audit Review of Data Sharing Activities: University College London

NHS Digital Post Audit Review of Data Sharing Activities: University College London Directorate / Programme Care Services Project Data Sharing Audits Status Approved Director Catherine O Keeffe Version 1.0 Owner Sean Walsh Version issue date 13/10/2017 NHS Digital Post Audit Review of

More information

Information Governance Strategic Management Framework

Information Governance Strategic Management Framework Document Summary Information Governance Strategic Management Framework 2017-2019 This framework sets out the Cumbria Partnership NHS Foundation Trust (the organisation) Strategic Management Framework and

More information

ARTICLE 29 DATA PROTECTION WORKING PARTY

ARTICLE 29 DATA PROTECTION WORKING PARTY ARTICLE 29 DATA PROTECTION WORKING PARTY 17/EN WP 256 Working Document setting up a table with the elements and principles to be found in Binding Corporate Rules (updated) Adopted on 29 November 2017 INTRODUCTION

More information

GDPR. The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council 27 April

GDPR. The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council 27 April www.thalesgroup.com/uk SECURE COMMUNICATIONS AND INFORMATION SYSTEMS The General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council 27 April 2016 Contents What is the

More information

Bowmer. & Kirkland. Kirkland. & Accommodation. Health & Safety Policy.

Bowmer. & Kirkland. Kirkland. & Accommodation. Health & Safety Policy. Bowmer Kirkland & Kirkland & Accommodation Health & Safety Policy December 2013 www.bandk.co.uk Index Policy Statement Page 3 Interaction of Health and Safety Responsibilities Page 5 Organisation Page

More information

Guidance on conducting consultations in the HRA Internal HRA guidance only

Guidance on conducting consultations in the HRA Internal HRA guidance only Guidance on conducting consultations in the HRA Internal HRA guidance only Author: Amanda Hunn Date of Release: 19 th February 2015 Version No. & Status: v.1.0 Final Approved by: EMT Supersedes Version:

More information

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY

INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY INFORMATION GOVERNANCE MANAGEMENT FRAMEWORK POLICY Version: 1.4 Approved by: Date approved: 19 January 2017 Name of Originator/Author: Name of Responsible Committee/Individual: Date issued: Information

More information

General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance.

General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance. General Data Protection Regulation and Episerver Learn how to leverage your organization s data to support GDPR compliance. Page 2 What is General Data Protection Regulation? What The general data protection

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy 2017-2019 Created by: Role Name Title Author / Editor Kevin McMahon Head of Risk Management & Resilience Lead Executive Margo McGurk Director of Finance & Performance Approved

More information

GDPR Compliance Checklist

GDPR Compliance Checklist GDPR Compliance Checklist GDPR Compliance Checklist This GDPR Compliance Checklist sets out the key requirements that the General Data Protection Regulation will introduce into EU Privacy law on 25 May

More information

WSGR Getting Ready for the GDPR Series

WSGR Getting Ready for the GDPR Series WSGR Getting Ready for the GDPR Series Overview, main concepts, principles and obligations Cédric Burton Of Counsel Laura De Boel Senior Associate Christopher Kuner Senior Privacy Counsel WSGR Webinar,

More information

Information Governance Management Framework

Information Governance Management Framework Management Framework Summary: This document sets out the framework, structure, system and accountabilities for Management within West Kent CCG Clinical Commissioning Group. APPROVED BY: Chief Finance Officer

More information

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead

DATA QUALITY POLICY. Version: 1.2. Management and Caldicott Committee. Date approved: 02 February Governance Lead DATA QUALITY POLICY Version: 1.2 Approved by: Date approved: 02 February 2016 Name of Originator/Author: Name of Responsible Committee/Individual: Information Governance, Records Management and Caldicott

More information

Draft terms of reference for the Staff Forum and communicate relaunch.

Draft terms of reference for the Staff Forum and communicate relaunch. Equality, Diversity and Inclusion Action Plan 2017 Action Refresh Staff Forum with a focus on EDI. The Chief Executive and EMT will lead on the promotion of EDI. Success measure Workshop to focus on discussing

More information

2017 IBM Corporation. IBM s Journey to GDPR Readiness

2017 IBM Corporation. IBM s Journey to GDPR Readiness IBM s Journey to GDPR Readiness IBM s Journey to GDPR Readiness At IBM, we have a deep rooted understanding that privacy is foundational to trust. We are approaching the GDPR in the same spirit, both internally

More information

RING FENCING GUIDELINE

RING FENCING GUIDELINE RING FENCING GUIDELINE PLAN AER Submission - July 2017 Purpose of this document > This document outlines Essential Energy s strategy to achieve compliance with the AER s Ring Fencing Guideline > This strategic

More information

Conducting privacy impact assessments code of practice

Conducting privacy impact assessments code of practice Conducting privacy impact assessments code of practice Data Protection Act Contents Data Protection Act... 1 Information Commissioner s foreword... 2 About this code... 3 Chapter 1 Introduction to PIAs...

More information

GOVERNANCE STRATEGY October 2013

GOVERNANCE STRATEGY October 2013 GOVERNANCE STRATEGY October 2013 1. Introduction 1.1. The Central Manchester University Hospitals NHS Foundation Trust believes that the role of the governing body is pivotal to the success of the Trust.

More information

Chair Job Description and Person Specification

Chair Job Description and Person Specification Chair Job Description and Person Specification Remuneration: 3,000 pa (excluding expenses) The Role of the Board The primary purpose of the Board is to maintain a strategic role in governing Healthwatch

More information

The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner,

The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner, The General Data Protection Regulation (GDPR): Getting in good shape for the deadline Copenhagen, 19 September 2017 Janus Friis Bindslev Partner, Deloitte, Cyber Advisory Table of Contents Introduction

More information

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges

GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges GDPR and Canadian organizations: Addressing key challenges Cyber Risk 1 GDPR and Canadian organizations: Addressing key challenges The regulation

More information

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting

with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting with Xavier Darmstaedter Managing Partner GEDAPRE DACOTA Consulting xada@gedapre.eu tel 0475-41.03.22 xavier.darmstaedter@dacota.eu Gent, 3 October 2017 4 facts 1. We are not really in control of our personal

More information

Fixed Term Staffing Policy

Fixed Term Staffing Policy Fixed Term Staffing Policy Who Should Read This Policy Target Audience All Trust Staff Version 1.0 October 2015 Ref. Contents Page 1.0 Introduction 4 2.0 Purpose 4 3.0 Objectives 4 4.0 Process 4 4.1 Recruitment

More information

Recruitment Pack General Data Protection Regulation Project Manager Battersea Dogs & Cats Home

Recruitment Pack General Data Protection Regulation Project Manager Battersea Dogs & Cats Home Recruitment Pack General Data Protection Regulation Project Manager Battersea Dogs & Cats Home Dear Applicant, Thank you for requesting further information for our General Data Protection Regulation Project

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

GDPR Webinar : Overview & practical compliance steps. 23 October 2017

GDPR Webinar : Overview & practical compliance steps. 23 October 2017 GDPR Webinar : Overview & practical compliance steps 23 October 2017 1 Dr Michelle Goddard Director Policy & Communication, EFAMRO Mattias Strandberg Skribent, dagensanalys.se copyright efamro 2010 2 About

More information

Corporate Procurement Policy

Corporate Procurement Policy Corporate Procurement Policy Director Responsible Author Gordon Laidlaw (Finance & IT) Roy Aitken (Procurement Manager) Date October 2015 Version Number 2 Approved by Board Dec 2015 Review Date Nov 2018

More information

INFORMATION GOVERNANCE STRATEGY. Documentation control

INFORMATION GOVERNANCE STRATEGY. Documentation control INFORMATION GOVERNANCE STRATEGY Documentation control Reference Date Approved Approving Body Version Supersedes Consultation Undertaken Target Audience Supporting procedures GG/INF/01 TRUST BOARD Information

More information

TWELVE STEP PLAN TO BECOME COMPLIANT WITH THE GENERAL DATA PROTECTION REGULATION

TWELVE STEP PLAN TO BECOME COMPLIANT WITH THE GENERAL DATA PROTECTION REGULATION TWELVE STEP PLAN TO BECOME COMPLIANT WITH THE GENERAL DATA PROTECTION REGULATION Awareness Data Stream Map Communication Rights of the subject Legal basis Consent Data Breaches Privacy by design and PIA

More information

INDUCTION POLICY AND PROCEDURE

INDUCTION POLICY AND PROCEDURE Summary INDUCTION POLICY AND PROCEDURE New members of staff require an induction period to enable them to settle in to their new place of work. This policy sets out the framework and responsibilities for

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Unique Reference / Version Primary Intranet Location Information Management & Governance Secondary Intranet Location Policy Name Information Governance Policy Version Number

More information

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY

NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY NHS SOUTH DEVON AND TORBAY CLINICAL COMMISSIONING GROUP INFORMATION LIFECYCLE MANAGEMENT POLICY Version Control Version: 2.0 dated 17 July 2015 DATE VERSION CONTROL 04/06/2013 1.0 First draft of new policy

More information

TECHNICAL GOVERNANCE AND ADVISORY STRUCTURES FOR THE STANDARDS DEVELOPMENT PROCESS

TECHNICAL GOVERNANCE AND ADVISORY STRUCTURES FOR THE STANDARDS DEVELOPMENT PROCESS STANDARDISATION GUIDE 005: TECHNICAL GOVERNANCE AND ADVISORY STRUCTURES FOR THE STANDARDS DEVELOPMENT PROCESS COPYRIGHT Standards Australia Limited ABN: 85 087 326690 All rights are reserved. No part of

More information

Asset Risk Management Journey Plan

Asset Risk Management Journey Plan Asset Risk Management Journey Plan STRATEGIC PLAN 2010-2013 Transpower New Zealand Limited April 2011 TABLE OF CONTENTS EXECUTIVE SUMMARY... 3 1. PURPOSE... 4 2. OVERVIEW OF TRANSPOWER S RISK MANAGEMENT

More information

COMMUNICATIONS STRATEGY

COMMUNICATIONS STRATEGY COMMUNICATIONS STRATEGY 2016-2019 Introduction and purpose This strategy details how communications will support the delivery of shaping the future of urgent & emergency care (EEAST strategy 2016-21).

More information

Within Band 6: 39,270-66,865 (pro rata) CEO and Chair of Board of Trustees as Company Secretary

Within Band 6: 39,270-66,865 (pro rata) CEO and Chair of Board of Trustees as Company Secretary Job outline JOB TITLE: JOB REF: HOURS: SALARY: CONTRACT: REPORTS TO: Company Secretary/Policy Officer HFLMAT CO002 Part time 0.8 FTE (52 weeks per year) Within Band 6: 39,270-66,865 (pro rata) Permanent

More information

Information Governance Management Framework 2017/18 Reference: IG12

Information Governance Management Framework 2017/18 Reference: IG12 Information Governance Management Framework 2017/18 Reference: IG12 Compliance with all CCG policies, procedures, protocols, guidelines, guidance and standards is a condition of employment. Breach of policy

More information

Procurement Strategy period September 2012 September 2014

Procurement Strategy period September 2012 September 2014 National Library of Scotland Procurement Strategy period September 2012 September 2014 Aims This document aims to identify NLS strategy for the development and continued improvement of procurement systems,

More information

Role Title: Chief Officer Responsible to: CCG chairs - one employing CCG Job purpose/ Main Responsibilities

Role Title: Chief Officer Responsible to: CCG chairs - one employing CCG Job purpose/ Main Responsibilities Role Title: Chief Officer Responsible to: CCG chairs - one employing CCG Job purpose/ Main Responsibilities Accountable to: All employed staff working within the 3 CCGs Within the 3 CCGs the Chief Officer

More information

Preparing for GDPR 27th September, Reykjavik

Preparing for GDPR 27th September, Reykjavik Preparing for GDPR 27th September, Reykjavik Introduction Who I am? Solicitor fromlondon Worked in digital industry for the last 7years Specialized in Privacy for the last 7 years and did some consulting

More information

Information Governance Training Plan

Information Governance Training Plan Information Governance Training Plan Page 1 of 10 Paper O2 - CCG_IG_Training_Plan_2017-18_V3.0 Final Paper O2 - CCG_IG_Training_Plan_2017-18_V3.0 Final Information Governance Training Plan Derbyshire Clinical

More information

POLICY ON MANAGING POLICIES, PROCEDURES AND GUIDANCE DOCUMENTS

POLICY ON MANAGING POLICIES, PROCEDURES AND GUIDANCE DOCUMENTS POLICY ON MANAGING POLICIES, PROCEDURES AND GUIDANCE DOCUMENTS Version: 6 Date Ratified: February 2017 Review Date: February 2020 Applies to: Senior Managers and staff who produce procedural documents.

More information

Risk Management Strategy

Risk Management Strategy High Value Health Care Risk Management Strategy (Reference No. GR21 0914) Version: Version 4, September 2014 Version Superseded: Version 3, March 2012 Ratified by: Date ratified: 11 th November 2014 Designation

More information

Delegated primary care commissioning. January 2017 governing bodies (version: 0.9)

Delegated primary care commissioning. January 2017 governing bodies (version: 0.9) Delegated primary care commissioning January 2017 governing bodies (version: 0.9) Authors: Chloë Hardcastle, Acting Local Services Programme Manager, Strategy and Transformation Emma Raha, Collaboration

More information

VOLUNTARY CODE OF CONDUCT IN RELATION TO EXECUTIVE REMUNERATION CONSULTING IN THE UNITED KINGDOM

VOLUNTARY CODE OF CONDUCT IN RELATION TO EXECUTIVE REMUNERATION CONSULTING IN THE UNITED KINGDOM VOLUNTARY CODE OF CONDUCT IN RELATION TO EXECUTIVE REMUNERATION CONSULTING IN THE UNITED KINGDOM (December 2015) Preamble Executive remuneration consultants are business advisers who provide a valuable

More information

Job Description & Person Specification. Age UK Kensington & Chelsea Values

Job Description & Person Specification. Age UK Kensington & Chelsea Values Job Description & Person Specification Job Title Hours Contract Salary HSCA Service Delivery Manager 35 hours per week Permanent 35,353 per annum Age UK Kensington & Chelsea Values We promote the well-being

More information

A questionnaire for senior management

A questionnaire for senior management Getting ready for GDPR Part 2: Accountability - A questionnaire for senior management Accountability is more than simple compliance with the rules - it implies a culture change organisations and not Data

More information

A Quality Assurance Framework for Knowledge Services Supporting NHSScotland

A Quality Assurance Framework for Knowledge Services Supporting NHSScotland Knowledge Services B. Resources A1. Analysis Staff E. Enabling A3.1 Monitoring Leadership A3. Measurable impact on health service Innovation and Planning C. User Support A Quality Assurance Framework for

More information

KING III ON CORPORATE GOVERNANCE. The AEEI level of compliance continually increases since the introduction of the Code.

KING III ON CORPORATE GOVERNANCE. The AEEI level of compliance continually increases since the introduction of the Code. KING III ON CORPORATE GOVERNANCE The Board of African Equity Empowerment Investments Limited (AEEI) remains committed to and endorses the principles of the Code of Corporate Practices and Conduct as set

More information

A Parish Guide to the General Data Protection Regulation (GDPR)

A Parish Guide to the General Data Protection Regulation (GDPR) A Parish Guide to the General Data Protection Regulation (GDPR) What s happening and why is it important? The law is changing. Currently, the Data Protection Act 1998 governs how you process personal data

More information

CORPORATE GOVERNANCE KING III COMPLIANCE REGISTER 2017

CORPORATE GOVERNANCE KING III COMPLIANCE REGISTER 2017 CORPORATE GOVERNANCE KING III COMPLIANCE REGISTER 2017 This document has been prepared in terms of the JSE Listing Requirements and sets out the application of the 75 corporate governance principles by

More information

General Optical Council. Data Protection Policy

General Optical Council. Data Protection Policy General Optical Council Data Protection Policy Authors: Lisa Sparkes Version: 1.2 Status: Live Date: September 2013 Review Date: September 2014 Location: Internet / Intranet Document History Version Date

More information

JOB DESCRIPTION. JOB TITLE: Communications Project Manager (STP) PAY BAND: Band 7. DEPARTMENT/DIVISION: Communications

JOB DESCRIPTION. JOB TITLE: Communications Project Manager (STP) PAY BAND: Band 7. DEPARTMENT/DIVISION: Communications JOB DESCRIPTION JOB TITLE: Communications Project Manager (STP) PAY BAND: Band 7 DEPARTMENT/DIVISION: Communications BASED AT: Queen Elizabeth Hospital Birmingham REPORTS TO: Fiona Alexander PROFESSIONALLY

More information

Information Governance Policy

Information Governance Policy Information Governance Policy Applicable to All employees Version1.0 Last Updated March 2014 CONFIDENTIAL Page 2 of 6 Contents 1. Objectives 3 2. Scope 3 3. Principles 3 4. Information Governance Policy

More information

HSCIC Audit of Data Sharing Activities:

HSCIC Audit of Data Sharing Activities: Directorate / Programme Data Dissemination Services Project Data Sharing Audits Status Approved Director Terry Hill Version 1.0 Owner Rob Shaw Version issue date 20/04/2016 HSCIC Audit of Data Sharing

More information

INFORMATION GOVERNANCE POLICY

INFORMATION GOVERNANCE POLICY INFORMATION GOVERNANCE POLICY Page 1 of 13 INFORMATION GOVERNANCE POLICY EXECUTIVE SUMMARY Key Messages Principles of Information Governance Openness Confidentiality and Legal Compliance Information Security

More information

Humber Information Sharing Charter

Humber Information Sharing Charter External Ref: HIG 01 Review date November 2016 Version No. V07 Internal Ref: NELC 16.60.01 Humber Information Sharing Charter This Charter may be an uncontrolled copy, please check the source of this document

More information

The postholder will work as a key member of the senior team for Organisational Learning and Development.

The postholder will work as a key member of the senior team for Organisational Learning and Development. JOB TITLE: BAND: BASE: RESPONSIBLE TO: ACCOUNTABLE TO: OD Consultant AFC 8b XX Director of L&D and OD Director of L&D and OD JOB SUMMARY To provide specialist OD consultancy expertise and support to the

More information

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER

SOLUTION BRIEF EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER EU GENERAL DATA PROTECTION REGULATION COMPLIANCE WITH RSA ARCHER ARRIVAL OF GDPR IN 2018 The European Union (EU) General Data Protection Regulation (GDPR) that takes effect in 2018 will bring changes for

More information

Date of review: Policy Category:

Date of review: Policy Category: Title: Disciplinary Policy Date Approved by: Approved: February JSPF 2015 March 2015 OD and Workforce Committee October 2016 JSPF Division/Department: Date of review: November 2018 Policy Category: Policy

More information

JOB DESCRIPTION. Service Line Manager for [one of Education/Research/Business/Infrastructure] Job Family/Level: Professional Services, level 6

JOB DESCRIPTION. Service Line Manager for [one of Education/Research/Business/Infrastructure] Job Family/Level: Professional Services, level 6 JOB DESCRIPTION Job Title: Department/Division/Faculty: Campus location: Service Line Manager for [one of Education/Research/Business/Infrastructure] ICT (Information and Communication Technologies), South

More information

Final Report. Guidelines. on internal governance under Directive 2013/36/EU EBA/GL/2017/ September 2017

Final Report. Guidelines. on internal governance under Directive 2013/36/EU EBA/GL/2017/ September 2017 EBA/GL/2017/11 26 September 2017 Final Report Guidelines on internal governance under Directive 2013/36/EU Contents Executive Summary 3 Background and rationale 5 1. Compliance and reporting obligations

More information

The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry

The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry The EU General Data Protection Regulation (GDPR) A briefing for the digital advertising industry 1 Contents Introduction 5 Brexit: GDPR or New UK Law? 8 The eprivacy Directive 10 The GDPR: 10 Key Areas

More information

Executive Board Terms of Reference. 1. Purpose 1.1

Executive Board Terms of Reference. 1. Purpose 1.1 Executive Board Terms of Reference 1. Purpose 1.1 1.2 Executive Board assists the Chief Executive and Accounting Officer in the performance of his duties. It is responsible for developing and implementing

More information

Privacy governance survey. The state of privacy management in Belgian organisations

Privacy governance survey. The state of privacy management in Belgian organisations Privacy governance survey The state of privacy management in Belgian organisations January 2017 Welcome How are Belgian organisations performing when it comes to the protection of personal data? In November

More information

St Mark s Church of England Academy Data Protection Policy

St Mark s Church of England Academy Data Protection Policy St Mark s Church of England Academy Data Protection Policy 1 Contents Purpose:... Error! Bookmark not defined. Scope:... Error! Bookmark not defined. Procedure:... Error! Bookmark not defined. Definitions:...

More information

Data Flow Mapping and the EU GDPR

Data Flow Mapping and the EU GDPR Data Flow Mapping and the EU GDPR Adrian Ross LLB (Hons), MBA GRC Consultant IT Governance Ltd 29 September 2016 www.itgovernance.co.uk Introduction Adrian Ross GRC Consultant Infrastructure services Business

More information

JOB DESCRIPTION. Temporary Project Administration Officer Corporate Services Redesign 3 to 6 months. Hot Desking from Tatchbury Mount, Calmore

JOB DESCRIPTION. Temporary Project Administration Officer Corporate Services Redesign 3 to 6 months. Hot Desking from Tatchbury Mount, Calmore JOB DESCRIPTION Job Title: Temporary Project Administration Officer Corporate Services Redesign 3 to 6 months Grade: 1.0 WTE Band 3 Work Base: Accountable to: Responsible to: Hot Desking from Tatchbury

More information

EDUCATION SUPPORT OFFICER. GRADE FIVE Position Information Document

EDUCATION SUPPORT OFFICER. GRADE FIVE Position Information Document J:\office\Advertising new positions\bursar\finanaceofficer2015.docx EDUCATION SUPPORT OFFICER GRADE FIVE Position Information Document Name Position Title School Finance Officer Stream Resources Admin

More information

R&D Manager Hillingdon Hospital. Revision History Effective Date Reason For Change. recommendations Version no:

R&D Manager Hillingdon Hospital. Revision History Effective Date Reason For Change. recommendations Version no: Research as a Participating site STANDARD OPERATING PROCEDURE FOR OVERSIGHT SOP No: P08/PF2 V2 Effective Date: 31 st July 2013 Supersedes: P08/PF2 Revision Date: 31 st March 2014 Author: Position: Approved

More information

Isle of Wight Council Job Description

Isle of Wight Council Job Description Isle of Wight Council Job Description Identifying Facts Title of Post: Youth Offending Team Officer Directorate: Children s Services Post No: 50043897 Section: Youth Offending Team Date: May 2014 Responsible

More information