Data Protection and Information Governance Officer - Manchester City Council - Manchester, United Kingdom
(2026-03 - 2026-08)
Deliver data protection and information governance activity within a complex local authority, supporting the wider Risk and Assurance function and helping services embed privacy by design and default into day-to-day processing and service changes.
- Manage complex Subject Access Requests from receipt to disclosure, applying UK GDPR and Data Protection Act 2018 requirements, exemptions, third-party balancing tests and proportionate redaction.
- Apply privacy by design and default when reviewing proposed processing activities, helping service areas consider lawful basis, necessity, proportionality, data minimisation, transparency, access controls, retention and risks to individuals from the outset.
- Support the review and development of Data Protection Impact Assessments, data-sharing agreements, privacy information and related governance documentation.
- Triage data protection queries and incidents, identify potential risks and consequences, document remedial action and escalate matters for appropriate review.
- Contribute to organisational assurance work, including records of processing, retention-related controls, compliance registers and policy governance.
- Advise operational colleagues on lawful, secure and proportionate handling, sharing, retention and disclosure of personal and special category data.
- Work with stakeholders across service areas to obtain evidence, clarify processing activity, assess risk and agree practical compliance actions.
- Prepare clear case summaries, recommendations and written responses for management review, maintaining complete and auditable decision records.
- Balance legal obligations, individual rights and operational needs while managing competing deadlines in a fast-paced public sector environment.
- Support continuous improvement of information-handling processes, templates, tracking arrangements and team guidance.
Subject Access Clerk - Information Governance - Manchester University NHS Foundation Trust (MFT)
(2025-11 - 2026-02)
Managed information rights casework involving complex health records and special category data within a highly regulated NHS environment.
- Received, logged and acknowledged requests; verified identity, clarified scope and planned case activity against statutory deadlines and service standards.
- Applied privacy by design and default throughout the disclosure process by limiting retrieval to relevant records, minimising unnecessary personal data and ensuring secure handling of sensitive information.
- Applied exemptions and redactions, drafted accurate disclosure responses and maintained clear audit trails on case-management systems.
- Identified information governance and confidentiality risks during record review and escalated concerns promptly for resolution.
- Worked collaboratively with stakeholders to improve consistency, accuracy and secure information handling.
Volunteer Information Governance Administrator (Medico-Legal) - Stepping Hill Hospital
(2025-02 - 2025-11)
Retrieved, organised, quality-checked and prepared clinical and administrative records for SAR and medico-legal disclosure.
- Flagged inconsistencies and potential disclosure risks, supporting accurate, secure and timely case handling.
- Applied privacy by design when preparing records by checking relevance, limiting disclosure to necessary information and maintaining confidentiality, secure handling and appropriate access controls.
Entries and Results Administrator - AQA
(2024-04 - 2024-09)
- Applied privacy-by-design principles when processing examination entries and results by using only necessary information, maintaining accuracy, restricting access and handling personal data securely.
- Maintained accurate, auditable records and responded professionally to internal and external data-related queries.
Data Protection Officer / Information Governance Lead - Dot ICT Institute of Technology, Nigeria
(2016-05 - 2024-04)
Led day-to-day data protection and information governance activity for an education and technology organisation, advising staff and management on responsible use of personal information.
- Embedded privacy by design and default into organisational processes and governance controls, ensuring that data minimisation, appropriate access, security, retention and transparency were considered when staff, student and client information was handled.
- Advised staff and management on privacy, confidentiality, information sharing, records management and appropriate disclosure.
- Managed information access requests and ensured that responses were accurate, appropriately authorised and securely delivered.
- Maintained policies, governance documentation, registers and compliance records to evidence accountability and support management oversight.
- Monitored compliance, identified information risks and supported proportionate corrective and preventive action.
- Promoted privacy awareness and good information-handling practice across the organisation.