Infomation Risk Officer
Current• Drive, implement and maintain a Data Protection Action Plan.• Conduct gap assessments of critical processes to ensure continuous improvement across the organisation• Maintain the data asset catalogue.• Build and maintain a data map.• Assess data protection risks in processing activities (including new supplier and partner relationships).• Be a critical stakeholder of the procurement committee.• Engage with a range of stakeholders to improve data protection and data governance.• Work closely with the information security analysts to identify and mitigate data protection risks.• Ensure new and existing products/services comply with regulations, in particular, the General Data Protection Regulations (GDPR).• Support the management of data assets, including data protection and quality improvement.• Ensure the use of data assets adheres to the Data Governance Framework, relevant policies, standards, and controls.• Serve as a point of escalation for data protection tasks and issues.• Support with the preparation of risk assessments relating to data use, including Data Protection Impact Assessments (DPIAs), and Legitimate Interest Assessments (LIAs).• Report on risks, issues, and performance to the Data Protection Officer and the Director of Information Security.• Monitor data incidents and assist with the investigation and root cause analysis.