Data Protection Strategic Lead
Listed on 2026-06-10
-
IT/Tech
Data Security, Information Security
Overview
SID is part of the Service Transformation Group. The Group oversees the building of a strategic vision for modernising and digitising our legacy systems, generating a coordinated plan across the MoJ and its agencies for transformation, and tracking delivery of this transformation.
Security and information management are fundamental building blocks of enabling the department to deliver. We have highly skilled experts working collaboratively with the department, Government Security Group and other partners to enable the whole of the MoJ to function securely, lawfully and transparently. We identify, manage and mitigate MoJ's security, data protection and information risks, and provide assurance against those risks.
We are also home to the Counter Fraud Centre of Expertise. Part of our mission is to up‑skill the department so that security becomes second nature to our people and partners.
The remit of the Data Protection Team covers Headquarters, the five Executive Agencies and twelve Arm's Length Bodies. Their work includes monitoring and overseeing compliance with data protection legislation and MoJ personal data policies, advising on Data Protection Impact Assessments, acting as the point of contact with the Information Commissioner's Office and receiving requests from data subjects who wish to exercise their rights to access, restrict, rectify or erase their personal data.
We are recruiting a Data Protection Strategic Lead to be part of our warm and collaborative Data Protection Team. Reporting to a Deputy Data Protection Officer, the role will play a leading part in improving how the department manages personal data, including the promotion of adherence to and provision of guidance across a vast spectrum of business areas on information legislation, and be part of the management of high‑impact incidents involving personal data.
Responsibilities- Provide advice and guidance on data protection issues for the MoJ and to make decisions on whether to report data breaches to the ICO.
- Contribute to regular commissions from Government departments to identify the most critical activities and likely risks.
- Act as point of contact for several of the MoJ's Executive Agencies and Arm's Length Bodies and the central work streams covering commercial and contract management, HR, finance and digital/technology functions. Generate a common interpretation of emerging cross‑government guidance, and provide specific interpretations to cultivate a strong MoJ approach towards achieving compliance.
- Explore and promote critical deliverables on a department‑wide basis.
- Maintain relationships with appropriate teams and stakeholders in support of delivering UK GDPR/DPA
18/DUAA
25 compliance across MoJ technology systems. - Providing compliance advice and guidance on:
- The transparency requirements of the UK GDPR and the DPA
18. - Data Protection‑by‑design and default throughout the data journey and across multiple platforms.
- The ability of the Department to evidence proactive supplier management and compliance, with expected standards (as a data controller).
- A long‑term compliance plan for information held within systems across the MoJ estate, including new and legacy systems.
- An incident management process for data incidents and assessing whether data breaches should be reported to the ICO.
- The transparency requirements of the UK GDPR and the DPA
- Providing in the above in liaison with appropriate technical information assurance professionals within the business including:
- The Information Assurance Leads.
- Senior Information Risk Owners (SIROs) and their delegated Information Asset Owners (IAOs).
- Senior technical and non‑technical stakeholders across Government, including Government Digital Service and Open Government Data.
- Job holder is expected to accept reasonable alterations and additional tasks of a similar level that may be necessary.
- A current and constantly renewed understanding of both UK GDPR and the DPA
18/DUAA
25 – especially regarding the processing of data for law enforcement purposes and the ability to recognise and advise upon the potential impacts of such on MoJ's existing and emerging technology systems/projects. - A proven track record in developing and leading…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: