Ref
19340
Division/Department
Corporate & Medical | Corporate (0490)
Location
Onsite - Hospital/Hospice
Employment type
Part-time
Salary
Competitive
DBS required
Standard
Hours
22.5 hours a week
Closing date
05/10/2026
Description

We are looking for an experienced Information Governance Manager to join our Corporate team, reporting to the Company Secretary and General Counsel in their capacity as our statutory Data Protection Officer.

This is a part-time role (0.6 FTE) for a specialist who thrives on embedding good information governance across a busy healthcare environment – keeping the organisation compliant, investigating incidents thoroughly, and helping colleagues at every level handle personal and sensitive data with confidence.

St John & St Elizabeth Hospital is a leading private hospital in London, offering a comprehensive range of specialist medical treatments, clinics and diagnostic services from a team of world-class consultants, supported by a dedicated team of clinical and non-clinical staff.

We are known for our exceptional standards of care, excellent nursing standards, and cutting-edge medical treatments.

We have 170 years of history and are looking for people to join us for the next chapter. We are very unique as the only truly charitable private hospital in London and as a charity, every private patient treated helps support our on-site community hospice.

Am I the right person for the Information Governance Manager?

  • You will have substantial experience in information governance or data protection, ideally gained in a hospital or comparable regulated setting, and be confident applying the rules to real, practical situations.
  • You will hold – or be actively working towards – a recognised data protection or information governance qualification (for example the BCS Practitioner Certificate in Data Protection or IAPP CIPP/E), or be able to demonstrate equivalent professional experience.
  • You will have a working knowledge of the UK GDPR, the Data Protection Act 2018 and the common law duty of confidentiality, along with an awareness of ICO guidance; familiarity with the Caldicott Principles and the NHS Data Security and Protection Toolkit would be a real advantage.
  • You will have a track record of investigating information governance incidents and personal data breaches, handling data subject requests to statutory deadlines, and developing and delivering training that raises awareness across an organisation.
  • Above all, you will bring sound analytical judgement, discretion and the highest standards of integrity, the ability to influence and challenge colleagues at all levels, and the resilience to work autonomously and prioritise competing statutory deadlines.

What are the responsibilities of the Information Governance Manager?

  • As the operational lead for information governance, you will support the Data Protection Officer to ensure HJE remains compliant with the UK GDPR, the Data Protection Act 2018, ICO guidance and sector best practice, including the NHS Data Security and Protection Toolkit.
  • You will investigate information governance incidents and complaints, working closely with the DPO, SIRO and Caldicott Guardian to assess risk and potential breaches, meet the 72-hour reporting window where required, and turn lessons learned into lasting good practice.
  • Day to day, you will develop and deliver information governance training and guidance, maintain policies, privacy notices and the IG risk register, and carry out audits and compliance spot checks across the Hospital and Hospice.
  • You will work with Information Asset Owners to map assets and data flows and maintain the centralised Register of Processing Activities, support colleagues with Data Protection Impact Assessments, and – under the supervision of the General Counsel – review Data Sharing Agreements and carry out supplier due diligence.
  • You will ensure data subject requests are answered within statutory timeframes (supporting the Medical Records team on medical records requests), attend and report to the Information Governance Committee on key compliance KPIs, complete and submit the annual NHS Data Security and Protection Toolkit, and support the SIRO, DPO and Caldicott Guardian in discharging their duties.

Why apply for this role?

We offer a genuinely supportive environment where compliance and genuine purpose sit alongside each other. Benefits include:

  • Private healthcare scheme worth up to £20,000 per year
  • 27 days annual leave (pro rata)
  • Interest-free season ticket loans
  • Cycle to work scheme
  • Free eye tests with contribution towards lenses
  • Local business and retail discounts
  • Free Cinema Society membership
  • Staff Gym
  • Refer a Friend scheme
  • Personal development and training
  • Annual recognition awards and events

If you are ready for a new challenge and relish the chance to become part of a successful, forward thinking organisation then we would love to hear from you.

This post is subject to a satisfactory Disclosure and Barring Service (DBS) check and the right to work in the UK.