Role Description
Rank\Scale PO2
Head of Governance and Compliance
Reports To
Main Responsibilities Hold the post of Force Data Protection Officer and Force Freedom of Information Officer, with the responsibilities as set out in the Association of Chief Police Officers Data Protection and Freedom of Information Authorised Professional Practice (APP).
1.
The post holder will be responsible for the final sign off of disclosures made on behalf of the Chief Constable.2. The post holder will be the point of contact for the Information Commissioners Office. You will be responsible for managing any S55 Data Breaches and where necessary notification to the ICO. This will involve maintaining a log of all breaches, a rationale for reporting, the review of practices and liaison with specific internal departments namely Professional Standards and the Chief Officer Group to advise on how to mitigate any current or future risk. You will also need to interpret any decisions made by the ICO.
3.
Providing appropriate strategic advice, assistance, guidance and compliance by interpreting relevant legislation to ensure information disclosure or compliance aspects are duly regarded at all levels and within Constabulary policies, procedures, guidance and projects.
4.
Provide advice to project managers through the implementation of Privacy Impact Assessments and keeping a log of all advice given with regards to this process
5.
You will be expected to manage the Information Disclosure Team within the force. To manage staff performance using the ?Individual Performance Review (IPR) system, ensuring that annual and interim meetings take place and objectives are agreed and actioned
6.
Develop and provide an effective and efficient appeal mechanism as required under the provisions of the Freedom of Information Act 2000.
7.
You will be responsible for the implementation and continued use of a Data Protection and Freedom of Information training package suitable for all levels of personnel within the Constabulary. ensuring all personnel are kept up to date with changes to legislation. This will include the maintenance of a training log, and escalation to line mangers to ensure compliance with annual and/or mandatory training.
8.
You will need to have a thorough working knowledge of the formal disclosure of information to statutory bodies and individuals in the following disciplines:
Freedom of Information (FOI)◦ Environmental Information Regulation (EIR)◦ Data Protection Subject Access Requests (DP SAR)◦ Data Protection Section 35 (2) – Civil legal proceedings.◦ Disclosures to governing bodies / employers (CLPD and ‘pull’ requests)◦ Insurance Memoranda of Understanding.◦ Children and Family Court Advisory and Support Service (CAFCASS)◦ Criminal Injuries Compensation Authority (CICA)◦ Information Sharing Agreements.◦
9.
Ensure that all disclosures made meet the legal obligations whilst applying best practice to protect information throughout the organisation. Implement regular reviews ensuring that these requests are dealt with in line with the service level agreements and carried out in accordance with legislation/national guidance.
10.
You need to be able to research nominals, analyse and evaluate all information, particularly crimes, intelligence, storm together with other relevant information from local force systems. Where appropriate, interrogate national databases to gather evidence for the collation and preparation of relevant documentation.
11.
To maintain a good working knowledge of all relevant DP and FoI legislative guidance, policies and procedures and advising on implications of related developments external to the Force at local, regional and national level e.g. legislative changes and decisions from the Information Commissioner.
12.
To create Data Processing Agreements with outside contractors and liaise with the Force Vetting Officer to ensure that contractors associated to the agreement are vetted to the appropriate level.
13.
To develop and maintain relationships and partnerships with other Forces and outside agencies whilst ensuring representation of the Constabulary at regional and national level as appropriate.
14.
To be the focal point in the Force providing advice on Data Protection, Freedom of Information, and Information Sharing matters ensuring implementation of all necessary policies, procedures and other measures in compliance with the Authorised Professional Practice (APP) for Data Protection, Freedom of Information and Information Sharing.
Role Profile
Governance and Compliance: Data Protection Officer
Page: 126/11/2025 10:39:54
Additional Information Vetting Level: The role must be vetted to a minimum of Management Vetting (MV & SC). Mobility: The Force reserves the right to request you to carry out any other duties or move you to any other post appropriate to your grade, at any location within the county of Gloucestershire, as business requirements dictate. Working Pattern: Normal working hours will average 37 per week or will be pro rata. This will be worked subject to the needs of the service and may involve shift, night, weekend and public holiday working. Standards of Professional Behaviour: All members of Police Staff / Police Officers must comply with these standards. Travel: The post holder will be required to travel to attend regional and national meetings. Training and development: The postholder will be required to maintain professional knowledge and attend any other courses appropriate to the grade of the role.
Minimum criteria for role:
Hold a professional Data Protection and/or FOI qualification• Proven substantial Data Protection / FOI experience, particularly around decision making• Experience of managing a team• Experience of working in a confidential environment and able to demonstrate a high level of personal integrity• Good verbal and written communication skills (as the role requires the postholder to present at meetings and complete reports both internally and externally)
•
Able to demonstrate accuracy to detail•
Desirable:
Previous experience of working within a policing environment would be desirable.•
Experience and Qualifications
Notes This post is Politically Restricted and defined by legislation as “Sensitive”.
Progression
Skill Category Skill Name Skill Level Skill Description For PDR
Intelligent, Creative and Informed Policing
We analyse critically Practitioner I recognise the need to think critically about issues and challenge my assumptions, ensuring I find information and data that can help me make better decisions.<br /> I absorb and interpret information accurately and in an appropriate timeframe, separating what is relevant and not relevant. <br /> I solve problems proactively by understanding the reasons behind them, using learning from evidence and from my experiences to take action. <br /> I apply professional knowledge and decision- making frameworks, in addition to drawing on my personal experience and judgement, to make better decisions. <br /> I recognise where there may be gaps and inconsistencies in data and information and think about the potential implications of this. <br /> I keep clear and accurate records of information and data to support evidence-based decision making.
Yes
Role Profile
Governance and Compliance: Data Protection Officer
Page: 226/11/2025 10:39:54
Inclusive, Enabling and Visionary Leadership
We are collaborative Practitioner I learn about stakeholders in other teams, organisations, and the community so I can work with them effectively.<br /> I work to get to know others and build rapport so that we can achieve shared goals. <br /> I work flexibly with people across different levels, teams and backgrounds. <br /> I work cooperatively with others to get things done, willingly giving help and support to colleagues.<br /> I actively seek to engage with and learn from a diverse group to improve the work I do.
Yes
Resolute, Compassionat e and Committed
We are emotionally aware
Practitioner I communicate effectively and compassionately, tailoring my communication so I can be easily understood by others.<br /> I seek to understand and manage my own emotions to remain effective, even under pressure.<br /> I seek out support to help me perform effectively.<br /> I recognise that some situations might affect my ability to deal with stress and pressure.<br /> I adapt my style and approach by understanding the emotional needs of the people I am working with and the public.<br /> I seek to understand the concerns of others even when they are unable to express themselves clearly.
Yes
Intelligent, Creative and Informed Policing
We are innovative and open-minded
Practitioner I seek to learn from new ideas and experiences, including the diverse experiences of others.<br /> I share suggestions with colleagues, speaking up to help improve existing working methods and practices. <br /> I reflect on my experience of different situations and act on the learning this provides <br /> I show that I am open to new ideas and ways of working.<br /> I adapt flexibly to change as the need arises, encouraging others to do the same.
Yes
Inclusive, Enabling and Visionary Leadership
We deliver, support and inspire
Practitioner I take opportunities to share my positive commitment to policing and its values with others.<br /> I take steps to understand how my work contributes to the purpose of policing and the priorities of my force. <br /> I am conscientious in my approach, working hard to provide the best service and remove obstacles that could prevent or hinder delivery. <br /> I take on challenging tasks to help to improve the service continuously and support my colleagues. <br /> I support the efficient use of resources to create the most value and to deliver the right impact.
Yes
Role Profile
Governance and Compliance: Data Protection Officer
Page: 326/11/2025 10:39:54
Resolute, Compassionat e and Committed
We take ownership Practitioner I approach tasks with enthusiasm and a positive attitude, adapting quickly from one situation to the next.<br /> I take responsibility for my own actions and decisions.<br /> I respond to demanding and tough situations, demonstrating commitment to tackling the issue.<br /> I seek appropriate advice and guidance on tasks and decisions when necessary.<br /> I take responsibility to regularly update people who are relying on me. <br /> I seek feedback to understand the quality of my work and the impact of my actions.
Yes
NOS
NOS Unit Unit Name Unit Description
Role Profile
Governance and Compliance: Data Protection Officer
Page: 426/11/2025 10:39:54