Data Governance Manager
NewBe an early applicantSalary: £37,500 - 42,500 per year
Requirements:- A recognised professional qualification in data protection or privacy, such as the BCS Practitioner Certificate in Data Protection, IAPP CIPP/E, or an equivalent recognised professional qualification.
- Strong working knowledge of UK GDPR and the Data Protection Act 2018.
- Previous professional experience in data governance, data protection, information governance, information security or a closely related field.
- Practical experience of managing data protection compliance, including SARs, DPIAs, privacy risks and data governance policies.
- Experience of conducting data access reviews, governance audits, compliance reviews or risk assessments.
- An understanding of role-based access controls, security groups and the principle of least privilege.
- An understanding of Data Loss Prevention, information classification and data leakage risks.
- Experience of working with or supporting an ISO 27001 Information Security Management System.
- Strong written and verbal communication skills, with the ability to explain regulatory and technical matters to both employees and senior management.
- Strong organisational and project management skills.
- The ability to work independently and confidently challenge practices where they create data protection, security or compliance risks.
- An ISO/IEC 27001 qualification, such as Internal Auditor, Lead Implementer, Lead Auditor or equivalent, is desirable.
- A relevant degree or professional qualification in data protection, information governance, information security, cyber security, law, risk or compliance is desirable.
- Experience of the ISO 27001 framework and providing operational support to achieving and maintaining certification is desirable.
- Previous experience acting as, or supporting, a Data Protection Officer is desirable.
- Experience implementing data classification, retention management or Data Loss Prevention controls is desirable.
- Experience with role-based access controls and periodic user-access reviews is desirable.
- Experience within a large, multi-site organisation is desirable.
- Familiarity with Microsoft 365 security, compliance and data governance tools, including SharePoint, OneDrive and Microsoft Purview, is desirable.
- Data protection experience of 1 year is required.
- Act as the principal point of contact within the business for data protection and data governance matters.
- Manage and coordinate Subject Access Requests (SARs) and other data subject rights requests.
- Monitor compliance with UK GDPR, the Data Protection Act 2018 and other applicable data protection requirements.
- Provide advice and guidance to management and employees regarding their data protection responsibilities.
- Support and advise the business on Data Protection Impact Assessments (DPIAs) and data-related risk assessments.
- Maintain, audit and develop the companys Data Governance Policies.
- Support and maintain the companys ISO 27001 compliance framework.
- Work closely with IT, HR, Legal and operational departments to identify and manage data risks.
- Review how data is collected, stored, accessed, retained, transferred and shared across the business.
- Promote a strong culture of data security, compliance and responsible data use throughout the organisation.
- Establish and maintain a formal process for reviewing user access rights and security groups across company systems.
- Ensure employees only have access to the information, reports, applications and systems required for their role.
- Conduct regular reviews of access to reporting platforms, shared folders, SharePoint, OneDrive, shared mailboxes and other company systems.
- Review access arrangements across individual departments and ensure appropriate controls are applied consistently throughout the business.
- Establish controls to reduce the risk of unauthorised extraction, transfer or disclosure of company information.
- Work with IT to develop appropriate Data Loss Prevention controls.
- Review and develop controls around the emailing of commercially sensitive information to personal or unauthorised external email addresses.
- Establish appropriate monitoring and controls for the use of removable storage and memory devices.
- Review controls around access to company systems from personal, unauthorised or unknown devices.
- Support the development of appropriate controls for company laptops, mobile devices and other authorised equipment.
- Review printing requirements and implement appropriate controls, monitoring and traceability where commercially sensitive information may be printed.
- Develop appropriate controls around downloading, exporting, forwarding and printing sensitive business reports.
- Review the use of messaging applications and personal mobile devices where company or customer information may be shared.
- Work with HR to ensure confidentiality requirements and appropriate contractual protections support the companys wider data governance framework.
- Investigate suspected or attempted breaches of company data governance policies and escalate matters appropriately.
- Establish and maintain a comprehensive Company Data Register.
- Develop a formal Data Classification Framework, categorising information according to sensitivity and business risk.
- Establish clear ownership of data and identify who should be authorised to access different categories of information.
- Work with IT to introduce appropriate technical controls for data classification and protection.
- Establish and implement data retention and deletion policies.
- Develop processes for regular Data Risk Reviews across departments and business systems.
- Ensure data governance and data availability are appropriately considered within Business Continuity and Disaster Recovery planning.
- Review how data is stored, accessed, transferred and shared throughout the organisation.
- Establish appropriate governance controls around third-party systems and cloud-based services.
- Develop a structured process for reviewing data access when employees join, change roles or leave the organisation.
- Monitor changes in legislation, technology and best practice and recommend improvements where appropriate.
- Conduct scheduled audits of data access permissions and governance controls.
- Identify excessive, inappropriate or unnecessary access to company information.
- Monitor compliance with data governance policies and agreed security controls.
- Review data-related incidents, attempted breaches and unusual activity.
- Work with IT to ensure appropriate monitoring and reporting is in place for potentially unauthorised access or movement of information.
- Track agreed actions and ensure identified weaknesses are addressed.
- Produce a monthly Data Governance report for senior management and the Board, highlighting key risks, incidents, audit findings, outstanding actions and areas requiring improvement.
- Provide recommendations to senior management regarding improvements to data security and governance arrangements.
- Cloud
- Support
- Microsoft 365
- Mobile
- Security
- SharePoint
- Office 365
More:
Bond International is a major distributor of tyres in the UK, operating a nationwide B2B tyre distribution service and acting as a dedicated third-party logistics provider to some of the worlds leading tyre brands. We are looking to appoint a Data Governance Manager based at our Head Office in Pocklington, East Yorkshire. This is a full-time, permanent, office-based role working Monday to Friday, 09:00 to 17:30, 40 hours per week. The salary is £37,500–£42,500 per annum, dependent on experience, and the role includes on-site parking. We offer the opportunity to shape our future data governance strategy and work closely with senior management, IT, HR, Legal and operational teams across the business.
last updated 35 week of 2026