Skip to content
site-logo

FEDIP Job Profiles

  • Home
  • About
  • All Job Roles
  • Submit Feedback
  • News
  • FAQs

SFIA Skills: Personal data protection (PEDP)

Regulatory compliance (Level 5)

Reviews and assists own organisation to maintain a privacy notice and record of processing activities (ROPA). Advises and, where necessary, assists on the application of data protection impact assessments (DPIA) and maintain records for compliance within regulatory access requirements.

Regulatory compliance (Level 6)

Identifies the impact of any relevant statutory, internal or external regulations on the organisation’s use of personal information and develops strategies for compliance. Leads and plans activities to communicate and implement information management and privacy strategies. Monitors and advises on application of privacy notice, ROPA and application of DPIAs. Acts as contact point for regulatory authority (Commissioner) on issues relating to processing, prior consultations and other matters as appropriate.

Cooperation and relationships (PEDP) (Level 6)

Instigates and encourages cooperation where opportunities and requirements to work with subject matter experts exist to build effective relationships within the organisation. Demonstrates how collaborative working will increase the organisation’s effectiveness, reduce risk and create trust and resilience with the general public. Areas to work with should include legal, public relations, learning and development, procurement, information security, IT, security, data management and architecture.

Policies, procedures and governance (PEDP) (Level 6)

Consults, collaborates and offers expert advice on developing organisational policies, procedures, best practice, privacy policies, standards and guidelines ensuring recognised data protection definitions and practices are applied throughout the organisation. Has due regard to the risk associated with processing operations, taking into account the nature, context and purpose of processing.

Incident Response (PEDP) 5

Assesses and manages the risk for any potential personal data breaches and cyber incidents. Sets in motion the agreed procedures to identify breach, including with third parties, works within statutory timeline, mitigates risk, and maintains communications with Data Protection Officer (DPO), or equivalent when not required, to comply with statutory notification to the regulatory authority (Commissioner) if breach confirmed.

Information sharing (PEDP)(Level 6)

Advises on information sharing requirements including agreements and ad hoc disclosures for example police requests.

Data protection by design and default (PEDP)(Level 6)

Monitoring compliance with data protection and default through DPIAs and associated documentation.

Training and raising awareness (PEDP)(Level 6)

Influencing culture through training and raising the awareness of staff.

Internal compliance (PEDP)(IG)(Level 6)

Monitors compliance of the organisation (or its processors) in relation to the protection of personal data, including the assignment of responsibilities to manage functions under UK GDPR.

Individual rights requests (PEDP)(IG)(Level 6)

Monitors the organisation’s compliance with individual rights requests.

Individual rights requests (PEDP)(IG)(Level 5)

Processes straight forward subject access requests in accordance with GDPR requirements as applicable. Maintains compliance with appropriate timeframes, any allowed charges or refusals.

Information Governance Audit (PEDP) (Level 5)

Principles, practices, tools and techniques of information governance auditing and the Data Security and Protection Toolkit.

Access requests (Level 4)

Supports the processing of subject access requests in accordance with GDPR requirements.

Regulatory compliance (Level 5)

Reviews and assists own organisation to maintain a privacy notice and record of processing activities (ROPA). Advises and, where necessary, assists on the application of data protection impact assessments (DPIA) and maintain records for compliance within regulatory access requirements.

Job Families

  • IT Operations (47)
    • Application Operations Engineer (6)
    • End User Computing Engineer (5)
    • Infrastructure Operations Engineer (5)
    • Infrastructure Engineer (5)
    • Service Transition Manager (4)
    • Service Desk Manager (4)
    • IT Service Manager (4)
    • Command and Control Centre Manager (4)
    • Change and Release Manager (3)
    • Business Relationship Manager (3)
    • Incident Manager (2)
    • Problem Manager (2)
  • User Centred Design (37)
    • User Researcher (6)
    • Service Designer (6)
    • Interaction Designer (6)
    • Graphic Designer (6)
    • Content Designer (6)
    • Accessibility Specialist (4)
    • Technical Writer (2)
    • Content Strategist (1)
  • Architecture (27)
    • Solutions Architect (5)
    • Technical Architect (5)
    • Business Architect (4)
    • Enterprise Architect (4)
    • Network Architect (3)
    • Data Architect (3)
    • Security Architect (3)
  • Data (25)
    • Data Engineer (5)
    • Data Analyst (5)
    • Analytics Engineer (4)
    • Data Scientist (4)
    • Data Governance Manager (3)
    • Machine Learning Engineer (2)
    • Data Ethicist (2)
  • Software Development (24)
    • Software Developer (9)
    • Development Operations Engineer​​ (9)
    • Frontend ​Developer​ (6)
  • Product and Delivery (21)
    • Business Analyst (6)
    • Product Manager (5)
    • Delivery Manager (4)
    • Digital Portfolio Manager (4)
    • Service Owner (1)
    • Programme Delivery Manager (1)
  • Patient Services (18)
    • Clinical Coder (7)
    • Records and Information Manager​​ (4)
    • Patient Access​ Manager​ (4)
    • Data Quality​ Officer​ (3)
  • Quality Assurance Testing (10)
    • Quality Assurance Testing (QAT) Analyst (4)
    • Test Engineer (4)
    • Test Manager (2)
  • Cyber Security (10)
    • Cyber Security Specialist (Governance Risk and Compliance) (4)
    • Cyber Security Specialist (Operations) (4)
    • Cyber Security Analyst (2)
  • Digital Leadership Roles (9)
    • Chief Technology Officer (1)
    • Chief Information Officer (1)
    • Chief Audit Officer (1)
    • CxIO (1)
    • Chief Information Security Officer (1)
    • Chief Analytics Officer (1)
    • Caldicott Guardian (1)
    • Chief Data Officer (1)
    • Chief Pharmacy Information Officer (1)
  • Knowledge, Library and Information Management (8)
    • Knowledge Manager (5)
    • Library Manager (2)
    • Information Manager (1)
  • Digital Education Services (6)
    • Digital Education Specialist (2)
    • Digital Education Manager (2)
    • Digital Education Administration (1)
    • Digital Education Trainer​ (1)
  • Information Governance (6)
    • Information Governance Officers​ (3)
    • Information Governance Manager​​s (2)
    • Data Protection Officer​​ (1)
  • Clinical Informatics (3)
    • Clinical Informatician​ (2)
    • Clinical Safety Officer (1)
FEDIP logo

The Federation for Informatics Professionals in Health and Care

Registered in England and Wales No. 10639143

email: info@fedip.org

Copyright © 2026 All Rights Reserved FEDIP | Use of cookies | Legal notices
Registered in England and Wales No. 10639143

website by Sarah Scriven