Overview
Data Protection Assistant – maternity cover (9 months) at DfT Operator (DFTO). Hybrid location. Reporting to the Group Data Protection Officer within Legal.
About DfT Operator
DFTO is the government’s rail owning group. Its purpose is to bring privately-owned train operators into public ownership in advance of Great British Railways in 2027, and to improve operations through unified public ownership. DFTO has over 23,000 employees and delivers extensive rail services and journeys each year. The strategy is to unify and strengthen train operators under the DFTO banner and become industry-leading in safety, customer service, financial sustainability and operational performance.
Duration: 9 months maternity cover | Location: Hybrid | Reporting to: Group Data Protection Officer within legal
Primary Purpose of Job
Deliver day-to-day data protection services across DFTO’s operating companies. Take responsibility for the complete handling of Data Subject Access Requests (DSARs) and other statutory rights requests from receipt to final response, in line with legal deadlines and quality standards. Maintain accurate local data protection records, support routine operational checks, and coordinate information gathering from multiple teams. Ensure processes are applied consistently, statutory obligations are met, and potential compliance risks are identified and escalated promptly.
Key Responsibilities
- Deliver the full DSAR process for allocated operating companies from receipt to completion, including logging, co-ordinating searches, collating results, redacting personal data, and issuing responses within statutory deadlines.
- Process other rights requests (e.g., rectification, erasure, restriction) in line with legal requirements and DFTO procedures, escalating complex cases as required.
- Maintain complete, auditable records of all requests and correspondence to demonstrate compliance.
Local compliance record-keeping
- Maintain and update local Records of Processing Activities (ROPA), Information Asset Registers, and other compliance documentation to ensure accuracy and currency.
- Align local records with DFTO templates and update promptly following organisational or process changes.
- Gather and prepare evidence to support internal audits, inspections, and assurance reviews.
Operational liaison and co-ordination
- Act as the local contact point for routine data protection queries, providing guidance within defined procedures and escalating more complex matters to the Analyst or Group DPO.
- Coordinate information gathering from local teams to support DPIAs, LIAs, and other compliance work led by the Group DPO or Analysts.
- Maintain an organised local filing system to support efficient retrieval of compliance records and evidence.
Awareness and training support
- Deliver short, locally tailored induction and refresher sessions using DFTO materials.
- Track local completion rates for mandatory training and escalate non-compliance promptly.
Process improvement and flexibility
- Identify recurring issues in request handling or records management and propose practical improvements to the Analyst or Group DPO.
- Work flexibly across operating companies to meet priorities and deadlines.
Knowledge, Skills, Experience & Technical Qualifications
Knowledge
- Applied knowledge of UK GDPR, DPA 2018, and information rights principles in DSAR handling; commitment to ongoing learning.
- Understanding of statutory processes for fulfilling DSARs and handling sensitive personal data securely.
Skills
- Strong organisational skills to manage multiple statutory requests and compliance tasks to deadline.
- Attention to detail in reviewing and redacting personal data.
- Clear and professional written and verbal communication for internal and external audiences.
- Competence in Microsoft 365 (Outlook, Excel, Word, SharePoint) and ability to use case management and redaction tools.
Experience
- Experience in an administrative or compliance role involving handling of sensitive or confidential information.
- Prior experience with DSARs or similar statutory request processes is desirable.
Qualifications
- No formal qualification required; relevant training in data protection or information governance is an advantage.
Benefits/Other: Annual Leave starts at 25 days, rising with service (up to 30 days). Opportunities to learn and network across the wider industry.
Contact: For questions or reasonable adjustments, contact Dean Palmer.
Note: We are an inclusive employer and welcome applications from everyone. Flexible working options can be discussed.
Disclaimer: If applying on a secondment, inform your line manager prior to submission.
Seniority level
- Associate
Employment type
- Full-time
Job function
- Information Technology and General Business
Industries
- Rail Transportation
#J-18808-Ljbffr
Contact Detail:
DfT Operator Recruiting Team