Skip to content
Job VacanciesIRELANDPost a job

Data Protection/Freedom of Information Officer/Oifigeach Cosanta Sonraí / um Shaoráil Faisnéise in Dublin

Closes
Salary
Not stated
Contract
Other
Sector
Public
Closes
19 Oct 2026

About the Role

Data Protection/Freedom of Information Officer/Oifigeach Cosanta Sonraí / um Shaoráil Faisnéise
Dublin, Ireland

Contract: Permanent Part-time - Onsite

Hours: 21 hours per week

Reporting to: Chief Executive Officer

Closing date: 19 October 2026

The Data Protection / Freedom of Information Officer holds primary operational and statutory responsibility for overseeing Clontarf Hospital’s adherence to data protection laws and the Freedom of Information (FOI) Act 2014. The post holder reports directly to the Chief Executive Officer, maintaining the professional independence required to act as the formal statutory Data Protection Officer (DPO) and formal Information Decision Maker.

Duties and Responsibilities

Data Protection Advisory & Compliance

  • Act as the principal point of contact for the Data Protection Commission (DPC) on all data protection issues and monitor all ongoing responses to regulatory requests.
  • Serve as the formal point of contact for internal and external regulatory organisations, patients, and staff regarding the processing of personal data.
  • Act as the first point of contact for data subjects wishing to make a formal complaint in relation to their rights and freedoms.
  • Work with the hospital’s ICT manager to develop ICT policies and procedures as they relate to GDPR, privacy laws, and data protection.
  • Assist and advise on corporate business decisions that carry data protection implications, ensuring that decisions are designed with data protection and privacy in mind.
  • Provide structured GDPR and Data Protection Act compliance planning and advisory support to Heads of Services/Departments in the hospital as necessary.
  • Assist and advise on the development, enhancement, and revision of Hospital policies, procedures, standards, guidelines, best practices, templates, and checklists. Ensure materials reflect changes in laws, regulatory mandates, or Hospital standards to drive operational consistency.
  • Prepare and communicate comprehensive reports regarding data protection compliance breaches and other relevant compliance updates to the CEO, the Executive Management Team, the Hospital Board and the Data Protection Commissioner.
  • Provide structured monthly updates directly to the CEO on all matters relating to data protection and GDPR compliance.
  • Ensure the timely adoption and execution of all GDPR and data privacy compliance requirements across all hospital departments.

Data Governance Operations & Registers

  • Centralise, maintain, and formally audit the organisational Record of Processing Activities (RoPA) under Article 30 of the GDPR.
  • Maintain a centralised register of signed Clontarf Hospital Data Sharing Agreements (DSAs)
  • Provide ongoing advice to Heads of Departments regarding GDPR compliance to ensure that formal agreements are actively in place for all existing and new contracts with third parties who process (view, access, store, or process) identifiable patient or employee data.
  • Actively review and assess any reported data protection incidents recorded on the Hospital’s Data Breach Log. Direct notifications to the Data Protection Commission as appropriate, and provide technical advice alongside letter templates to departments for formal breach notifications to affected data subjects.
  • Act as an advocate for data protection and privacy within Clontarf Hospital. Promote compliance by designing, updating, and delivering GDPR awareness and education training courses to hospital staff regarding the foundational importance of data protection in a rehabilitation hospital environment.

Data Protection Impact Assessments (DPIAs)

  • Undertake and systematically review completed Data Protection Impact Assessments (DPIAs) submitted by internal departments and external stakeholders.
  • Audit all newly proposed data processing activities, including new ICT systems, new mobile applications, research ethics applications, and new Electronic Referral Systems etc.
  • Recommend clear mitigating steps to reduce data risks if they are not initially identified by stakeholders. Risks must be deemed entirely acceptable under statutory frameworks for the post holder to formally sign off on the activity from a GDPR perspective.

Freedom of Information (FOI) Decision Maker

  • Responsibility for the end-to-end management of the hospital's FOI process.
  • Recording of requests, open communication with requesters, and adherence to statutory timeframes.
  • Co-ordinate and cross-reference records with relevant colleagues, hospital departments, and external agencies as appropriate.
  • Review and assess records, applying relevant legal exemptions appropriately to ensure strict adherence to the provisions of the FOI Act 2014.
  • Formulate and issue legally sound, timely decisions in line with the provisions of the FOI Act.
  • Maintain FOI files documenting the underlying decision and all relevant procedural matters to demonstrate institutional compliance with the Act and to aid internal or external reviews.
  • Liaise directly with the Appeals Officer when required. Prepare submissions to the Office of the Information Commissioner (OIC) when required.

GDPR Decision Maker (Information Requests / DSARs)

  • Lead the management of the GDPR process for all information requests, acting as the primary point of contact for Subject Access Requests under Article 15 of the GDPR.
  • Ensure the logging of requests, transparent communication with the requester, and adherence to strict statutory timelines.
  • Apply relevant restrictions or exemptions in line with GDPR and the Data Protection Acts 1988–2018.
  • Maintain files documenting the decision and all relevant procedural matters to demonstrate full compliance with GDPR and to aid independent reviews.
  • Compile and provide formal statistical information on SAR data for reporting to the EMT, Hospital Board and HSE Consumer Affairs.
  • Prepare formal submissions to the Office of the Data Protection Commission where required.

Requirements

  • Hold a 3rd Level qualification in a relevant field e.g., Data Protection, Information Compliance, Law, Records Management or a related discipline.
  • Have a minimum of 2 years’ experience in the area of Data Protection, Information Management and/or Records Management or similar role.
  • Experience managing GDPR and FOI processes.
  • Strong knowledge of Irish and EU Data Protection legislation.
  • Excellent organisational, analytical and decision-making skills.
  • High standard of integrity, professional judgement and communication skills.
  • Ability to work with multiple internal and external stakeholders.
  • Fluent command and understanding of the English language to include spoken and written word.

Details

Sector: public sector

Salary: HSE Consolidated pay-scale (Current Applicable Scale)

Organisational Context

Clontarf Hospital is a 160-bed Voluntary Hospital providing rehabilitation Services under Section 38 of the Health Act 2004 for Adults and Older Persons. At Clontarf Hospital, our committed, expert and compassionate staff provide excellent care to patients on their rehabilitation journey. Our goal is to work in partnership with patients, providing care that is tailored to their unique needs, empowering them to achieve their optimum level of independence at home and in their communities. The patient pathways include:

  • Older Persons Rehabilitation
  • Step-up beds and hospital avoidance pathways with the Integrated Care Team for Older Persons (ICPOP Team)
  • Specialist Rehabilitation Services including neuro-rehabilitation and rehabilitation after trauma for adults and older persons
  • Orthopaedic Rehabilitation

The Hospital has close links with the Mater Hospital, Beaumont Hospital, The National Orthopaedic Hospital, HSE Services and our Community Partners.

Documents & Campaign Information

Frequently asked

What are the essential criteria for this role?
Hold a 3rd Level qualification in a relevant field e.g., Data Protection, Information Compliance, Law, Records Management or a related discipline. Have a minimum of 2 years’ experience in the area of Data Protection, Information Management and/or Records Management or similar role. Experience managing GDPR and FOI processes. Strong knowledge of Irish and EU Data Protection legislation. Excellent organisational, analytical and decision-making skills. High standard of integrity, professional judgement and communication skills. Ability to work with multiple internal and external stakeholders. Fluent command and understanding of the English language to include spoken and written word.
What are the main duties of this role?
Act as the principal point of contact for the Data Protection Commission (DPC) on all data protection issues and monitor all ongoing responses to regulatory requests. Serve as the formal point of contact for internal and external regulatory organisations, patients, and staff regarding the processing of personal data. Act as the first point of contact for data subjects wishing to make a formal complaint in relation to their rights and freedoms. Work with the hospital’s ICT manager to develop ICT policies and procedures as they relate to GDPR, privacy laws, and data protection. Assist and advise on corporate business decisions that carry data protection implications, ensuring that decisions are designed with data protection and privacy in mind. Provide structured GDPR and Data Protection Act compliance planning and advisory support to Heads of Services/Departments in the hospital as necessary. Assist and advise on the development, enhancement, and revision of Hospital policies, procedures, standards, guidelines, best practices, templates, and checklists. Ensure materials reflect changes in laws, regulatory mandates, or Hospital standards to drive operational consistency. Prepare and communicate comprehensive reports regarding data protection compliance breaches and other relevant compliance updates to the CEO, the Executive Management Team, the Hospital Board and the Data Protection Commissioner. Provide structured monthly updates directly to the CEO on all matters relating to data protection and GDPR compliance. Ensure the timely adoption and execution of all GDPR and data privacy compliance requirements across all hospital departments. Centralise, maintain, and formally audit the organisational Record of Processing Activities (RoPA) under Article 30 of the GDPR. Maintain a centralised register of signed Clontarf Hospital Data Sharing Agreements (DSAs). Provide ongoing advice to Heads of Departments regarding GDPR compliance to ensure that formal agreements are actively in place for all existing and new contracts with third parties who process (view, access, store, or process) identifiable patient or employee data. Actively review and assess any reported data protection incidents recorded on the Hospital’s Data Breach Log. Direct notifications to the Data Protection Commission as appropriate, and provide technical advice alongside letter templates to departments for formal breach notifications to affected data subjects. Act as an advocate for data protection and privacy within Clontarf Hospital. Promote compliance by designing, updating, and delivering GDPR awareness and education training courses to hospital staff regarding the foundational importance of data protection in a rehabilitation hospital environment. Undertake and systematically review completed Data Protection Impact Assessments (DPIAs) submitted by internal departments and external stakeholders. Audit all newly proposed data processing activities, including new ICT systems, new mobile applications, research ethics applications, and new Electronic Referral Systems etc. Recommend clear mitigating steps to reduce data risks if they are not initially identified by stakeholders. Risks must be deemed entirely acceptable under statutory frameworks for the post holder to formally sign off on the activity from a GDPR perspective. Responsibility for the end-to-end management of the hospital's FOI process. Recording of requests, open communication with requesters, and adherence to statutory timeframes. Co-ordinate and cross-reference records with relevant colleagues, hospital departments, and external agencies as appropriate. Review and assess records, applying relevant legal exemptions appropriately to ensure strict adherence to the provisions of the FOI Act 2014. Formulate and issue legally sound, timely decisions in line with the provisions of the FOI Act. Maintain FOI files documenting the underlying decision and all relevant procedural matters to demonstrate institutional compliance with the Act and to aid internal or external reviews. Liaise directly with the Appeals Officer when required. Prepare submissions to the Office of the Information Commissioner (OIC) when required. Lead the management of the GDPR process for all information requests, acting as the primary point of contact for Subject Access Requests under Article 15 of the GDPR. Ensure the logging of requests, transparent communication with the requester, and adherence to strict statutory timelines. Apply relevant restrictions or exemptions in line with GDPR and the Data Protection Acts 1988–2018. Maintain files documenting the decision and all relevant procedural matters to demonstrate full compliance with GDPR and to aid independent reviews. Compile and provide formal statistical information on SAR data for reporting to the EMT, Hospital Board and HSE Consumer Affairs. Prepare formal submissions to the Office of the Data Protection Commission where required.
What are the hours and contract type for this role?
Permanent Part-time - Onsite. Hours: 21 hours per week

Similar jobs

Get new Dublin jobs by email

A tidy digest of matching roles. Confirm once, unsubscribe anytime.