Implementing data protection, GDPR, and other information-related legislation.
Information, records and knowledge management.
Strategy and policy formulation.
Interpretation of new legal requirements.
Integration of compliance into core business processes.
Project and change management.
Negotiation and influencing.
Delivery of training and skills acquisition programmes.
Nov 04 - Date
Tkm Consulting Managing Director
Deliver projects for private and public sector clients, managing strategic, corporate records management and related compliance. Recent experience includes delivery of information governance programmes, development and implementation of records management plans, knowledge and information audits, and legal compliance audits and assessments.
Specific data protection projects include risk-based programmes to address gaps in compliance, designing and integrating compliant procedures into core business processes, and assessment of GDPR requirements.
Offer adhoc advice on subject access requests, breach reporting, privacy impact assessments, and develop contractual documentation including both data processing and data sharing agreements. Also cover compliance with the Privacy and Electronic Communication Regulations.
Design, deliver and assess a range of recognised qualifications, together with customised workplace training.
Provide Data Protection Officer as a Service to a number of organisations.
Author of two business guides published by Chandos Publishing:
Knowledge, Information and the Business Process: Revolutionary Thinking or Common Sense? (published January 2007); and
Freedom of Information: working towards compliance (published November 2004)
Mar 15 – Mar 17
Highlands & Islands Airports Ltd
Managed the project to deliver information-related legislative compliance across the organisation, focusing on data protection, initial preparation for the GDPR, and public records legislation.
Developed the programme of organisational change necessary to achieve project goals. Includes the development and implementation of policies, procedures, legal agreements and frameworks, complemented by an organisation-wide customised training programme.
Dec 03 – Mar 08
Highlands & Islands Enterprise (HIE), Inverness
Information Compliance Project Manager (part time role from Nov 04)
HIE is the agency responsible for economic development in the Highlands and Islands. The agency comprises a number of offices located throughout the Highlands and Islands.
Data Protection expert for the Network that provided advice on all aspects of the legislation.
Management of the programme of activities to ensure compliance with Freedom of Information legislation which included:
Interpretation of the legislation to provide practical advice to HIE, businesses and the media on all aspects of integrating compliance into existing business processes, including legal agreements;
Development of processes and resourcing structure to meet the requirements of compliance while minimising the impact on core business deliverables;
Design and delivery of a training program for all staff across the organisation;
System development to support new processes;
Set up and management of the enquiry unit covering the whole of the HIE area.
Member of the team that won the International Information Award for Innovation in Content Management 2006.
Jun 02 – Dec 03
Qualifications & Curriculum Authority (QCA), London
Member of programme board that successfully implemented a programme of change for the E-business Group (EBG), transforming service delivery.
Delivered a strategy for skills acquisition for the group. Successfully project managed the improvement to EBG customer services, re-engineering associated business processes and increasing customer satisfaction by over 30%.
Managed the Knowledge Management Team, which included the library and the programme of activity to improve knowledge and information management across QCA.
Jun 99 – Jun 02
Naval Manning Agency (NMA), Royal Navy (RN)
Managed project to implement the Data Protection Act (1998) across NMA.
Managed the NMMIS programme of system change, including several large business-critical projects.
RN representative on a multi-million pound system development and change management project to redesign business processes and implement a new personnel and logistics system.
96 - 99
HMS Collingwood, RN
Education and Qualifications
2016: Post Graduate Certificate in Data Protection Law and Information Governance (Distinction, Dean's List), Northumbria University
2003: MSc Knowledge Management Systems (Distinction), South Bank University London
2000: MSc Education and Training Management (Pass), University of Portsmouth, Hampshire
Vocations qualifications & membership
2017: SQA Assessor L&D9i award
2010: NEBOSH National General Certificate in Occupational Health and Safety (Distinction), Reid Kerr College
2003: PRINCE2 Project Management Practitioner