Job Introduction
At Avery Healthcare, our commitment to exceptional care begins with the people who deliver it. We champion our teams, invest in their growth, and create an environment where professionalism, respect, and purpose guide everything we do.
We are now seeking an experienced Subject Access Request Administrator to join our central support team based in Northampton. Working in close partnership with our National Data Protection Officer, you will play a vital role in safeguarding the rights, privacy, and dignity of our residents, colleagues, and families.
About the Role
This position is responsible for coordinating and managing Subject Access Requests (SARs) and other data rights requests across Avery Healthcare, ensuring full compliance with UK GDPR and the Data Protection Act 2018. You will act as a key liaison between the National DPO, care homes, regional teams, and external requestors, ensuring that all disclosures are lawful, accurate, and handled with the highest level of professionalism.
Key Responsibilities
SAR Coordination — Receive, log, and acknowledge SARs and data rights requests; manage the end‑to‑end process in collaboration with the National DPO; ensure statutory deadlines are met.
Information Gathering — Work closely with care homes, regional teams, and support functions to obtain all relevant documentation.
Document Review & Redaction — Review care records, HR files, incident reports, and other sensitive materials; apply precise redaction to protect third‑party and confidential information; ensure disclosures are proportionate and compliant.
Compliance & Governance — Maintain accurate audit trails; ensure all activity aligns with UK GDPR, the Data Protection Act 2018, and Avery policies; escalate complex or high‑risk cases appropriately.
Stakeholder Support — Provide clear guidance to care home teams on documentation standards and information provision; respond professionally to requestors, families, and external bodies.
Continuous Improvement — Support enhancements to SAR processes, templates, and tracking systems; contribute to internal audits and compliance reporting; promote data‑protection best practice across the organisation.
About You
You’ll be someone who naturally lives our values — caring, supportive, honest, respectful, and accountable — and brings them into everything you do.
Skills & Experience
Experience managing SARs or working within data protection / information governance
Strong understanding of UK GDPR and the Data Protection Act 2018
Experience handling sensitive personal data, ideally within a healthcare or care‑home environment
Excellent attention to detail, particularly in document review and redaction
Strong organisational skills with the ability to manage competing deadlines
Confident communicator with the ability to engage professionally at all levels
Personal Attributes
Professional, discreet, and trustworthy
Methodical and highly organised
Able to work independently and prioritise effectively
Calm and resilient when managing complex or sensitive cases
Desirable
Experience in a healthcare or care‑home setting
Awareness of CQC expectations relating to record‑keeping and data protection
About Avery
Avery Healthcare is one of the UK’s leading providers of luxury elderly care, with over 100 homes nationwide. Guided by our vision of “creating meaningful lives together,” we foster a culture where colleagues feel supported, empowered, and valued. We believe in delivering care with dignity, purpose, and compassion — and in creating a workplace where people genuinely enjoy being part of the team.
Additional Information
A DBS Disclosure is required (funded by Avery Healthcare)
Proof of eligibility to work in the UK is essential
Occasional travel to care homes or other Avery sites may be required
This advert may close early depending on application volume
