Leave this site
We use some essential cookies to make our website work. We’d like to set additional cookies so we can remember your preferences and understand how you use our site.
You can manage your preferences and cookie settings at any time by clicking on “Customise Cookies” below. For more information on how we use cookies, please see our Cookies notice.
Your cookie preferences have been saved. You can update your cookie settings at any time on the cookies page.
Your cookie preferences have been saved. You can update your cookie settings at any time on the cookies page.
Sorry, there was a technical problem. Please try again.
This site is a beta, which means it's a work in progress and we'll be adding more to it over the next few weeks. Your feedback helps us make things better, so please let us know what you think.
Request
Under the Freedom of Information Act 2000, please provide the following information about your procurement of any
(i) external Data Protection Officer (DPO),
(ii) Data protection GDPR compliance services for the period FY2022-23 to FY2024-25:
1. Current DPO arrangements
1.1 Is the organisation’s DPO and other staff that work on data protection
compliance:
(a) An internal employee
(b) A DPO provided by an external service provider
(c) Hybrid (internal staff with external service provider support)
1.2 Where services are provided by external providers, please share the following information:
(a) The Company name(s)
(b) Annual spend by your organisation (FY2022/2023 through to
FY2024/2025)
(c) The highest day rate paid
(d) Contract dates (start/end/renewal terms)
(e) A brief description of the project or services provided (for instance, project title or internal reference)
(f) Services covered (e.g., audits, breach management, SAR management, delivery of DPIAs) • Please indicate what deliverables were produced • Procurement method (e.g., open competition, framework agreement, direct
award) and name of the procurement framework, if applicable.
2. Consultancy Spend
2.1 What is the organisation’s, total annual expenditure on data protection/GDPR consultancy services?
2.2 For SoW/projects which have a spend of more than £5k), please share the following information:
3.1 The Number of in-house data protection staff in the organisation?
(FTE)
3.2 Are there any vacant roles? (Yes/No)
3.3 Where there any ICO investigations, audits, or enforcement actions for the period from FY2022/2023 to FY 2024/2025?
4. Future Plans
4.1 Is your organisation planning to put out to tender for any DPO/GDPR services in the current financial year?
4.2 If yes please provide the following:
Expected timeline
Budget range
Key service requirements
Procurement method
Response
Please find enclosed our response.
Under the Freedom of Information Act 2000, please provide the following information about your procurement of any
(i) external Data Protection Officer (DPO),
(ii) Data protection GDPR compliance services for the period FY2022-23 to FY2024-25:
1. Current DPO arrangements
1.1 Is the organisation’s DPO and other staff that work on data protection
compliance:
(a) An internal employee – yes internal employee
(b) A DPO provided by an external service provider - No
(c) Hybrid (internal staff with external service provider support) - No
1.2 Where services are provided by external providers, please share the following information:
(a) The Company name(s)
(b) Annual spend by your organisation (FY2022/2023 through to FY2024/2025)
(c) The highest day rate paid
(d) Contract dates (start/end/renewal terms)
(e) A brief description of the project or services provided (for instance, project title or internal reference)
(f) Services covered (e.g., audits, breach management, SAR management, delivery of DPIAs)
• Please indicate what deliverables were produced
• Procurement method (e.g., open competition, framework agreement, direct award) and name of the procurement framework, if applicable.
Not applicable to 1.2 (a – f)
2. Consultancy Spend
2.1 What is the organisation’s, total annual expenditure on data protection/GDPR consultancy services?
Not applicable – we do not use a consultancy for this work.
2.2 For SoW/projects which have a spend of more than £5k), please share the following information:
Not applicable
3. Data Protection Compliance staffing
3.1 The Number of in-house data protection staff in the organisation?
(FTE)
3.2 Are there any vacant roles? (Yes/No)
3.3 Where there any ICO investigations, audits, or enforcement actions for the period from FY2022/2023 to FY 2024/2025?
1 x DPO
There are vacant roles which will be advertised in the coming months
ICO reprimand issued in March 2024, details of which can be found: https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2024/03/ico-reprimands-west-midlands-police-for-data-protection-failure/
4. Future Plans
4.1 Is your organisation planning to put out to tender for any DPO/GDPR services in the current financial year?
4.2 If yes please provide the following: