-
-
FOI request (FOIR-708633358)
Data Protection Services
Requested Thu 24 April 2025
Responded Thu 01 May 2025Under the Freedom of Information Act 2000, please provide the following information about your procurement of any:
(i) external Data Protection Officer (DPO)
(ii) Data protection GDPR compliance services for the period FY2022-23 to FY2024-25.
1. Current DPO arrangements
1.1 Is the organisation's DPO and other staff that work on data protection compliance:
(a) An internal employee?
(b) A DPO provided by an external service provider?
(c) Hybrid (internal staff with external service provider support)?
1.2 Where services are provided by external providers, please share the following information:
(a) The Company name(s).
(b) Annual spend by your organisation (FY2022/2023 through to FY2024/2025).
(c) The highest day rate paid.
(d) Contract dates (start/end/renewal terms).
(e) A brief description of the project or services provided (for instance, project title or internal reference).
(f) Services covered (for example, audits, breach management, SAR management, delivery of Data Protection Impact Assessments).
- Please indicate what deliverables were produced.
- Procurement method (for example, open competition, framework agreement, direct award) and name of the procurement framework, if applicable.
2. Consultancy Spend
2.1 What is the organisation's total annual expenditure on data protection/GDPR consultancy services?
2.2 For projects which have a spend of more than £5k), please share the following information:
- Supplier company name.
- The scope of the Project (for example, ICO investigation support and DPIA support, Internal Audit recommendation support).
- Spend.
- Procurement method.
3. Data Protection Compliance Staffing
3.1 The Number of in-house data protection staff in the organisation (FTE).
3.2 Are there any vacant roles?
3.3 Where there any ICO investigations, audits, or enforcement actions for the period from FY2022/2023 to FY 2024/2025?
4. Future Plans
4.1 Is your organisation planning to put out to tender for any DPO/GDPR services in the current financial year?
<4.2 If yes, please provide the following:
- Expected timeline.
- Budget range.
- Key service requirements.
- Procurement method.
Response
1. Current DPO arrangements:
1.1 An internal employee
1.2 Not applicable
2. Consultancy Spend:
2.1 £0.00
2.2 Not applicable
3. Data Protection Compliance staffing:
3.1 0.5 FTE
3.2 No
3.3 No
4. Future Plans:
4.1 No
4.2 Not applicable
-
-
Freedom of Information
Contact
Contact us if you have a question about democratic services.
Comments
The content on this page is the responsibility of our Democratic Services team.