Skip to main content

Request Number: FOI/14557

Category: Finance and Procurement - Contracts

Subject: Data Protection Services

Request and Answer: 

Your request for information has now been considered. In respect of Section 1(1)(a) of the Act we can confirm that the Police Service of Northern Ireland does hold some of the information to which your request relates. The decision has been taken to disclose the following.

Request 1
Under the Freedom of Information Act 2000, please provide the following information  about your procurement of any 
(i) external Data Protection Officer (DPO),
(ii) Data protection GDPR compliance services for the period FY2022-23 to FY2024-25:

Current DPO arrangements. Is the organisation's DPO and other staff that work on data protection compliance:
a) An internal employee
b) A DPO provided by an external service provider
c) Hybrid (internal staff with external service provider support)

Answer 1a 

Yes 

Answers 1b and 1c

No

Request 2 
Where services are provided by external providers, please share the following information:
a) The Company name(s)
b) Annual spend by your organisation (FY2022/2023 through to FY2024/2025)
c) The highest day rate paid
d) Contract dates (start/end/renewal terms)
e) A brief description of the project or services provided (for instance, project title or internal reference)
f) Services covered (e.g., audits, breach management, SAR management, delivery of DPIAs)
g) Please indicate what deliverables were produced
h) Procurement method (e.g., open competition, framework agreement, direct award) and name of the procurement framework, if applicable.

Request 3 
Consultancy Spend, what is the organisation's, total annual expenditure on data protection/GDPR consultancy services?

Request 4

For SoW/projects which have a spend of more than £5k), please share the following information:
a) Supplier company name
b) The scope of the Project (e.g., "ICO investigation support", DPIA support, Internal Audit recommendation support)
c) Spend
d) Procurement method

Answers 2, 3 and 4 

Your request for information has now been considered. In respect of Section 1(1)(a) of the Act we can confirm that the Police Service of Northern Ireland (PSNI) does not hold information in relation to your requests. Enquiries made in relation to your request failed to locate any records or documents relevant to your request based on the information you have provided. 

Accordingly, we have determined that the Police Service of Northern Ireland does not hold the information to which you seek access.

Request 5

Data Protection Compliance Staffing- what is the number of in-house data protection staff in the organisation? (FTE)

Answer 5 

There are currently 7 full time equivalent (FTE) in the Data Protection Office.

Request 6 
Are there any vacant roles? (Yes/No)

Answer 6

Yes

Request 7 
Where there any ICO investigations, audits, or enforcement actions for the period from FY2022/2023 to FY 2024/2025?

Answer 7 

Yes

Request 8 
Future Plans -Is your organisation planning to put out to tender for any DPO/GDPR services in the current financial year?

Answer 8

No

Request 9
 If yes please provide the following:
a) Expected timeline
b) Budget range
c) Key service requirements
d) Procurement method

Fulfilment of this request:
Format: Prefer CSV/Excel, Word or PDF or any commonly used filetype format.
If fulfilling the full request would exceed the appropriate cost limit under Section 12 of the Act, please provide as much of the information as possible within the limit, and advise me under your obligations in Section 16 on how I may refine the request to bring it within scope.

Answer 9 
Your request for information has now been considered. In respect of Section 1(1)(a) of the Act we can confirm that the Police Service of Northern Ireland (PSNI) does not hold information in relation to your requests. Enquiries made in relation to your request failed to locate any records or documents relevant to your request based on the information you have provided. 

Accordingly, we have determined that the Police Service of Northern Ireland does not hold the information to which you seek access.

Please note the answers above relate solely to the Data Protection Office and does not cover other related data protection areas within PSNI.

It should also be noted that the PSNI is not obliged to search for, or compile some of the requested information before refusing a request that we estimate will exceed the appropriate limit. The ICO advised that we are not obliged to search up to the appropriate limit simply because the applicant has asked. As set out in their guidance below, a request framed by the cost limit is not a valid request.                      

https://ico.org.uk/for-organisations/foi/freedom-of-information-and-environmental-information-regulations/recognising-a-request-made-under-the-freedom-of-information-act-section-8/