Award

NHS GDPR Compliance Tool

THE COMMON SERVICES AGENCY (MORE COMMONLY KNOWN AS NHS NATIONAL SERVICES SCOTLAND) (NSS)

This public procurement record has 2 releases in its history.

Award

11 Aug 2025 at 00:00

Tender

12 Dec 2024 at 00:00

Summary of the contracting process

The procurement process for the NHS GDPR Compliance Tool, initiated by NHS National Services Scotland (NSS), is focused on acquiring services to enhance their Information Governance through a Comprehensive GDPR Compliance Tool. This tool is pivotal for tasks such as data protection assessments and information asset management. Situated in Edinburgh, Scotland, this process uses an open procurement method, offering an active contract valued at £900,000. The tender was publicly tendered using an open procedure, with an initial active stage for submissions ending on 27 January 2025, demonstrating the importance placed on maintaining regional compliance and operational efficiency in the health sector.

This tender presents significant opportunities for businesses specialising in data protection, compliance services, and information management systems. With the contract awarded to AWTG LTD, a small to medium enterprise based in London, the contract underscores the potential for SMEs to secure lucrative public contracts, particularly those with expertise in GDPR and information governance solutions. Companies skilled in providing high-quality, value-driven compliance tools that enhance operational efficiency are well-positioned to compete for similar opportunities in the future. Engaging in such contracts not only facilitates business growth but also aligns with strategic initiatives to support local economies and community benefits, integral to public sector procurement in Scotland.

Find more tenders on our Open Data Platform.
How relevant is this notice?

D3 Tenders Premium

Win More Public Sector Contracts

AI-powered tender discovery, pipeline management, and market intelligence — everything you need to grow your public sector business.

Notice Title

NHS GDPR Compliance Tool

Notice Description

Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.

Lot Information

Lot 1

Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.

Renewal: The Agreement includes two optional extension periods of 12 months each.

Publication & Lifecycle

Open Contracting ID
ocds-r6ebe6-0000784857
Publication Source
Public Contracts Scotland
Latest Notice
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=AUG536763
Current Stage
Award
All Stages
Tender, Award

Procurement Classification

Notice Type
OJEU - F3 - Contract Award Notice
Procurement Type
Standard
Procurement Category
Services
Procurement Method
Open
Procurement Method Details
Open procedure
Tender Suitability
Not specified
Awardee Scale
SME

Common Procurement Vocabulary (CPV)

CPV Divisions

72 - IT services: consulting, software development, Internet and support


CPV Codes

72000000 - IT services: consulting, software development, Internet and support

Notice Value(s)

Tender Value
£900,000 £500K-£1M
Lots Value
£900,000 £500K-£1M
Awards Value
Not specified
Contracts Value
£512,000 £500K-£1M

Notice Dates

Publication Date
11 Aug 20256 months ago
Submission Deadline
27 Jan 2025Expired
Future Notice Date
Not specified
Award Date
22 Jul 20257 months ago
Contract Period
Not specified - Not specified
Recurrence
Not specified

Notice Status

Tender Status
Complete
Lots Status
Complete
Awards Status
Not Specified
Contracts Status
Active

Contracting Authority (Buyer)

Main Buyer
THE COMMON SERVICES AGENCY (MORE COMMONLY KNOWN AS NHS NATIONAL SERVICES SCOTLAND) (NSS)
Contact Name
Ross Glen
Contact Email
michael.walker3@nhs.scot, ross.glen3@nhs.scot
Contact Phone
+44 1312756000

Buyer Location

Locality
EDINBURGH
Postcode
EH12 9EB
Post Town
Edinburgh
Country
Scotland

Major Region (ITL 1)
TLM Scotland
Basic Region (ITL 2)
TLM1 East Central Scotland
Small Region (ITL 3)
TLM13 City of Edinburgh
Delivery Location
TLM Scotland

Local Authority
City of Edinburgh
Electoral Ward
Drum Brae/Gyle
Westminster Constituency
Edinburgh South West

Supplier Information

Number of Suppliers
1
Supplier Name

AWTG

Further Information

Notice Documents

Open Contracting Data Standard (OCDS)

View full OCDS Record for this contracting process

Download

The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.

{
    "tag": [
        "compiled"
    ],
    "id": "ocds-r6ebe6-0000784857-2025-08-11T00:00:00Z",
    "date": "2025-08-11T00:00:00Z",
    "ocid": "ocds-r6ebe6-0000784857",
    "initiationType": "tender",
    "parties": [
        {
            "id": "org-70",
            "name": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)",
            "identifier": {
                "legalName": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)"
            },
            "address": {
                "streetAddress": "1 South Gyle Crescent",
                "locality": "Edinburgh",
                "region": "UKM",
                "postalCode": "EH12 9EB"
            },
            "contactPoint": {
                "email": "michael.walker3@nhs.scot",
                "telephone": "+44 1312756000",
                "url": "http://www.publictendersscotland.publiccontractsscotland.gov.uk/"
            },
            "roles": [
                "buyer",
                "centralPurchasingBody"
            ],
            "details": {
                "classifications": [
                    {
                        "id": "Body governed by public law",
                        "scheme": "TED_CA_TYPE"
                    },
                    {
                        "id": "07",
                        "description": "Health",
                        "scheme": "COFOG"
                    }
                ],
                "url": "http://www.nss.nhs.scot/browse/procurement-and-logistics"
            }
        },
        {
            "id": "org-71",
            "name": "Sheriff Court House",
            "identifier": {
                "legalName": "Sheriff Court House"
            },
            "address": {
                "locality": "Edinburgh",
                "postalCode": "EH1 1LB"
            },
            "contactPoint": {
                "url": "http://"
            },
            "roles": [
                "reviewBody"
            ]
        },
        {
            "id": "org-3",
            "name": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)",
            "identifier": {
                "legalName": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)"
            },
            "address": {
                "streetAddress": "1 South Gyle Crescent",
                "locality": "Edinburgh",
                "region": "UKM",
                "postalCode": "EH12 9EB"
            },
            "contactPoint": {
                "name": "Ross Glen",
                "email": "ross.glen3@nhs.scot",
                "url": "http://"
            },
            "roles": [
                "buyer",
                "centralPurchasingBody"
            ],
            "details": {
                "classifications": [
                    {
                        "id": "Body governed by public law",
                        "scheme": "TED_CA_TYPE"
                    },
                    {
                        "id": "07",
                        "description": "Health",
                        "scheme": "COFOG"
                    }
                ],
                "url": "http://www.nss.nhs.scot/browse/procurement-and-logistics"
            }
        },
        {
            "id": "org-243",
            "name": "AWTG LTD",
            "identifier": {
                "legalName": "AWTG LTD"
            },
            "address": {
                "streetAddress": "8 Canham Mews, Canham Road",
                "locality": "London",
                "region": "UKI",
                "postalCode": "W37SR"
            },
            "contactPoint": {
                "telephone": "+44 02035155151"
            },
            "roles": [
                "supplier"
            ],
            "details": {
                "scale": "sme",
                "url": "http://"
            }
        },
        {
            "id": "org-11",
            "name": "Sheriff Court House",
            "identifier": {
                "legalName": "Sheriff Court House"
            },
            "address": {
                "streetAddress": "27 Chambers Street",
                "locality": "Edinburgh",
                "postalCode": "EH1 1LB"
            },
            "contactPoint": {
                "telephone": "+44 1312252525",
                "url": "https://scotcourts.gov.uk/the-courts/sheriff-court/about-sheriff-courts"
            },
            "roles": [
                "reviewBody"
            ]
        }
    ],
    "buyer": {
        "name": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)",
        "id": "org-3"
    },
    "tender": {
        "id": "ocds-r6ebe6-0000784857",
        "title": "NHS GDPR Compliance Tool",
        "description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
        "status": "complete",
        "items": [
            {
                "id": "1",
                "deliveryLocation": {
                    "description": "Scotland"
                },
                "deliveryAddresses": [
                    {
                        "region": "UKM"
                    },
                    {
                        "region": "UKM"
                    }
                ],
                "relatedLot": "1"
            }
        ],
        "value": {
            "amount": 900000,
            "currency": "GBP"
        },
        "procurementMethod": "open",
        "procurementMethodDetails": "Open procedure",
        "mainProcurementCategory": "services",
        "submissionMethod": [
            "electronicSubmission"
        ],
        "submissionMethodDetails": "http://www.publictendersscotland.publiccontractsscotland.gov.uk/",
        "tenderPeriod": {
            "endDate": "2025-01-27T12:00:00Z"
        },
        "awardPeriod": {
            "startDate": "2025-01-27T12:00:00Z"
        },
        "documents": [
            {
                "id": "DEC520107",
                "documentType": "contractNotice",
                "title": "NHS GDPR Compliance Tool",
                "description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
                "url": "https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=DEC520107",
                "format": "text/html"
            },
            {
                "id": "AUG536763",
                "documentType": "awardNotice",
                "title": "NHS GDPR Compliance Tool",
                "description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
                "url": "https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=AUG536763",
                "format": "text/html"
            }
        ],
        "lots": [
            {
                "id": "1",
                "description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
                "status": "complete",
                "value": {
                    "amount": 900000,
                    "currency": "GBP"
                },
                "awardCriteria": {
                    "criteria": [
                        {
                            "type": "quality",
                            "name": "Functional Requirements",
                            "description": "40"
                        },
                        {
                            "type": "price",
                            "description": "30"
                        }
                    ]
                },
                "hasOptions": false,
                "submissionTerms": {
                    "variantPolicy": "notAllowed"
                },
                "contractPeriod": {
                    "durationInDays": 1080
                },
                "hasRenewal": true,
                "renewal": {
                    "description": "The Agreement includes two optional extension periods of 12 months each."
                }
            }
        ],
        "bidOpening": {
            "date": "2025-01-27T12:00:00Z"
        },
        "contractTerms": {
            "hasElectronicPayment": true,
            "hasElectronicOrdering": true,
            "electronicInvoicingPolicy": "allowed"
        },
        "coveredBy": [
            "GPA"
        ],
        "selectionCriteria": {
            "criteria": [
                {
                    "type": "economic",
                    "description": "SPD Q.4B.1.1: Bidders are required to provide statement of accounts or extracts relating to their business for the previous 3 years. Where any are risks identified by NSS as part of the due diligence carried out on the above information NSS may require Bidders to provide additional information to demonstrate financial standing. Additional information can include but not be limited to: - parent company accounts (if applicable) - deeds of guarantee - bankers statements and references - accountants' references - management accounts - financial projections, including cash flow forecasts - details and evidence of previous contracts, including contract values - capital availability. Bidders who cannot provide suitable evidence of a secure financial standing may be excluded from the procurement. Q.4B.5.1 and Q.4B.5.2: It is a requirement of this contract that bidders hold, or can commit to obtain prior to the commence of any subsequently awarded contract, the types and levels of insurance indicated below: Employers liability insurance: 5 000 000 GBP; Public liability insurance: 1 000 000 GBP; Professional indemnity insurance: 1 000 000 GBP"
                },
                {
                    "type": "technical",
                    "description": "4C.1.2 Please provide details of three relevant examples of services carried out during the last three years. 4.C.2 Bidders are required to confirm compliance with standards, such as ISO or equivalent, set by technical bodies, especially those responsible for quality control. Please provide examples such as the following: - Cyber Essentials - ISO 9001 - Quality Management Systems - ISO 27001 - Information Security Management - ISO 27017 - Code of practice for information security controls - ISO 27018 - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors - UK Government 14 Cloud Security Principles Please state the relevance of any such educational and professional qualifications. 4C.6: Bidders will be required to confirm that they and/or the service provider have relevant educational and professional qualifications such as the following: ISO27001 or equivalent ITIL qualifications [Helpdesk, etc] or equivalent other professional qualifications relevant to the Services outlined in the Contract Notice. And: 4C.6.1: Bidders will be required to confirm that they and/or the service provider's managerial staff have relevant educational and professional qualifications such as the following: ISO27001 or equivalent ITIL qualifications [Helpdesk, etc] or equivalent other professional qualifications relevant to the Services outlined in the Contract Notice. 4C.10: Bidders will be required to confirm whether they intend to subcontract and, if so, for what proportion of the contract"
                }
            ]
        },
        "submissionTerms": {
            "languages": [
                "en"
            ]
        },
        "classification": {
            "id": "72000000",
            "scheme": "CPV"
        },
        "reviewDetails": "Economic operators should approach the contracting authority in the first instance. However, the only formal remedy is to apply to the courts: An economic operator that suffers, or is at risk of suffering, loss or damage attributable to a breach of duty under the Public Contracts (Scotland) Regulations 2015 or the Procurement Reform (Scotland) Act 2014, may bring proceedings in the Sheriff Court or the Court of Session.",
        "hasRecurrence": false,
        "legalBasis": {
            "id": "32014L0024",
            "scheme": "CELEX"
        }
    },
    "language": "EN",
    "relatedProcesses": [
        {
            "id": "1",
            "relationship": [
                "planning"
            ],
            "scheme": "EU-OJ",
            "identifier": "2024/S 000-040058"
        }
    ],
    "description": "Estimated Value: The estimated value provided in sections II.1.7 and V.2.4 includes the initial 36 month contract period and the two optional extension periods of 12 months each. (SC Ref:807004)",
    "links": [
        {
            "rel": "canonical",
            "href": "https://api.publiccontractsscotland.gov.uk/v1/Notice?id=ocds-r6ebe6-0000784857"
        },
        {
            "rel": "canonical",
            "href": "https://api.publiccontractsscotland.gov.uk/v1/Notice?id=ocds-r6ebe6-0000784857"
        }
    ],
    "noticetype": "OJEU - F3 - Contract Award Notice",
    "awards": [
        {
            "id": "NP610424",
            "suppliers": [
                {
                    "id": "org-243",
                    "name": "AWTG LTD"
                }
            ],
            "relatedLots": [
                "1"
            ]
        }
    ],
    "contracts": [
        {
            "id": "NP610424",
            "awardID": "NP610424",
            "status": "active",
            "value": {
                "amount": 512000,
                "currency": "GBP"
            },
            "dateSigned": "2025-07-22T00:00:00Z"
        }
    ],
    "bids": {
        "statistics": [
            {
                "id": "586",
                "measure": "bids",
                "value": 4,
                "relatedLot": "1"
            },
            {
                "id": "587",
                "measure": "smeBids",
                "value": 3,
                "relatedLot": "1"
            },
            {
                "id": "588",
                "measure": "foreignBidsFromEU",
                "value": 0,
                "relatedLot": "1"
            },
            {
                "id": "589",
                "measure": "foreignBidsFromNonEU",
                "value": 4,
                "relatedLot": "1"
            },
            {
                "id": "590",
                "measure": "electronicBids",
                "value": 4,
                "relatedLot": "1"
            }
        ]
    }
}