Notice Information
Notice Title
NHS GDPR Compliance Tool
Notice Description
Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.
Lot Information
Lot 1
Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.
Renewal: The Agreement includes two optional extension periods of 12 months each.
Notice Details
Publication & Lifecycle
- Open Contracting ID
- ocds-r6ebe6-0000784857
- Publication Source
- Public Contracts Scotland
- Latest Notice
- https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=AUG536763
- Current Stage
- Award
- All Stages
- Tender, Award
Procurement Classification
- Notice Type
- OJEU - F3 - Contract Award Notice
- Procurement Type
- Standard
- Procurement Category
- Services
- Procurement Method
- Open
- Procurement Method Details
- Open procedure
- Tender Suitability
- Not specified
- Awardee Scale
- SME
Common Procurement Vocabulary (CPV)
- CPV Divisions
72 - IT services: consulting, software development, Internet and support
-
- CPV Codes
72000000 - IT services: consulting, software development, Internet and support
Notice Value(s)
- Tender Value
- £900,000 £500K-£1M
- Lots Value
- £900,000 £500K-£1M
- Awards Value
- Not specified
- Contracts Value
- £512,000 £500K-£1M
Notice Dates
- Publication Date
- 11 Aug 20256 months ago
- Submission Deadline
- 27 Jan 2025Expired
- Future Notice Date
- Not specified
- Award Date
- 22 Jul 20257 months ago
- Contract Period
- Not specified - Not specified
- Recurrence
- Not specified
Notice Status
- Tender Status
- Complete
- Lots Status
- Complete
- Awards Status
- Not Specified
- Contracts Status
- Active
Buyer & Supplier
Contracting Authority (Buyer)
- Main Buyer
- THE COMMON SERVICES AGENCY (MORE COMMONLY KNOWN AS NHS NATIONAL SERVICES SCOTLAND) (NSS)
- Contact Name
- Ross Glen
- Contact Email
- michael.walker3@nhs.scot, ross.glen3@nhs.scot
- Contact Phone
- +44 1312756000
Buyer Location
- Locality
- EDINBURGH
- Postcode
- EH12 9EB
- Post Town
- Edinburgh
- Country
- Scotland
-
- Major Region (ITL 1)
- TLM Scotland
- Basic Region (ITL 2)
- TLM1 East Central Scotland
- Small Region (ITL 3)
- TLM13 City of Edinburgh
- Delivery Location
- TLM Scotland
-
- Local Authority
- City of Edinburgh
- Electoral Ward
- Drum Brae/Gyle
- Westminster Constituency
- Edinburgh South West
Further Information
Notice Documents
-
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=DEC520107
NHS GDPR Compliance Tool - Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing. -
https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=AUG536763
NHS GDPR Compliance Tool - Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.
Open Contracting Data Standard (OCDS)
View full OCDS Record for this contracting process
The Open Contracting Data Standard (OCDS) is a framework designed to increase transparency and access to public procurement data in the public sector. It is widely used by governments and organisations worldwide to report on procurement processes and contracts.
{
"tag": [
"compiled"
],
"id": "ocds-r6ebe6-0000784857-2025-08-11T00:00:00Z",
"date": "2025-08-11T00:00:00Z",
"ocid": "ocds-r6ebe6-0000784857",
"initiationType": "tender",
"parties": [
{
"id": "org-70",
"name": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)",
"identifier": {
"legalName": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)"
},
"address": {
"streetAddress": "1 South Gyle Crescent",
"locality": "Edinburgh",
"region": "UKM",
"postalCode": "EH12 9EB"
},
"contactPoint": {
"email": "michael.walker3@nhs.scot",
"telephone": "+44 1312756000",
"url": "http://www.publictendersscotland.publiccontractsscotland.gov.uk/"
},
"roles": [
"buyer",
"centralPurchasingBody"
],
"details": {
"classifications": [
{
"id": "Body governed by public law",
"scheme": "TED_CA_TYPE"
},
{
"id": "07",
"description": "Health",
"scheme": "COFOG"
}
],
"url": "http://www.nss.nhs.scot/browse/procurement-and-logistics"
}
},
{
"id": "org-71",
"name": "Sheriff Court House",
"identifier": {
"legalName": "Sheriff Court House"
},
"address": {
"locality": "Edinburgh",
"postalCode": "EH1 1LB"
},
"contactPoint": {
"url": "http://"
},
"roles": [
"reviewBody"
]
},
{
"id": "org-3",
"name": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)",
"identifier": {
"legalName": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)"
},
"address": {
"streetAddress": "1 South Gyle Crescent",
"locality": "Edinburgh",
"region": "UKM",
"postalCode": "EH12 9EB"
},
"contactPoint": {
"name": "Ross Glen",
"email": "ross.glen3@nhs.scot",
"url": "http://"
},
"roles": [
"buyer",
"centralPurchasingBody"
],
"details": {
"classifications": [
{
"id": "Body governed by public law",
"scheme": "TED_CA_TYPE"
},
{
"id": "07",
"description": "Health",
"scheme": "COFOG"
}
],
"url": "http://www.nss.nhs.scot/browse/procurement-and-logistics"
}
},
{
"id": "org-243",
"name": "AWTG LTD",
"identifier": {
"legalName": "AWTG LTD"
},
"address": {
"streetAddress": "8 Canham Mews, Canham Road",
"locality": "London",
"region": "UKI",
"postalCode": "W37SR"
},
"contactPoint": {
"telephone": "+44 02035155151"
},
"roles": [
"supplier"
],
"details": {
"scale": "sme",
"url": "http://"
}
},
{
"id": "org-11",
"name": "Sheriff Court House",
"identifier": {
"legalName": "Sheriff Court House"
},
"address": {
"streetAddress": "27 Chambers Street",
"locality": "Edinburgh",
"postalCode": "EH1 1LB"
},
"contactPoint": {
"telephone": "+44 1312252525",
"url": "https://scotcourts.gov.uk/the-courts/sheriff-court/about-sheriff-courts"
},
"roles": [
"reviewBody"
]
}
],
"buyer": {
"name": "The Common Services Agency (more commonly known as NHS National Services Scotland) (NSS)",
"id": "org-3"
},
"tender": {
"id": "ocds-r6ebe6-0000784857",
"title": "NHS GDPR Compliance Tool",
"description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
"status": "complete",
"items": [
{
"id": "1",
"deliveryLocation": {
"description": "Scotland"
},
"deliveryAddresses": [
{
"region": "UKM"
},
{
"region": "UKM"
}
],
"relatedLot": "1"
}
],
"value": {
"amount": 900000,
"currency": "GBP"
},
"procurementMethod": "open",
"procurementMethodDetails": "Open procedure",
"mainProcurementCategory": "services",
"submissionMethod": [
"electronicSubmission"
],
"submissionMethodDetails": "http://www.publictendersscotland.publiccontractsscotland.gov.uk/",
"tenderPeriod": {
"endDate": "2025-01-27T12:00:00Z"
},
"awardPeriod": {
"startDate": "2025-01-27T12:00:00Z"
},
"documents": [
{
"id": "DEC520107",
"documentType": "contractNotice",
"title": "NHS GDPR Compliance Tool",
"description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
"url": "https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=DEC520107",
"format": "text/html"
},
{
"id": "AUG536763",
"documentType": "awardNotice",
"title": "NHS GDPR Compliance Tool",
"description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
"url": "https://www.publiccontractsscotland.gov.uk/search/show/search_view.aspx?ID=AUG536763",
"format": "text/html"
}
],
"lots": [
{
"id": "1",
"description": "Procurement of a GDPR Compliance Tool to support NHS Scotland Information Governance with the delivery of their core compliance activities which include completion and review of Data Protection Impact Assessments, maintenance of Information Asset Registers and Records of Processing.",
"status": "complete",
"value": {
"amount": 900000,
"currency": "GBP"
},
"awardCriteria": {
"criteria": [
{
"type": "quality",
"name": "Functional Requirements",
"description": "40"
},
{
"type": "price",
"description": "30"
}
]
},
"hasOptions": false,
"submissionTerms": {
"variantPolicy": "notAllowed"
},
"contractPeriod": {
"durationInDays": 1080
},
"hasRenewal": true,
"renewal": {
"description": "The Agreement includes two optional extension periods of 12 months each."
}
}
],
"bidOpening": {
"date": "2025-01-27T12:00:00Z"
},
"contractTerms": {
"hasElectronicPayment": true,
"hasElectronicOrdering": true,
"electronicInvoicingPolicy": "allowed"
},
"coveredBy": [
"GPA"
],
"selectionCriteria": {
"criteria": [
{
"type": "economic",
"description": "SPD Q.4B.1.1: Bidders are required to provide statement of accounts or extracts relating to their business for the previous 3 years. Where any are risks identified by NSS as part of the due diligence carried out on the above information NSS may require Bidders to provide additional information to demonstrate financial standing. Additional information can include but not be limited to: - parent company accounts (if applicable) - deeds of guarantee - bankers statements and references - accountants' references - management accounts - financial projections, including cash flow forecasts - details and evidence of previous contracts, including contract values - capital availability. Bidders who cannot provide suitable evidence of a secure financial standing may be excluded from the procurement. Q.4B.5.1 and Q.4B.5.2: It is a requirement of this contract that bidders hold, or can commit to obtain prior to the commence of any subsequently awarded contract, the types and levels of insurance indicated below: Employers liability insurance: 5 000 000 GBP; Public liability insurance: 1 000 000 GBP; Professional indemnity insurance: 1 000 000 GBP"
},
{
"type": "technical",
"description": "4C.1.2 Please provide details of three relevant examples of services carried out during the last three years. 4.C.2 Bidders are required to confirm compliance with standards, such as ISO or equivalent, set by technical bodies, especially those responsible for quality control. Please provide examples such as the following: - Cyber Essentials - ISO 9001 - Quality Management Systems - ISO 27001 - Information Security Management - ISO 27017 - Code of practice for information security controls - ISO 27018 - Code of practice for protection of personally identifiable information (PII) in public clouds acting as PII processors - UK Government 14 Cloud Security Principles Please state the relevance of any such educational and professional qualifications. 4C.6: Bidders will be required to confirm that they and/or the service provider have relevant educational and professional qualifications such as the following: ISO27001 or equivalent ITIL qualifications [Helpdesk, etc] or equivalent other professional qualifications relevant to the Services outlined in the Contract Notice. And: 4C.6.1: Bidders will be required to confirm that they and/or the service provider's managerial staff have relevant educational and professional qualifications such as the following: ISO27001 or equivalent ITIL qualifications [Helpdesk, etc] or equivalent other professional qualifications relevant to the Services outlined in the Contract Notice. 4C.10: Bidders will be required to confirm whether they intend to subcontract and, if so, for what proportion of the contract"
}
]
},
"submissionTerms": {
"languages": [
"en"
]
},
"classification": {
"id": "72000000",
"scheme": "CPV"
},
"reviewDetails": "Economic operators should approach the contracting authority in the first instance. However, the only formal remedy is to apply to the courts: An economic operator that suffers, or is at risk of suffering, loss or damage attributable to a breach of duty under the Public Contracts (Scotland) Regulations 2015 or the Procurement Reform (Scotland) Act 2014, may bring proceedings in the Sheriff Court or the Court of Session.",
"hasRecurrence": false,
"legalBasis": {
"id": "32014L0024",
"scheme": "CELEX"
}
},
"language": "EN",
"relatedProcesses": [
{
"id": "1",
"relationship": [
"planning"
],
"scheme": "EU-OJ",
"identifier": "2024/S 000-040058"
}
],
"description": "Estimated Value: The estimated value provided in sections II.1.7 and V.2.4 includes the initial 36 month contract period and the two optional extension periods of 12 months each. (SC Ref:807004)",
"links": [
{
"rel": "canonical",
"href": "https://api.publiccontractsscotland.gov.uk/v1/Notice?id=ocds-r6ebe6-0000784857"
},
{
"rel": "canonical",
"href": "https://api.publiccontractsscotland.gov.uk/v1/Notice?id=ocds-r6ebe6-0000784857"
}
],
"noticetype": "OJEU - F3 - Contract Award Notice",
"awards": [
{
"id": "NP610424",
"suppliers": [
{
"id": "org-243",
"name": "AWTG LTD"
}
],
"relatedLots": [
"1"
]
}
],
"contracts": [
{
"id": "NP610424",
"awardID": "NP610424",
"status": "active",
"value": {
"amount": 512000,
"currency": "GBP"
},
"dateSigned": "2025-07-22T00:00:00Z"
}
],
"bids": {
"statistics": [
{
"id": "586",
"measure": "bids",
"value": 4,
"relatedLot": "1"
},
{
"id": "587",
"measure": "smeBids",
"value": 3,
"relatedLot": "1"
},
{
"id": "588",
"measure": "foreignBidsFromEU",
"value": 0,
"relatedLot": "1"
},
{
"id": "589",
"measure": "foreignBidsFromNonEU",
"value": 4,
"relatedLot": "1"
},
{
"id": "590",
"measure": "electronicBids",
"value": 4,
"relatedLot": "1"
}
]
}
}