Following receipt of legal advice from the Chief State Solicitor’s Office (CSSO) in July 2021, it was accepted that there was not, at that time, a sufficiently clear and robust lawful basis for the routine collection and processing by the Office of Government Procurement (OGP) of certain procurement payment data from Public Service Bodies where such data could contain personal data. That advice identified deficiencies in the legal clarity and foreseeability underpinning inter-public-body data sharing, particularly in respect of bodies outside central government.
Since that advice issued, the OGP and the Department have engaged with the CSSO and the Office of the Attorney General, and internally with the Department’s Data Protection Officer (DPO) and the Data Governance Unit in the Office of the Government Chief Information Officer (OGCIO) — the unit responsible for data policy and implementation of the Data Sharing and Governance Act 2019. This engagement has focused on addressing the issues identified and on placing the collection and use of procurement spend data on a more explicit and defensible legal footing, including consideration of the interaction between the GDPR, the Data Protection Act 2018, the Ministers and Secretaries (Amendment) Act 2011, and the Data Sharing and Governance Act 2019.
In December 2025, further correspondence confirmed that, subject to appropriate governance, transparency and data-sharing arrangements, procurement spend data could again be collected and processed on the basis of Article?6(1)(e) GDPR, with the act of data sharing between public bodies to be underpinned by formal Data Sharing Agreements in accordance with the Data Sharing and Governance Act 2019.
Work is now progressing to implement this approach. This includes the preparation of Data Sharing Agreements with relevant public bodies, the establishment of the necessary governance arrangements, and phased engagement to enable lawful, transparent and proportionate data sharing.