Home Office Data Protection Compliance – Departmental Transformation Programme
Details
- Buyer
- Home Office
- Published
- 16 March 2020
- Submission
- 30 March 2020
- Source
- DigitalMarketplace
Tender description
Why the Work is Being Done This requirement is for a team to augment the new departmental Data Protection Compliance team whilst it recruits and develops people and processes. The supplier team is expected to act as both ‘thinkers’ and ‘doers’ i.e. assisting with the detailed design of services whilst delivering related products that will form the ongoing capability. In May 2018, the new General Data Protection Regulation (GDPR) Legislation was established, which required organisations to implement stronger measures to protect the personal data of individuals. A series of isolated activities were undertaken to address the key requirements of the legislation across various Home Office Departments. In response to this, the Data and Identity Directorate established the Data Protection Legislation Implementation Programme in January 2019 to co-ordinate departmental activities and help the Home Office to secure compliance with the new legislation. The programme aimed to assess the people, processes and technology required to support the Home Office’s compliance with this new Data Protection Legislation, whilst focussing on two key objectives: 1. Deliver initiatives which will provide long term sustainable compliance with Data Protection Legislation. 2. Increase the Department’s awareness of Data Protection Compliance and its importance. Problem to Be Solved The Data Protection Compliance team will be accountable for services that deliver or enable: • Personal data breach management • Information asset ownership & register • Governance & (evidence-based) risk management • Training, culture & awareness • Privacy by design & default High level designs and key products have already been produced, we require is to implement these, refine products at a working level, manage risks and opportunities, and provide a value-added service across the department in conjunction with the inter-related central functions e.g. Office of the Data Protection Officer (ODPO), Legal, Knowledge and Information Management, Cyber and Security. This requirement is for mix of business analysis, performance analysis and design with elements of delivery and communications management to not only augment this team, but to bring experience of operationalising data protection within a complex environment and this latter element is what we’re really looking for. The first six months of operation of the new team will be critical to prove their value to the Department. Delivery of defined pre-requisites will be required to help them prepare for full operation, also a stakeholder management approach to engage with the business and embed the new processes in day-to-day ways of working. Who Are the Users Users include, but are not limited to, the related central support functions e.g. KIMU, Security and Legal, Operations and Policy Groups, Data Protection Practitioners, including Information Asset Owners, and the Executive Committee. Data Protection is everyone’s responsibility and this programme is part of a combined departmental culture transformation to ensure staff put data first and effectively exploit their information, whilst being complaint with legislation and guidelines. It is also expected that the Supplier will offer skills transfer opportunities to the Data Protection Team and community, either via on-the-job training or by delivering one-off sessions (which can be delivered by alternative subject matter experts). Early Market Engagement N/A Work Already Done The programme has made good progress in building a positive stakeholder community, convening departmental activity to address its objectives, as well as mitigating risk and acting on assurance recommendations e.g. designed IAO training, initiated roll-out and developed a high-level IAR. Existing Team The Data and Identity Directorate was established in April 2017 to set the strategic direction in the use of data and identity as a centre of excellence and trusted partner across the sector. The Directorate has responsibilities spanning the Home Office sector, combines deep expertise and experience in data protection, identity and forensics policy, excellence in policy making and strategy and blends policy, technology, project management and sector experience to tackle challenging user problems and build a stronger Department. There is a related commercial arrangement in place, whereby a supplier is assessing our systems’ data retention compliance. Current Phase Not applicable Work Location We expect the supplier to be predominantly present at the 2 Marsham Street office and working from home/alternative HO sites/supplier sites is also supported. Working Arrangments Flexible working is supported but core hours are 10:00-16:00, Monday – Friday. We are seeking a small team to deliver these benefits and anticipate that it will be 4 or 5 individuals working part/full time. Suppliers may propose a team with an appropriately diverse mixture of skills, experience and specialisations to deliver the work, but it is essential to demonstrate experience of implementing data protection compliance and knowledge of the data protection legislation and standards. The Supplier shall ensure protection of HMG information assets and with all materials produced branded for the Home Office and readily accessible/retrievable. Security Clearance All staff must be SC security cleared (or be willing to be). We will provide laptops, but if supplier ICT is utilised then personal data held off-shore should be kept within the EEA or in compliance with the U.S. - EU “Safe Harbor” Framework or countries with positive Adequacy findings. Additional T&Cs Rate caps - rates over £1000 per day are excluded. SFIA 7 level resource is excluded. SFIA 6 is excluded for 'hands on' delivery roles. Skills & Experience Have knowledge and understanding of the data protection legislation Demonstrate experience of implementing data protection compliance regimes within an operational environment and within the last two years Proven experience of delivering successful cultural change across a large and complex business environment Demonstrate evidence of establishing information asset register(s) and developing information asset owner capabilities Demonstrate evidence of embedding risk management frameworks/processes, preferably in relation to data protection, within the last two years. Provide experience of successfully embedding governance Evidence agility and flexibility to respond to changing demand and priorities e.g. from customer needs or own analysis, within the last twelve months. Nice to Haves Demonstrate at least 2-years’ experience of working successfully in a central government environment Describe the challenges often encountered when implementing data protection compliance within a large business Access a range of additional resource and networks Detail a proven track record of working in a multi-stakeholder environment and of bringing organisations together to deliver a shared objective No. of Suppliers to Evaluate 3 Proposal Criteria Mobilisation, approach/methodology & how they meet the programme objectives (including estimated timeframes for the work). How they’ve identified risks and dependencies and offered approaches to manage them Team organisation, diversity, skills and experience Value for money Cultural Fit Criteria Work collaboratively with our organisation and other suppliers Being open, honest and transparent when making decisions including having a no-blame culture and encouraging people to learn from their mistakes Share knowledge, participate in skills transfer and can work with clients with low technical expertise Be flexible in adapting to meet changing priorities and business requirements. Payment Approach Capped time and materials Assessment Method Case study Work history Evaluation Weighting Technical competence 50% Cultural fit 15% Price 35% Questions from Suppliers No questions have been answered yet Budget range
Timeline
- Completed: Tender published16 March 2020Current notice
- Completed: Submission date30 March 2020
About the buyer
Home Office is a public sector buyer in United Kingdom publishing tenders and awards on Stotles. Explore their procurement activity and find more opportunities like this one.
Decision makers
Connect with the people behind this procurement.
| Contact name | Job title | Phone number | Work email |
|---|---|---|---|
| Head of Procurement | +44 •••• •••••• | ••••••••@home-office.gov | |
| Commercial Director | +44 •••• •••••• | ••••••••@home-office.gov | |
| Procurement Manager | +44 •••• •••••• | ••••••••@home-office.gov | |
| Category Lead | +44 •••• •••••• | ••••••••@home-office.gov | |
| Senior Buyer | +44 •••• •••••• | ••••••••@home-office.gov | |
| Contracts Manager | +44 •••• •••••• | ••••••••@home-office.gov |
Related topics
Topics related to Home Office Data Protection Compliance – Departmental Transformation Programme, ranked by notice volume.
- 407£6.4bn
- 5,684£136.4bn
- 3,366£105.8bn
- 11,175£1.0tn
- 26,969£1.7tn
- 4,088£269.5bn
- 4,068£249.4bn
Related buyers
Buyers similar to Home Office.
- 1,531£58.3bn
- 750£1.3bn
- 692£133.2bn
- 641£160.0bn
- 338£7.4bn
- 326£1.3bn
- 280£1.1bn
- 263£902.6m
- 228£550.1m
- 184£222.3bn
Win more public sector contracts
Track every UK and Ireland tender in one place — set up alerts, find decision-makers, and never miss an opportunity.
