Data Sole
Legal

Procurement Policy

Policy Owner: Data Sole
Policy Area: Procurement, Supply Chain & Commercial Governance
Version: 1.1
Effective Date: 27 August 2026
Review Cycle: At least annually
Jurisdiction: United Kingdom

Contents

  1. 1. Purpose
  2. 2. Scope
  3. 3. Procurement Principles
  4. 4. Procurement Planning
  5. 5. Procurement Thresholds
  6. 6. Prohibition on Contract Splitting
  7. 7. Supplier Selection
  8. 8. Supplier Due Diligence
  9. 9. Technology and Cloud Procurement
  10. 10. Data Protection and Supplier Processing
  11. 11. Cybersecurity Requirements
  12. 12. Requests for Quotation and Tenders
  13. 13. Evaluation
  14. 14. Conflicts of Interest
  15. 15. Gifts and Hospitality
  16. 16. Anti-Bribery and Corruption
  17. 17. Purchase Approval
  18. 18. Purchase Orders
  19. 19. Contract Management
  20. 20. Supplier Performance
  21. 21. Sole-Source Procurement
  22. 22. Emergency Procurement
  23. 23. Public-Sector Procurement and Contracts
  24. 24. Sustainable and Responsible Procurement
  25. 25. Records and Audit Trail
  26. 26. Confidentiality
  27. 27. Procurement Fraud
  28. 28. Policy Exceptions
  29. 29. Compliance
  30. 30. Policy Review
  31. Appendix A: Definitions
  32. Appendix B: Roles and Responsibilities
  33. Appendix C: Due Diligence Tiers
  34. Appendix D: Worked Scenarios

1. Purpose

This Procurement Policy establishes the principles, responsibilities and controls governing the purchase of goods, services, software, cloud infrastructure, professional services and other resources by Data Sole.

The objectives of this Policy are to ensure that procurement activities are:

  • Commercially responsible and cost-effective;
  • Fair, transparent and appropriately competitive;
  • Secure and technically suitable;
  • Properly authorised;
  • Supported by appropriate due diligence;
  • Compliant with applicable laws and contractual obligations;
  • Consistent with Data Sole’s information-security and data-protection requirements; and
  • Properly documented and auditable.

As a provider of cloud infrastructure and hosting services, Data Sole’s own supply chain is a meaningful part of its overall security and resilience posture: a weakness introduced by a poorly vetted supplier can propagate into the services Data Sole provides to its own customers. This Policy therefore treats procurement not purely as a commercial or administrative function, but as a control point that supports the commitments made elsewhere in Data Sole’s policy framework, including its Data Retention Policy, Privacy Policy, Terms and Conditions of Use, and Copyright and Trademark Use Policy.

1.1 Relationship to Other Data Sole Policies

This Policy operates alongside, and should be read together with, several other Data Sole policies. Where a supplier will process personal data on Data Sole’s behalf, Section 10 of this Policy and the Data Sole Privacy Policy both apply, and the resulting Data Processing Agreement must be consistent with the retention principles set out in the Data Sole Data Retention Policy. Where a supplier relationship involves use of Data Sole’s brand assets — for example, a co-marketing arrangement with a reseller — the Data Sole Copyright and Trademark Use Policy governs that use in addition to the commercial terms agreed under this Policy. Where a supplier contract itself constitutes a Data Sole service offered onward to customers, the Data Sole Terms and Conditions of Use may also be relevant to how that supplier relationship is structured.

1.2 A Plain-Language Guide, Not a Substitute for Advice

This Policy is written so that a requesting manager without a procurement or legal background can understand what is expected of them at each stage of a purchase, from first identifying a need through to managing the resulting contract. It is not a substitute for specific legal, tax or regulatory advice on an individual transaction, and personnel should seek advice from Legal and Compliance, Finance or the Data Protection Lead, as appropriate, where a specific procurement raises a question this Policy does not clearly answer.

2. Scope

This Policy applies to employees, directors, contractors, consultants and other personnel authorised to purchase or procure on behalf of Data Sole.

It applies to procurement including:

  • Hardware and IT equipment;
  • Servers and networking equipment;
  • Data-centre and colocation services;
  • Cloud infrastructure;
  • Software and SaaS subscriptions;
  • Software licences;
  • Cybersecurity products and services;
  • Telecommunications;
  • Professional and consultancy services;
  • Outsourced and managed services;
  • Marketing services;
  • Office equipment and supplies;
  • Recruitment and staffing services;
  • Training and certification services;
  • Logistics and transportation;
  • Facilities and utilities; and
  • Other goods and services purchased for Data Sole operations.

This Policy applies regardless of the funding source for a purchase, including expenditure charged to a departmental budget, a project budget, or an individual’s expense account where that expenditure is procurement-related rather than ordinary personal expenses covered by a separate expenses policy. Where a purchase is ambiguous as to which policy applies — for example, a recurring individual software subscription used by a single employee — the Procurement Function can advise on the correct treatment.

3. Procurement Principles

Data Sole procurement shall be based on the following principles:

Value for Money — purchasing decisions should consider total value rather than price alone.

Competition — competitive quotations or tenders should be obtained where proportionate to the value and risk of the procurement.

Transparency — material purchasing decisions should be appropriately documented.

Accountability — expenditure must be approved by personnel with appropriate authority.

Security by Design — cybersecurity and information-security requirements should be considered before technology suppliers are appointed.

Privacy by Design — suppliers processing personal information must undergo appropriate privacy and data-protection assessment.

Fair Treatment — suppliers should be evaluated using relevant and proportionate criteria.

Conflict Management — personal interests must not improperly influence procurement decisions.

3.1 Applying the Principles Together

These principles are not a checklist to be applied mechanically and in isolation; they interact, and procurement decisions often involve balancing them against one another. For example, competition and value for money might point toward the cheapest available option, while security by design might justify paying a premium for a supplier with stronger, independently verified security controls where the procurement involves material access to Data Sole systems. Where principles pull in different directions, the individual approving the procurement should be able to explain, and where appropriate document, how the decision was reached, consistent with the transparency principle.

4. Procurement Planning

Before commencing significant procurement, the requesting department should establish:

  • The business requirement;
  • Technical specifications;
  • Required quantity and capacity;
  • Budget;
  • Delivery requirements;
  • Security requirements;
  • Data-protection implications;
  • Service levels;
  • Business-continuity requirements;
  • Contract duration;
  • Evaluation criteria; and
  • Required internal approvals.

Requirements should not be unnecessarily restrictive or designed to improperly favour a particular supplier. A specification that names a particular product or brand without an objective technical justification, or that includes requirements no genuine business need actually calls for, undermines the competition and fair-treatment principles in Section 3 and should be avoided unless there is a documented reason — for example, a genuine compatibility requirement with existing infrastructure, which may itself justify a sole-source approach under Section 21 rather than an artificially narrowed competitive process.

4.1 Early Engagement with Specialist Functions

For procurements involving material technology risk, personal data processing, or brand/marketing use of Data Sole intellectual property, the requesting department is encouraged to engage the relevant specialist function — Security Operations, the Data Protection Lead, or Legal and Compliance — during the planning stage rather than after a supplier has effectively been chosen. Early engagement allows security, privacy and contractual requirements to shape the specification and evaluation criteria, rather than being retrofitted onto a decision that has already been made in substance.

5. Procurement Thresholds

Unless a separate delegated-authority framework establishes different limits, Data Sole may apply the following internal procurement structure:

Contract / Purchase ValueMinimum Procedure
Up to £1,000Direct purchase with appropriate authorisation
£1,001–£10,000Normally obtain at least 2 quotations where reasonably practicable
£10,001–£50,000Normally obtain at least 3 competitive quotations
£50,001–£100,000Formal procurement assessment and documented evaluation
Above £100,000Formal tender/RFP process and senior management approval

Values should normally be calculated using the total anticipated contract value, rather than dividing a purchase into smaller transactions. For a multi-year contract or a subscription with automatic renewal, the relevant value is generally the total value over the initial committed term, not merely the first year or first invoice, so that the correct procedure is applied from the outset.

These thresholds are internal controls and may be amended by Data Sole management. Where a specific delegated-authority framework applies to a department, function or individual, that framework’s limits apply in place of the general thresholds above, provided it has been properly authorised and does not conflict with Section 17.

5.1 Currency and Foreign Suppliers

Where a purchase is denominated in a currency other than pounds sterling, the threshold band should be assessed using a reasonable exchange-rate estimate at the time of the procurement decision, rather than waiting for the final invoiced amount, so that the correct procedure is followed from the outset rather than determined retrospectively once actual costs are known.

6. Prohibition on Contract Splitting

Purchases must not be artificially divided into smaller transactions for the purpose of:

  • Avoiding an approval threshold;
  • Avoiding competitive procurement;
  • Avoiding financial controls; or
  • Circumventing this Policy.

Related purchases should be considered together when determining the appropriate procurement procedure. Purchases are generally “related” for this purpose where they serve the same underlying business requirement, are made from the same supplier within a short period, or are components of what would reasonably be understood as a single project or initiative, even if raised as separate purchase requests or invoices.

7. Supplier Selection

Suppliers may be evaluated according to factors including:

  • Price;
  • Total cost of ownership;
  • Technical capability;
  • Product or service quality;
  • Reliability;
  • Financial stability;
  • Cybersecurity;
  • Data protection;
  • Relevant certifications;
  • Service availability;
  • Support capability;
  • Scalability;
  • Business continuity;
  • Environmental considerations;
  • Insurance;
  • Reputation;
  • Previous performance;
  • Contractual terms; and
  • Delivery capability.

The lowest-priced supplier does not automatically have to be selected where another supplier represents better overall value or lower operational risk. Total cost of ownership is often a more meaningful comparison than headline price alone, since it captures factors such as implementation effort, ongoing support costs, the operational cost of switching suppliers later, and the cost of risk should a lower-quality or less secure supplier underperform or suffer an incident.

7.1 Documenting the Selection Decision

For procurements above the direct-purchase threshold, the reasoning behind a supplier selection should be recorded in a form proportionate to the value and risk of the procurement — for a small purchase, a brief note comparing the quotations obtained may suffice; for a formal tender, a full evaluation record against the documented criteria in Section 13 is expected. This record supports the transparency and accountability principles in Section 3 and forms part of the audit trail described in Section 25.

8. Supplier Due Diligence

Data Sole may conduct proportionate due diligence before appointing a supplier.

Depending on the nature and risk of the contract, checks may include:

  • Company registration;
  • Ownership information;
  • Financial standing;
  • Creditworthiness;
  • Insurance;
  • Professional qualifications;
  • References;
  • Regulatory status;
  • Cybersecurity controls;
  • Privacy practices;
  • Business-continuity arrangements;
  • Relevant certifications;
  • Litigation or material disputes;
  • Sanctions screening where appropriate;
  • Modern-slavery and supply-chain considerations; and
  • Conflicts of interest.

Higher-risk and strategically important suppliers should receive enhanced due diligence. Appendix C sets out an illustrative tiered approach, linking the depth of due diligence to the nature of the supplier relationship, to help requesting departments judge what level of scrutiny a given procurement is likely to warrant before engaging the Procurement Function.

8.1 Refreshing Due Diligence Over Time

Due diligence completed at the point a supplier is first appointed can become stale over the life of a long-running contract, particularly for enhanced and critical-tier suppliers under Appendix C, where a supplier’s ownership, financial position or security posture may change materially over several years. Material suppliers should have their due diligence refreshed periodically, and in any event at contract renewal, rather than relying indefinitely on checks completed at initial appointment.

9. Technology and Cloud Procurement

Technology suppliers require particular consideration because they may have access to Data Sole infrastructure, systems or information.

Before acquiring material cloud, SaaS, infrastructure or cybersecurity services, Data Sole should consider:

  • Hosting locations;
  • Data residency;
  • Encryption;
  • Identity and access management;
  • Authentication;
  • Logging and monitoring;
  • Vulnerability management;
  • Incident response;
  • Backup and disaster recovery;
  • Availability commitments;
  • Data portability;
  • Subprocessors;
  • Data deletion;
  • Exit procedures;
  • Vendor lock-in;
  • API availability;
  • Integration requirements; and
  • Security certifications where relevant.

Because Data Sole is itself a cloud infrastructure provider, its technology procurement decisions are held to a standard consistent with the commitments it makes to its own customers under its Terms and Conditions of Use and Privacy Policy. A technology supplier’s data-deletion and exit-procedure commitments, in particular, should be assessed against Data Sole’s own Data Retention Policy obligations, so that Data Sole can meet its own retention and deletion commitments even where the underlying data temporarily resides with a third-party technology supplier.

9.1 Vendor Lock-In and Portability

Vendor lock-in deserves specific attention because its consequences are often only felt well after the original procurement decision, when switching costs have already grown. Before committing to a technology supplier for a material or long-duration engagement, the requesting department should understand, and where possible document, how Data Sole’s own data and configurations could be extracted if the relationship needed to end — including the format in which data could be exported, whether proprietary formats or APIs would complicate a future migration, and whether the supplier’s standard contract terms impose any additional cost or delay on exit.

9.2 Layered Technology Stacks

Many technology procurements are not a single supplier relationship but a stack of dependencies: a SaaS product may itself run on a separate cloud infrastructure provider, and that provider may in turn depend on further subprocessors. Section 9 and Section 11 apply not only to the supplier Data Sole contracts with directly, but, so far as reasonably ascertainable, to the material dependencies further down that stack, since a failure or compromise at any layer can affect the service Data Sole ultimately receives.

10. Data Protection and Supplier Processing

Where a supplier processes personal data on behalf of Data Sole, appropriate contractual and organisational safeguards must be established.

Where required, this should include a Data Processing Agreement addressing matters such as:

  • Processing instructions;
  • Confidentiality;
  • Security measures;
  • Subprocessors;
  • International transfers;
  • Assistance with data-subject rights;
  • Personal-data breaches;
  • Retention and deletion; and
  • Audit or assurance rights.

This Section operates alongside Section 13 of the Data Sole Privacy Policy, which describes Data Sole’s general approach to third-party processors, and Section 7 of the Data Sole Data Retention Policy, which addresses third-party processors more specifically in the retention context. A Data Processing Agreement entered into under this Section should be consistent with both, in particular ensuring that any retention or deletion commitment the supplier makes is at least as protective as the standard Data Sole applies to its own systems.

10.1 Assessing the Need for a DPA

A Data Processing Agreement is required wherever a supplier will process personal data for which Data Sole is a controller, regardless of the size of the supplier or the perceived sensitivity of the data involved; the trigger is the nature of the processing, not the value of the contract. Where it is unclear whether a proposed supplier relationship involves processing of personal data — for example, a facilities contractor whose engineers may incidentally see visitor sign-in records — the Data Protection Lead should be consulted to confirm the correct treatment before the contract is signed.

11. Cybersecurity Requirements

Suppliers with material access to Data Sole systems or information may be required to demonstrate appropriate security controls.

Depending on risk, Data Sole may request evidence relating to recognised security frameworks or certifications, penetration testing, vulnerability management, access controls and incident-response capabilities.

Security requirements should be proportionate to the supplier’s access and the potential impact of compromise. A supplier with read-only access to non-sensitive marketing content warrants a lighter security review than a supplier with administrative access to production infrastructure or customer data, and Section 8 of Appendix C reflects this graduated approach.

12. Requests for Quotation and Tenders

For significant purchases, Data Sole may issue a:

  • Request for Information (RFI);
  • Request for Quotation (RFQ);
  • Request for Proposal (RFP); or
  • Invitation to Tender (ITT).

Procurement documents should clearly describe requirements, submission procedures, deadlines and evaluation criteria.

Material changes to requirements during a competitive process should be communicated fairly to affected bidders. Communicating a material change to only some bidders, or at materially different times, undermines the fair-treatment principle in Section 3 and may disadvantage bidders who do not receive the update in time to adjust their submission.

13. Evaluation

Formal procurements should use documented evaluation criteria.

Evaluation may consider weighted categories such as:

Evaluation AreaExample Weighting
Technical capability30%
Commercial/pricing25%
Security and compliance20%
Service and support10%
Resilience and scalability10%
Sustainability/social value5%

Weightings may be changed according to the nature of the procurement. For a procurement primarily concerned with commodity office supplies, commercial/pricing might reasonably carry a greater weight than security and compliance; for a procurement involving a new core infrastructure provider, the reverse is likely to be appropriate. Whatever weighting is used, it should be fixed before submissions are evaluated, rather than adjusted afterwards to favour a particular outcome.

14. Conflicts of Interest

Personnel involved in procurement must disclose actual, potential or perceived conflicts of interest.

A conflict may arise where an individual has a personal, financial, family or business relationship with a supplier or bidder.

Where appropriate, the affected individual may be excluded from evaluation or approval of the procurement. A disclosed conflict is not, by itself, prohibited or improper — what matters is that it is disclosed promptly and managed appropriately, typically by removing the conflicted individual from the decision-making process, so that the procurement decision is not, and does not appear to be, influenced by the personal interest.

15. Gifts and Hospitality

Employees and representatives must not accept gifts, payments, commissions, hospitality or other benefits intended to improperly influence a procurement decision.

Reasonable and legitimate business hospitality may be permitted where it:

  • Is proportionate;
  • Does not create an obligation;
  • Cannot reasonably be interpreted as a bribe; and
  • Complies with applicable Data Sole policies.

Cash or cash-equivalent inducements connected to procurement decisions are prohibited without exception, regardless of value.

16. Anti-Bribery and Corruption

Data Sole maintains zero tolerance for bribery and corruption.

No employee, contractor, supplier or representative may offer, request, provide or accept an improper financial or other advantage in connection with Data Sole procurement.

Suspected bribery, corruption, fraud or collusion must be reported through appropriate internal channels. This obligation applies regardless of the seniority of the individuals involved, the value of the procurement, or whether the suspected conduct appears to have benefited or disadvantaged Data Sole; the reporting obligation is triggered by reasonable suspicion, not by proof.

16.1 Third-Party Intermediaries

Where a supplier relationship involves an agent, intermediary or introducer acting on behalf of a prospective supplier, the same anti-bribery standard applies to payments or benefits flowing through that intermediary as would apply to a direct payment. Data Sole does not consider the use of an intermediary to reduce its own exposure or responsibility, and due diligence under Section 8 should extend to understanding the intermediary’s role and remuneration where one is involved in a material procurement.

17. Purchase Approval

No employee may commit Data Sole to expenditure without appropriate authority.

Approval should be obtained before:

  • Signing a contract;
  • Accepting supplier terms;
  • Issuing a purchase order;
  • Placing a material order;
  • Starting a paid subscription; or
  • Authorising significant additional expenditure.

Approval limits should correspond to the individual’s delegated financial authority. Clicking “accept” on an online supplier’s terms to start a paid subscription is a form of signing a contract for the purposes of this Section, and is subject to the same approval requirement as a formally executed written agreement, even where the process feels informal or is completed in a few clicks.

18. Purchase Orders

Where required by Data Sole procedures, a valid purchase order must be issued before goods or services are ordered.

Purchase orders should identify:

  • Supplier;
  • Goods or services;
  • Quantity;
  • Price;
  • Applicable taxes;
  • Delivery requirements;
  • Relevant project or department;
  • Contract reference; and
  • Authorised approver.

A purchase made without a required purchase order should be treated as a process exception under Section 28 and regularised as soon as reasonably practicable, rather than allowed to continue as an informal or undocumented arrangement.

19. Contract Management

Significant supplier contracts should be actively managed throughout their lifecycle.

Contract management may include:

  • Performance reviews;
  • SLA monitoring;
  • Security reviews;
  • Cost monitoring;
  • Usage reviews;
  • Invoice verification;
  • Compliance assessments;
  • Risk reviews;
  • Renewal management; and
  • Exit planning.

Exit planning deserves particular attention for suppliers providing technology, infrastructure or data-processing services: a contract should not be allowed to reach its end, or be terminated, without a clear understanding of how Data Sole information held by the supplier will be returned or securely deleted, consistent with the Data Sole Data Retention Policy, and how continuity of the underlying service or capability will be maintained during any transition.

19.1 Ownership of Ongoing Contract Management

Responsibility for day-to-day contract management typically sits with the requesting department or the relevant business owner, supported by the Procurement Function for commercial matters and Security Operations or the Data Protection Lead for technical and privacy matters where relevant. A significant contract should not be left unowned once signed; assigning a named contract owner at the point of award, consistent with Appendix B, helps ensure the activities in this Section actually happen rather than lapsing once the initial procurement process concludes.

20. Supplier Performance

Data Sole may maintain supplier performance records.

Material suppliers may be assessed against:

  • Quality;
  • Delivery;
  • Availability;
  • Responsiveness;
  • Security;
  • Compliance;
  • Cost;
  • SLA performance; and
  • Contractual obligations.

Repeated material underperformance may result in remediation requirements, reduced procurement opportunities, non-renewal or termination. Where a performance issue is identified, the supplier should generally be given a reasonable opportunity to remediate before more severe consequences are applied, except where the underperformance itself constitutes a security or compliance risk requiring more immediate action.

21. Sole-Source Procurement

Competitive procurement may not always be appropriate.

A direct or sole-source award may be justified where:

  • Only one supplier can reasonably meet the requirement;
  • Intellectual-property restrictions apply;
  • Compatibility with existing infrastructure is essential;
  • An emergency requires immediate procurement;
  • Changing supplier would create disproportionate technical risk;
  • Continuity of an existing project requires the incumbent supplier; or
  • Competition would otherwise be impracticable.

Material sole-source decisions should be documented and appropriately approved. The documentation should explain, in terms specific to the procurement, why the relevant justification applies — a generic statement that “only one supplier can meet the requirement” is less defensible on later audit than a specific explanation of the technical, contractual or operational basis for that conclusion.

22. Emergency Procurement

Normal procurement procedures may be accelerated where urgent action is necessary to:

  • Respond to a cybersecurity incident;
  • Restore critical services;
  • Prevent significant operational disruption;
  • Protect people or property;
  • Address an infrastructure failure; or
  • Respond to another genuine emergency.

Emergency procurement must still be appropriately documented and reviewed afterwards. A post-emergency review should confirm that the accelerated process was genuinely warranted, that appropriate approval was obtained even if compressed in timing, and that any due diligence or contractual protections deferred in the moment are completed retrospectively where the resulting supplier relationship continues beyond the immediate emergency.

23. Public-Sector Procurement and Contracts

Where Data Sole bids for, participates in or delivers public-sector contracts, it shall comply with the applicable procurement rules, tender requirements and contractual obligations.

Data Sole personnel must not attempt to obtain confidential competitor information, improperly influence public officials or circumvent a contracting authority’s procurement procedures.

All representations made within public-sector tenders must be accurate and capable of appropriate substantiation. This includes representations about Data Sole’s technical capabilities, security certifications, past performance and pricing; a representation that cannot be substantiated if challenged should not be included in a public-sector submission, regardless of the competitive advantage it might appear to offer.

23.1 Framework Agreements

Where Data Sole is appointed to a public-sector framework agreement or dynamic purchasing system, the specific call-off procedures, pricing schedules and service commitments set out in that framework take precedence over Data Sole’s general commercial terms for the scope of business conducted under the framework, and personnel involved in framework-related bids should familiarise themselves with the specific framework rules in addition to this Policy.

24. Sustainable and Responsible Procurement

Where proportionate, Data Sole may consider environmental and social factors when evaluating suppliers, including:

  • Energy efficiency;
  • Carbon impact;
  • Equipment lifecycle;
  • Electronic-waste management;
  • Responsible sourcing;
  • Labour standards;
  • Modern-slavery risks;
  • Supply-chain transparency; and
  • Environmental certifications.

Such considerations should be balanced against technical, commercial and operational requirements. For data-centre, hardware and hosting-related procurement in particular, energy efficiency and equipment lifecycle considerations are often directly relevant to Data Sole’s own operating costs and environmental commitments, and not merely a matter of supplier reputation.

25. Records and Audit Trail

Data Sole should maintain appropriate procurement records, which may include:

  • Business requirements;
  • Quotations;
  • Tender documents;
  • Supplier submissions;
  • Evaluation records;
  • Due-diligence results;
  • Approvals;
  • Purchase orders;
  • Contracts;
  • Amendments;
  • Invoices;
  • Performance reviews; and
  • Sole-source justifications.

Records shall be retained according to Data Sole’s applicable Data Retention Policy. Contracts and commercial agreements, and related invoices, accounting and tax records, are generally retained for the contract duration plus up to six years, consistent with the standard retention schedule set out in that Policy; procurement evaluation records for an unsuccessful tender are generally retained for a shorter period, reflecting their more limited ongoing relevance once a contract has been awarded.

26. Confidentiality

Supplier quotations, commercial proposals, pricing information, technical submissions and procurement evaluations should be treated appropriately according to their confidentiality.

Confidential supplier information must not be improperly disclosed to competitors or unauthorised parties. This obligation continues to apply after a procurement process concludes, including in relation to unsuccessful bidders’ submissions, which should be handled with the same care as those of the successful bidder.

27. Procurement Fraud

Prohibited conduct includes:

  • Falsifying quotations;
  • Creating fictitious suppliers;
  • Manipulating tenders;
  • Bid rigging or collusion;
  • Receiving secret commissions;
  • Inflating invoices;
  • Approving personal purchases as business expenses;
  • Concealing conflicts of interest;
  • Contract splitting to bypass approval limits; and
  • Altering procurement records to conceal misconduct.

Suspected procurement fraud should be investigated and escalated appropriately. Personnel who report a genuine, good-faith suspicion of procurement fraud should not suffer any detriment for having done so, even where an investigation subsequently finds no wrongdoing occurred.

28. Policy Exceptions

Exceptions to this Policy require a legitimate commercial, operational, technical or emergency justification.

Material exceptions should be documented and approved at the appropriate management level. An exception granted for one procurement does not set a precedent for future, similar procurements; each exception request should be assessed on its own facts.

29. Compliance

Failure to comply with this Policy may result in:

  • Withdrawal of purchasing authority;
  • Internal investigation;
  • Disciplinary action;
  • Supplier suspension or termination;
  • Contract termination; or
  • Referral to appropriate authorities where unlawful conduct is suspected.

The appropriate response will depend on the nature, seriousness and repetition of the non-compliance, consistent with the proportionate approach Data Sole applies to enforcement across its policy framework generally.

30. Policy Review

This Procurement Policy shall be reviewed at least annually and following significant changes to Data Sole’s operations, procurement requirements, regulatory environment or corporate structure.

Where a review results in a change to the thresholds in Section 5, the weightings in Section 13, or the due-diligence tiers in Appendix C, the updated figures supersede those shown in the previous edition of this Policy from the effective date of the revised version.

© 2026 Data Sole. All rights reserved.

Appendix A: Definitions

  • “Contract Splitting” means artificially dividing a single business requirement into smaller purchases to avoid an approval threshold or competitive procurement requirement, prohibited under Section 6.
  • “Data Processing Agreement” or “DPA” means the contractual document governing a supplier’s processing of personal data on Data Sole’s behalf, as described in Section 10.
  • “Delegated Authority” means the level of expenditure an individual is permitted to approve without further escalation, as set by Data Sole’s internal financial-authority framework.
  • “Due Diligence” means the checks Data Sole conducts on a prospective supplier before appointment, proportionate to the risk of the relationship, as described in Section 8 and Appendix C.
  • “Sole-Source Procurement” means the award of a contract to a single supplier without a competitive process, justified under Section 21.
  • “Total Cost of Ownership” means the full cost of a good or service over its useful life, including implementation, support, switching and risk costs, not merely the purchase price.

Appendix B: Roles and Responsibilities

The table below summarises indicative responsibilities for procurement activity across Data Sole. It supplements, and does not replace, the specific approval limits set by Data Sole’s delegated-authority framework.

RoleResponsibility
Requesting Manager/Budget HolderDefines the business requirement, confirms budget availability, and approves expenditure within their delegated authority.
Procurement FunctionRuns competitive processes above the direct-purchase threshold, coordinates due diligence, and maintains the supplier record and audit trail.
Data Protection LeadReviews Data Processing Agreements and privacy implications for suppliers processing personal data, consistent with the Data Sole Privacy Policy.
Security Operations / ITAssesses technical and cybersecurity suitability of technology and cloud suppliers, and reviews security evidence under Section 11.
Legal & ComplianceReviews material contracts, advises on sole-source justifications, sanctions screening and anti-bribery matters.
FinanceVerifies budget, processes purchase orders and invoices, and monitors spend against approved thresholds.
Senior ManagementApproves procurements above the formal-tender threshold and material exceptions to this Policy.
All Personnel Involved in ProcurementDisclose conflicts of interest, avoid contract splitting, and report suspected fraud or bribery.

Appendix C: Due Diligence Tiers

The table below provides an illustrative, non-exhaustive guide to the depth of due diligence typically appropriate for a given category of supplier relationship, as referenced in Section 8. The Procurement Function or Security Operations can advise where the correct tier for a specific procurement is unclear.

TierTypical ChecksTypical Suppliers
LowCompany registration check; basic reference where relevantMinor, low-value, low-access suppliers
StandardCompany registration, financial standing, insurance, references, relevant certificationsMost operational suppliers with limited system access
EnhancedAll standard checks plus cybersecurity controls review, privacy practices assessment, sanctions screening, business-continuity review, litigation/dispute checkSuppliers with material access to Data Sole systems, information or customer-facing infrastructure
Critical/StrategicAll enhanced checks plus on-site or documented audit, executive-level relationship review, contingency and exit planning, board-level visibility where appropriateSuppliers whose failure would materially disrupt Data Sole's services or security posture

Appendix D: Worked Scenarios

Scenario 1: A New Cloud Storage Sub-Supplier

A department wishes to engage a third-party cloud storage provider to support a new feature that will store customer files. Because the provider will process personal data on Data Sole’s behalf, Section 10 requires a Data Processing Agreement, and because the provider will have material access to customer information, Section 9 and Section 11 require a technology and cybersecurity assessment before appointment, consistent with the Enhanced tier in Appendix C. The Data Protection Lead and Security Operations are engaged during planning, consistent with Section 4.1, rather than after a preferred supplier has already been selected.

Scenario 2: Recurring Small Software Subscriptions

Several employees independently begin using the same low-cost SaaS tool, each starting a separate subscription under the £1,000 direct-purchase threshold. Once the department realises multiple subscriptions to the same tool are running in parallel, Section 6 requires the related purchases to be considered together: their combined value may exceed the direct-purchase threshold, and the department should consolidate onto a single, properly authorised subscription rather than continuing several small, individually authorised ones.

Scenario 3: An Urgent Security Incident Response Contract

Following a security incident, Data Sole urgently engages an incident-response specialist to contain the issue, without completing the standard competitive process described in Section 5. This is permitted under Section 22 as emergency procurement, provided the engagement is properly authorised even on a compressed timeline, and is documented and reviewed afterwards, including retrospective completion of any due diligence not feasible to complete before the engagement began.

Scenario 4: A Gift from a Prospective Supplier

During a competitive tender process, a bidder offers a member of the evaluation panel tickets to a major sporting event. Section 15 requires the panel member to decline the gift and to disclose the offer, since accepting hospitality of this kind from an active bidder during an ongoing evaluation cannot reasonably be treated as proportionate, unconnected to the procurement decision, or free of any risk of creating an obligation.

Scenario 5: A Long-Standing Sole-Source Relationship

Data Sole has used the same specialist hardware-maintenance supplier for several years without a competitive re-tender, on the basis that the supplier holds proprietary diagnostic tools compatible only with Data Sole’s existing equipment. Under Section 21, this may be a justified sole-source relationship, but Section 21 also requires the justification to be documented and periodically revisited — for example, at contract renewal — to confirm the underlying compatibility constraint still holds and that continuing without competition remains the appropriate approach.

Scenario 6: A Supplier Contract Ending Without an Exit Plan

A three-year hosting contract with a secondary infrastructure supplier approaches its end, and the requesting department realises only weeks beforehand that no exit plan exists for migrating the data held with that supplier. This is the situation Section 19 and its exit-planning guidance are designed to prevent: contract management for a technology or data-processing supplier should include exit planning well in advance of the contract’s natural end, so that data can be retrieved and securely handled consistently with the Data Sole Data Retention Policy without a last-minute scramble that itself creates operational and security risk.

Scenario 7: An Unsuccessful Bidder's Confidential Pricing

Following a competitive tender, an employee involved in the evaluation is later approached informally by the winning bidder, who asks how their pricing compared with the unsuccessful bidders. Section 26 requires that confidential pricing and submission details of unsuccessful bidders not be disclosed to the winning bidder or to any other third party; the employee should decline to share those specifics, consistent with the confidentiality obligation that continues to apply after the procurement process has concluded.

Contact

Skydatasol Holdings Plc., 321-323 High Road, Chadwell Heath, London RM6 6AX. Email cloud@skydatasol.com.