Guidance

Debarment Review Service Privacy Notice

Published 12 February 2025

Purpose

The Debarment Review Service (DRS) will carry out effective and comprehensive debarment investigations (as defined in the Procurement Act 2023). Part of the investigation involves determining if an exclusion ground applies and whether the circumstances giving rise to the application of the exclusion ground are continuing or likely to occur again.

To carry out the investigation and determination, the Debarment Review Service (DRS) must collect information associated with the referred Supplier (full name, contact details, criminal/civil data etc.) and any associated person(s), to corroborate that an exclusion ground applies and use this data to ensure that appropriate recommendations are made to the Minister of the Crown in relation to the findings of an investigation.

This includes discussing the data with the subject of the investigation and other stakeholders relevant to the investigation. As per section 61(3) of the Procurement Act, the conclusions of, and the Minister of the Crown’s decision in relation to a debarment investigation, will be published in a report. This report will be made public as will the Debarment List itself.

Publication of the report will be subject to safeguarding national security or preventing the publication of sensitive commercial information where there is an overriding public interest in it being withheld from publication or other disclosure.

Data will also be held and/or disclosed to deal with statutory legal challenges and judicial review challenges to debarment decisions. Data could also be disclosed when required to do so by law, and for the purposes of litigation or prosecution.

The data

We will process the following personal data:

  • name of the company/organisation and/or the appropriate people that are subject to the exclusion ground
  • email address
  • address
  • telephone number
  • job title
  • organisation
  • dates and location associated with the exclusion ground
  • description of the event giving rise to the exclusion ground
  • data relating to criminal convictions, offences or national security as listed in Schedule 6 and Schedule 7 of the Procurement Act 2023
  • ongoing monitoring and/or investigation into the supplier in relation to the exclusion ground
  • date in which the circumstances which led to the exclusion ground ended
  • full name of the referrer
  • email address of the referrer
  • telephone number of the referrer 
  • organisation of the referrer (or organisation they are submitting the referral on behalf of if different to their own

The legal basis for processing your personal data is:

  • The legal basis for processing your personal data is it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. In this case the Debarment Review Service (DRS), is required to carry out effective and comprehensive debarment investigations (as defined in the Procurement Act 2023).

If criminal convictions personal data is processed:

As part of the investigation process, the Debarment Review Service (DRS) will be processing criminal conviction and offences data.

The processing by us of personal data relating to criminal convictions and offences or related security measures is not carried out under official authority, but is authorised because:

  • processing is necessary for reasons of substantial public interest for the exercise of a function of the Crown, a Minister of the Crown, or a government department; the exercise of a function conferred on a person by an enactment; or the exercise of a function of either House of Parliament. 

  • processing is necessary for the establishment, exercise or defence of legal claims

Recipients

Data may be shared with other government agencies and associated bodies to assist the Debarment Review Service (DRS) exercise its functions under the Procurement Act 2023, in relation to considering a supplier for addition to the debarment list.

Those agencies and associated bodies include, but is not limited to:

  • The Serious Fraud Office
  • Foreign, Commonwealth & Development Office
  • National Crime Agency
  • Competition & Markets Authority
  • Association of Chief Police Officer, Criminal Records Office
  • Health & Safety Executive
  • Modern Slavery and Organised Immigration Crime Unit
  • Environment Agency
  • Gangmasters Labour Abuse Authority

As your personal data will be stored on our IT infrastructure it may be shared with our data processors who provide email, document management and storage services.

Your data will also be shared with the third party service Mendix, which provides an information management service to us.

Where personal data have not been obtained from you

Personal data may be provided by other government agencies and associated bodies to assist the Debarment Review Service (DRS) exercise its functions under the Procurement Act 2023, in relation to considering a supplier for addition to the debarment list.

Those agencies and associated bodies include:

  • The Serious Fraud Office
  • Foreign, Commonwealth & Development Office
  • National Crime Agency
  • Competition & Markets Authority
  • Association of Chief Police Officer, Criminal Records Office
  • Health & Safety Executive
  • Modern Slavery and Organised Immigration Crime Unit
  • Environment Agency
  • Gangmasters Labour Abuse Authority.

If information is obtained from an organisation not listed here, we will be able to identify and confirm the name of the organisation.

Retention

Your personal data will be kept by us for:

  • Five years from the date of the investigation being concluded, if no challenge or appeal is made.
  • If a challenge or appeal is made all personal data will be retained for a period of five years from the date the challenge or appeal has been finalised.

Your rights

You have the right to request information about how your personal data are processed, and to request a copy of that personal data. 

You have the right to request that any inaccuracies in your personal data are rectified without delay. 

You have the right to request that any incomplete personal data are completed, including by means of a supplementary statement. 

You have the right to request that your personal data are erased if there is no longer a justification for them to be processed. 

You have the right in certain circumstances (for example, where accuracy is contested) to request that the processing of your personal data is restricted. 

You have the right to object to the processing of your personal data where it is processed for direct marketing purposes. 

You have the right to object to the processing of your personal data.

You have the right to request a copy of any personal data you have provided, and for this to be provided in a structured, commonly used and machine-readable format.

International transfers

As your personal data is stored on our Corporate IT infrastructure, and shared with our data processors, it may be transferred and stored securely outside the UK. Where that is the case it will be subject to equivalent legal protection through an adequacy decision, reliance on Standard Contractual Clauses, or reliance on a UK International Data Transfer Agreement.

Recipients

As your data will be shared with third party service Mendix, which provides an information management service to us, it may be stored securely outside the UK. Where that is the case it will be subject to equivalent legal protection through:

  • Standard Contractual Clauses and/or a UK International Data Transfer Agreement

Complaints

If you consider that your personal data has been misused or mishandled, you may make a complaint to the Information Commissioner, who is an independent regulator. The Information Commissioner can be contacted at:

Information Commissioner’s Office 
Wycliffe House 
Water Lane 
Wilmslow 
Cheshire 
SK9 5AF 

Telephone: 0303 123 1113 

icocasework@ico.org.uk

Any complaint to the Information Commissioner is without prejudice to your right to seek redress through the courts.

Contact Information

The data controller for your personal data is the Cabinet Office. The contact details for the data controller are: 

Cabinet Office 
70 Whitehall 
London 
SW1A 2AS 

Telephone: 0207 276 1234

Public Enquiries: Online Contact Form 

The contact details for the data controller’s Data Protection Officer are: dpo@cabinetoffice.gov.uk

The Data Protection Officer provides independent advice and monitoring of Cabinet Office’s use of personal information