Bid exclusion risks in Public Procurement

Published  . 0 views
↓ Download
Bid exclusion risks in Public Procurement
1 / 1
Bid exclusion risks in Public Procurement - slide 1 of 35 Bid exclusion risks in Public Procurement - slide 2 of 35 Bid exclusion risks in Public Procurement - slide 3 of 35 Bid exclusion risks in Public Procurement - slide 4 of 35 Bid exclusion risks in Public Procurement - slide 5 of 35 Bid exclusion risks in Public Procurement - slide 6 of 35 Bid exclusion risks in Public Procurement - slide 7 of 35 Bid exclusion risks in Public Procurement - slide 8 of 35 Bid exclusion risks in Public Procurement - slide 9 of 35 Bid exclusion risks in Public Procurement - slide 10 of 35 Bid exclusion risks in Public Procurement - slide 11 of 35 Bid exclusion risks in Public Procurement - slide 12 of 35 Bid exclusion risks in Public Procurement - slide 13 of 35 Bid exclusion risks in Public Procurement - slide 14 of 35 Bid exclusion risks in Public Procurement - slide 15 of 35 Bid exclusion risks in Public Procurement - slide 16 of 35 Bid exclusion risks in Public Procurement - slide 17 of 35 Bid exclusion risks in Public Procurement - slide 18 of 35 Bid exclusion risks in Public Procurement - slide 19 of 35 Bid exclusion risks in Public Procurement - slide 20 of 35 Bid exclusion risks in Public Procurement - slide 21 of 35 Bid exclusion risks in Public Procurement - slide 22 of 35 Bid exclusion risks in Public Procurement - slide 23 of 35 Bid exclusion risks in Public Procurement - slide 24 of 35 Bid exclusion risks in Public Procurement - slide 25 of 35 Bid exclusion risks in Public Procurement - slide 26 of 35 Bid exclusion risks in Public Procurement - slide 27 of 35 Bid exclusion risks in Public Procurement - slide 28 of 35 Bid exclusion risks in Public Procurement - slide 29 of 35 Bid exclusion risks in Public Procurement - slide 30 of 35 Bid exclusion risks in Public Procurement - slide 31 of 35 Bid exclusion risks in Public Procurement - slide 32 of 35 Bid exclusion risks in Public Procurement - slide 33 of 35 Bid exclusion risks in Public Procurement - slide 34 of 35 Bid exclusion risks in Public Procurement - slide 35 of 35
Description: Bid exclusion risks in Public Procurement Procedures With focus on Competition and new Data Protection rules related breaches 11 APRIL 2017 Public Procurement the New Data Protection Regime: Roger Bickerstaff April 2017 page 3 Agenda

Related Topics

Download Presentation

"Bid exclusion risks in Public Procurement" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Bid exclusion risks in Public Procurement Procedures With focus on Competition and new Data Protection rules related breaches 11 APRIL 2017<br>
slide2. Public Procurement & the New Data Protection Regime: Roger Bickerstaff
April 2017<br>
slide3. page 3 Agenda What's new in the GDPR?
Managing personal data submitted by bidders in tender processes
How should data breaches by bidders be taken into account in procurement processes?
Privacy as a Selection Criteria
"Privacy by Design" as an award criteria?
Rules on the Export of Data
Concluding thoughts<br>
slide4. What is New in the General Data Protection Regulation?<br>
slide5. page 5 What's new in the GDPR? Expansion of definition of "personal data"

GDPR: an identifiable natural person is one who can be identified, directly or indirectly through "all the means reasonably likely to be used" (Recital 26), in particular by reference to:
an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

NB. Case c-582/14 0 CJEU ruled that dynamic IP addresses may constitute ‘personal data’<br>
slide6. page 6 What's new in the GDPR(2)? Privacy by Design and Privacy by Default
Data controllers must implement appropriate technical and organisational measures both when the means is decided upon and at the time of the processing itself in order to ensure data protection principles such as data minimisation are met. This may include, for example, pseudonymisation or other privacy-enhancing technologies.
Pseudonymous data
New concept of 'pseudonymisation' - privacy enhancing technique: information allowing data to be attributed to a particular individual is held separately and subject to technical and organisational measures to ensure non-attribution.
Pseudonymous data is still a form of personal data - its use is encouraged by the GDP.<br>
slide7. page 7 What's new in the GDPR(3)? Explicit or unambiguous consent?

All consents given by a data subject must be unambiguous
All consents to process sensitive personal data must be explicit
All consents must be specific, informed and active
Silence or inactivity is not sufficient
Consent must be freely given and individuals must be able to withdraw consent<br>
slide8. page 8 What's new in the GDPR(4)? Accountability, Impact Assessment and DPOs
Accountability: Organisations must be able to demonstrate compliance with data protection principles, including, where proportionate, through adoption of policies and codes of conduct
Privacy Impact Assessments: Needed where new technologies involve a high privacy risks - such as monitoring activities, systematic evaluations or processing of specific categories of data
May be a need to involve the data protection authority and obtain their view.
Data Protection Officer: public bodies must appoint a data protection officer.<br>
slide9. page 9 What's new in the GDPR(5)? Transparency
 
Organisations must provide extensive information to individuals about the processing of their data:
information must be provided in a concise, transparent, intelligible and easily accessible way
Use of standardised icons is a possibility, if the Commission chooses to introduce these via delegated acts at a later stage.<br>
slide10. page 10 What's new in the GDPR(6)? Enhanced Individuals' Rights
Retention of Rights of access and Rectification
Right to be forgotten (introduced by Google case) confirmed
Controllers who have made personal data public must take reasonable steps to notify others of the data subject's request for erasure of personal data.
Not an absolute right: controllers may still process personal data, notwithstanding an objection from the individual, if there are compelling legitimate grounds for the processing to continue.
Right to object to certain types of processing
New right to data portability:
right to 'port' the data to another provider, provided this is technically feasible.<br>
slide11. Managing personal data submitted by bidders in tender processes<br>
slide12. page 12 Managing personal data submitted by bidders (1) Personal data in the public procurement context may consist of:
Identification data – name; function; gender; contact details; passport/ID numbers
Financial identification data (for bidders bidding as individuals): bank details; VAT registrations; turnover evidence; balance sheets;
Proofs of social security and tax payments (for bidders bidding as individuals); extracts from judicial records; declarations that exclusion grounds do not apply
Evidence for tender evaluation: CV information –expertise; technical skills (languages spoken); educational and professional background; hourly rates ; credentials (details of past employment)<br>
slide13. page 13 Managing personal data submitted by bidders (2) Personal data is provided by bidders at various stages in procurement processes
Initial qualification processes – PD will be held in the ESPD
nb. In the UK - new Selection Questionnaire
During the course of a procurement process face to face or as part of submissions in competitive dialogue, competitive negotiation and negotiated procedures
In tender submissions<br>
slide14. page 14 Managing personal data submitted by bidders (3) Lawfulness of processing
Grounds for processing of data – largely stay the same in the GDPR:
Consent must be freely given, specific, informed and unambiguous
Legitimate interests ground not available to public authorities under the GDPR
Grounds for lawful processing:
Consent of data subject
Necessary for the performance of contract with a data subject or preparatory to it
Necessary for compliance with a legal obligation
Necessary to protect vital interests of a data subject
Necessary for the performance of a task in the public interests or in the exercise of official authority vested in the data controller<br>
slide15. Procurement Portal – Example, Bravo Solutions page 15<br>
slide16. Managing personal data submitted by bidders (4) Some personal data submitted in procurement processes will be "sensitive data"
Racial/ethnic origin, trade union membership, commission or allegation of commission of offences, court proceedings,
Extended in GDPR to include genetic and biometric data
Special protections apply to processing of sensitive data – processing only lawful if:
the data subject has given his explicit consent
necessary for the purposes of employment
necessary to protect the vital interests of the data subject where the data subject is physically or legally incapable of giving his consent
relates to data which are manifestly made public by the data subject
Sensitive data does not include information relating to criminal convictions and offences
But similar extra safeguards apply page 16<br>
slide17. page 17 Managing personal data submitted by bidders (5) Employee DP policy:
clear instructions to employees as to what they need to do to comply
Who can receive the data within the CA – reliability of staff, remembering the large GDPR fines?
How will personal data be accessed?
Tendering portals, access to bid data on CA's own/cloud servers?
General Rule on Confidentiality - Art. 21: CA shall not disclose information forwarded to it by economic operators which they have designated as confidential, including, but not limited to, technical or trade secrets and the confidential aspects of tenders.<br>
slide18. page 18 Managing personal data submitted by bidders (6) Bidder DP Notices
Good practice to issue notices to bidders setting out details of the processing of personal data that will be carried out during the procurement process
Contents of notices:
identification of data controller;
Personal data to be collected
purpose of processing;
who will have access to PD;
how data will be protected;
how long data will be kept for;
subject access and verification rights<br>
slide19. How should data breaches by bidders be taken into account in procurement processes?<br>
slide20. page 20<br>
slide21. Different Exclusion Strategies – across the World Performance Risk Reputation Risk Acknowledgements: Professor Yukins page 21<br>
slide22. Article 57(1) – the Mandatory Exclusion Ground Contracting Authority must treat a candidate or tenderer as being ineligible if
the Contracting Authority has actual knowledge that the candidate or tenderer
has been convicted (final judgement) of any of a list of offences – participation in a criminal organisation, fraud, money laundering, corruption.

DP breach is not one of the specified list of offences for which mandatory exclusion is required

No mandatory obligation on CAs to deselect if bidder has a known security breach – even breach has resulted in a conviction page 22<br>
slide23. Art 57(4) Discretionary Exclusions Deselection on basis of grave professional misconduct, which renders integrity questionable
Will breach of data protection obligations by a bidder amount to grave professional misconduct?
Depends on circumstances of the breach
Will breach bring the integrity of the bidder into question?
Depends on circumstances of the breach
Deselection on basis of significant or persistent performance deficiencies in a substantive requirement of a prior contract which led to early termination, damages or other comparable sanctions
Would breach of DP obligations by a bidder be a substantive requirement?
Did it lead to early termination, damages or other comparable sanctions? page 23<br>
slide24. Privacy as a selection criteria<br>
slide25. Art 58(4) - Privacy as a Selection Criteria Art 58(4): CAs may impose requirements ensuring that bidders possess the necessary human and technical resources and experience to perform the contract to an appropriate quality standard.
All requirements shall be related and proportionate to the subject- matter of the contract.

Evidence of bidders approach and experience on privacy matters could be a selection criteria where it is relevant to the subject matter of the contract
E.g. Procurements for health, social and education services
Unlikely to be applicable as a selection criteria for commodity product purchases page 25<br>
slide26. "Privacy by Design" as an award criteria<br>
slide27. GDPR Recital 78 – Privacy by Design "The principles of data protection by design and by default should also be taken into consideration in the context of public tenders"

"holistic" concept that may be applied to operations throughout an organisation, end-to-end, including its IT, business processes, physical design and networked architecture
"the Privacy by Design Resolution"

Building in privacy to products, services and organisations from the beginning of the design process
Preferable to adaptation of a product or service at a later stage page 27<br>
slide28. Privacy by Design – as an Award Criterion Consistent with GDPR Recital 78
Where security of data is relevant to the products, services or works being procured
Mandatory or a scored criteria?

Evaluation:
P0licies – review of relevant documentation, etc
Procedures – review of relevant documentation, etc
Practice – actual data handling complies with obligations

Compliance with standards
ISO/IEC 29100 – Privacy Framework: complementary to legal obligations
Certification – as long as the certification criteria are relevant page 28<br>
slide29. Rules on the Export of Data<br>
slide30. page 30 Rules on the export of data Outsourcing and "Cloud" service contracts frequently involve international data transfers
UK– no policy prohibition on export of public sector data outside the UK or EEA
Nordics – export prohibition is frequent wish by the CAs, but difficult to accomplish
Finland: Government's Decision (2013) requires that critical data and communications systems that are critical to national emergency supply situations (especially the supply, technical maintenance, and know-how) have to be kept within Finland entirely or in part of have to be able to be brought back; critical data needs to be stored in two locations in Finland<br>
slide31. page 31 Rules on the export of data (2) Contract terms – UK GCloud Framework Contract:
The Supplier shall provide the Buyer and/or Other Contracting Body with such information as the Buyer and/or Other Contracting Body may reasonably request to satisfy itself that the Supplier is complying with its obligations under the DPA including;

not to cause or permit to be processed, stored, accessed or otherwise transferred outside the European Economic Area any Buyer Data or Other Contracting Body Personal Data supplied to it by the Buyer or Other Contracting Body without approval.<br>
slide32. Concluding Thoughts<br>
slide33. Concluding Thoughts Overall impact of GDPR?
Increased focus on process
Need to be able to demonstrate compliance
Increased potential for DP fines will mean greater attention is given to DP issues
GDPR comes into force in May 2018
Contracts entered into now need to take GDPR provisions into account
Impact of Recital 78 on Public Procurement
DP issues likely to become more prominent in selection and award processes
Export of public sector data remains a contentious area page 33<br>
slide34. Bird & Bird LLP is a limited liability partnership, registered in England and Wales with registered number 0C340318 and is authorised and regulated by the Solicitors Regulation Authority. Its registered office and principal place of business is at 15 Fetter Lane, London EC4A 1JP. Bird & Bird is an international legal practice comprising Bird & Bird LLP and its affiliated and associated businesses and has offices in the locations listed on our web site: twobirds.com. The word “partner” is used to refer to a member of Bird & Bird LLP or an employee or consultant, or to a partner, member, director, employee or consultant in any of its affiliated and associated businesses, who is a lawyer with equivalent standing and qualifications. A list of members of Bird & Bird LLP, and of any non-members who are designated as partners and of their respective professional qualifications, is open to inspection at the above address.
twobirds.com Thank you Roger Bickerstaff roger.bickerstaff@twobirds.com
www.digitalbusiness.law<br>
slide35. Thank you!
www.emeaconferences.com<br>