Treat procurement as a service lifecycle
Selection is only the beginning of the governance work. The operating model must cover implementation, routine service, material changes, incidents, renewal, termination, transition, and deletion. UK government sourcing guidance recommends planning mobilisation and exit early rather than waiting until the end of a contract. [1]
Put shared responsibilities into the contract
A data-processing agreement is part of the control set, not the entire service contract. The ICO identifies required terms for controller-processor arrangements, including instructions, confidentiality, security assistance, subprocessor conditions, support for individual rights, end-of-contract handling, and audit information. The final allocation should reflect the actual data flows and responsibilities of the parties. [2]
- Named owners, governance forums, escalation paths, and approval authorities
- Service levels tied to clinically meaningful workflows, with measurement and exclusions
- Security, incident, vulnerability, continuity, backup, recovery, and notification duties
- Change control for material features, subprocessors, hosting, interfaces, and contract terms
- Audit, assurance, records, regulatory support, transition, export, deletion, and survival clauses
A reversible service lifecycle
A five-stage lifecycle showing how an exit-ready contract remains testable through implementation, operation, and transition.
- Contract
Allocate duties and specify acceptance, change, export, transition, and deletion.
- Mobilise
Map dependencies, rehearse failures, and accept against evidence.
- Operate
Review service, access, risk, incidents, assurance, and continuity.
- Rehearse
Test exports and transition responsibilities before they are urgent.
- Exit
Reconcile, transfer, revoke, delete, verify, and obtain accountable acceptance.
Mobilise with acceptance evidence
Convert contract commitments into an implementation plan with dependencies, accountable owners, acceptance criteria, training, support, data setup, integration testing, privacy and clinical-safety activities, and a rollback route. Rehearse critical pathways and failures with synthetic data. Do not treat a supplier's completion notice as local acceptance evidence. [1][5]
- Confirm access roles, least privilege, review ownership, audit visibility, and support escalation.
- Test invitations, completion, scoring, review, correction, export, and recovery from failure.
- Record residual risks, temporary workarounds, owners, expiry dates, and go-live authority.
- Retain evidence of acceptance and the exact configuration and product version accepted.
Govern changes and renewal with current evidence
Maintain a schedule for service reviews, assurance refreshes, access reviews, incident learning, subprocessor review, continuity tests, and export checks. Require notice and impact information for material changes. At renewal, compare the current service and evidence with the original requirements rather than relying on historical approval or switching cost. [3][5]
Test portability and complete the exit
An export is useful only if it is complete, intelligible, securely delivered, and usable by the receiving process. Test representative synthetic records before contract signature and periodically thereafter. On exit, reconcile record counts and key fields, document exceptions, preserve required records, revoke access and integrations, obtain deletion evidence where applicable, and close only when an accountable owner accepts the result. [5][2]
Data portability under a commercial exit plan is broader than the individual right to data portability. ICO guidance explains that the individual right applies only in defined circumstances and to qualifying personal data provided to a controller, while a contractual export can cover the clinic's wider operational records, metadata, and governance needs. The two should be planned separately, with appropriate legal or information-governance advice for the organisation's circumstances. [4]
Sources and further reading
- The Sourcing Playbook (opens in a new tab)UK Cabinet Office. Published 2021-05-20. Updated 2026-06-15. Accessed 2026-07-13. Government guidance covering mobilisation, contract management, risk allocation, and exit planning.
- What needs to be included in the contract? (opens in a new tab)Information Commissioner's Office. Accessed 2026-07-13. Official UK guidance on the required contents of controller-processor contracts.
- Data protection audit framework (opens in a new tab)Information Commissioner's Office. Published 2024-10-07. Accessed 2026-07-13. Official audit framework for assessing and recording privacy-management controls, evidence, actions, and accountability.
- Right to data portability (opens in a new tab)Information Commissioner's Office. Accessed 2026-07-13. Official UK guidance on the scope, conditions, formats, security, and limits of the individual right to data portability.
- The cloud security principles (opens in a new tab)UK National Cyber Security Centre. Accessed 2026-07-13. Official cloud-security principles including secure administration, audit information, data separation, and secure service use.