— a multi-niche blog
The Basics Of Procurement Law For Government Technology Contracts
Government technology purchasing involves far more than comparing software features and selecting the lowest price. A public-sector contract must usually demonstrate value for money, fair competition, proper authority, transparency and responsible management of public funds. The legal framework also reaches into privacy, cybersecurity, accessibility, intellectual property, records, subcontracting and service continuity.
In Australia, the applicable rules depend on the level of government and the purchasing organisation. A Commonwealth department follows a different procurement environment from a state health service, local council or government-owned corporation. This practical guide explains the main principles, while recognising that a particular tender or contract may require advice from an Australian procurement lawyer and the agency’s authorised procurement team.
Identify The Applicable Procurement Framework
For Commonwealth entities, the central framework is the Commonwealth Procurement Rules, issued under the Public Governance, Performance and Accountability Act 2013. The rules require officials to achieve value for money and to conduct procurement in a manner that is ethical, non-discriminatory and appropriately competitive. They apply across purchases such as cloud platforms, cybersecurity services, managed networks, software licences and professional ICT advice.
State and territory agencies operate under their own legislation, policies and mandatory directions. For example, a project in Sydney may be governed by New South Wales procurement requirements, while a Victorian department in Melbourne follows the Victorian Government’s procurement framework. Queensland, Western Australia, South Australia, Tasmania, the Australian Capital Territory and the Northern Territory each have distinct rules, thresholds and approved arrangements.
The purchasing method can change as the estimated contract value increases. An agency might use a panel, request for quotation, open tender, limited tender or a procurement marketplace. A contract extension, variation or series of related purchases should not be structured to avoid a threshold or competitive process. Splitting a technology program into smaller invoices can create compliance, audit and probity concerns.
Before approaching suppliers, the agency should identify its legal entity, funding authority, procurement threshold, delegation, mandatory panel arrangements and reporting obligations. AusTender is important for many Commonwealth opportunities, while state tender portals and local government systems publish their own notices.
Apply Value For Money And Fair Competition
Value for money is broader than the lowest purchase price. Decision-makers may assess total cost of ownership, implementation effort, licensing, support, accessibility, interoperability, energy use, security, exit costs and the risk of service failure. A cheap platform that cannot integrate with legacy systems or meet Australian privacy obligations may be poor value over a five-year term.
Tender documents should describe the business outcome and essential requirements clearly. Evaluation criteria need to be relevant, measurable and disclosed in advance. If a buyer says that cybersecurity accounts for 30 per cent of the score, evaluators should apply that criterion consistently rather than introducing an undisclosed preference during assessment.
Fair competition does not require every supplier to receive identical treatment in every circumstance. It does require equal access to material information, reasonable time to respond and a consistent evaluation process. If one bidder asks a question that could affect other responses, the answer should generally be shared with all participating tenderers.
Probity controls are particularly important in a small local market. A former employee, consultant or adviser may have relationships with a vendor in Canberra, Brisbane or Perth. Conflicts of interest should be declared, assessed and managed before evaluation begins. A probity adviser, confidentiality deed, conflict register and documented evaluation record can help protect the process from allegations of bias.
Build A Defensible Tender And Contract
A technology procurement record should show how the agency defined the need, considered options, selected the market approach and made its recommendation. That record may include a business case, risk assessment, market research, evaluation plan, moderation notes, approvals and a signed contract. Poor recordkeeping can undermine a sound decision when it is reviewed by an auditor, parliamentary body, ombudsman or court.
The request for tender should state the proposed contract terms, mandatory conditions, response format, pricing model and evaluation methodology. Suppliers need to know whether the agency expects a fixed-price implementation, subscription arrangement, time-and-materials engagement or outcome-based service. Ambiguity around acceptance testing, milestones and payment can lead to disputes after award.
The final contract should address service levels, support hours, incident response, maintenance windows, performance credits, reporting and remedies. For a platform used by a department in Darwin or a hospital network across regional New South Wales, resilience and disaster recovery deserve specific treatment. The agreement should explain how the supplier will continue or restore critical services during outages, cyber incidents and supply-chain disruptions.
Procurement law does not make every unsuccessful bidder entitled to a detailed explanation or compensation. However, a clear debrief process supports trust and can identify weaknesses in future tenders. A standstill period may be used before signing, depending on the organisation’s policy and the procurement method.
Manage Privacy, Cybersecurity And Data
A technology contract may involve personal information, health records, location data, identity credentials or information about vulnerable people. The Privacy Act 1988 and Australian Privacy Principles can apply to Commonwealth agencies and many private suppliers, while state and territory privacy laws may apply to state bodies. The contract should identify each party’s role, permitted uses, security obligations, breach notification duties and deletion or return requirements.
Cybersecurity requirements should be proportionate to the system’s risk. A public-sector buyer may require alignment with the Australian Government Information Security Manual, the Protective Security Policy Framework or the Essential Eight, although these controls do not automatically apply to every agency or supplier. Requirements should be expressed in contractual terms, supported by evidence such as independent assurance reports, penetration testing and vulnerability management records.
Agreements should explain what happens when a supplier detects a suspected breach. Useful clauses cover immediate notification, cooperation with forensic investigations, preservation of evidence, communication approval, remediation costs and assistance with regulatory reporting. They should also address subcontractors, because a vendor’s hosting provider, support desk or analytics service may handle the same government data.
Mobile and field technology creates particular exposure for inspectors, emergency workers and community-service staff. Agencies planning device deployment can draw on this mobile security guidance when considering encryption, authentication, remote wiping, application controls and secure connectivity. The contract should then convert those technical expectations into measurable supplier duties.
Data location deserves careful analysis rather than a simple “Australian hosting” promise. A cloud service may store backups overseas, use offshore support staff or permit a foreign parent company to access metadata. The agency should assess sovereignty, foreign disclosure laws, encryption key control and the practical ability to retrieve records at the end of the agreement.
Protect Public Records, Accessibility And Intellectual Property
Government technology contracts often create records that must be retained under applicable archives, records and information-management requirements. Audit logs, approval records, service reports, correspondence and system data may be needed years after a project ends. Clauses should require reliable export, readable formats, metadata preservation and cooperation with lawful access requests.
Freedom of information obligations can affect documents held by a supplier, even where the contractor is not itself an agency. A contract should require prompt assistance with searches, reviews, redactions and production. Commercial confidentiality should be defined carefully because a supplier’s assertion that information is “confidential” does not automatically override statutory disclosure obligations.
Accessibility is a procurement requirement as well as a design concern. Public portals, mobile applications and digital forms should be usable by people with disability and should work with assistive technologies. Evaluation criteria can cover WCAG conformance, keyboard navigation, captions, plain language and accessibility testing. Guidance on user-centred design can help teams connect legal responsibility with the everyday experience of residents using a government service.
Intellectual property clauses must distinguish pre-existing material, newly developed code, configurations, documentation and third-party components. The agency may need ownership of custom source code, or it may prefer a broad, perpetual licence that avoids paying for exclusive ownership. Open-source software is not automatically unsuitable, but its licence conditions, security maintenance and distribution implications must be assessed.
A contract should also address moral rights consents, patent or infringement claims, software escrow, dependency on proprietary formats and the agency’s rights to modify or transition the solution. Without these provisions, a supplier can become a practical gatekeeper when the agency changes providers.
Control Supplier Risk And Contract Change
Government buyers should assess a supplier’s financial strength, technical capacity, insurance, modern slavery controls, subcontracting model and history of performance. The Commonwealth Modern Slavery Act 2018 creates reporting obligations for certain large entities, but a smaller supplier can still present labour, sourcing or ethical risks. A procurement process should consider the whole delivery chain, including hardware manufacture and overseas support.
Risk allocation should reflect who can best prevent or manage a problem. A supplier may accept responsibility for its coding error, while the agency remains responsible for a poorly defined policy requirement. Liability caps, indemnities, insurance and exclusions need to be read together. A cap that is too low for a privacy breach or prolonged outage may leave the public body exposed.
Change control is essential in long-running digital programs. The contract should set out who can approve a change, how the price and timeline are calculated, and when a change becomes a new procurement rather than a permissible variation. A supplier should not receive a substantially different scope through informal emails or a succession of unapproved work orders.
Practical checks before the contract is signed:
- Confirm the entity, delegation, threshold and mandatory procurement channel.
- Record conflicts of interest, evaluation reasons and approval decisions.
- Test privacy, security, accessibility and records requirements against the proposed solution.
- Check termination, transition, data export and supplier-assurance provisions.
Contract administration should continue after signature. The agency should monitor service levels, invoices, incidents, subcontractors, audit findings and milestone acceptance. A contract manager in Adelaide or the Gold Coast may be coordinating remote teams across several time zones, so reporting responsibilities and escalation contacts need to remain current.
Useful evidence to retain during delivery includes:
- Signed variations and approved change requests.
- Security attestations, incident reports and remediation plans.
- Performance reports, acceptance records and payment approvals.
- Exit plans, data-retrieval tests and asset registers.
Public procurement is judged over the life of the arrangement, not just at tender award. Regular reviews help detect scope creep, unmanaged conflicts, weak controls and emerging technology risks before they become expensive disputes.
The safest approach is to treat procurement law as part of technology governance rather than a final legal checkpoint. Map the applicable Australian rules, define the public outcome, document the evaluation, negotiate workable protections and maintain evidence throughout delivery. For a live tender, renewal or high-risk cloud project, obtain advice from the relevant government procurement authority and qualified Australian legal professionals before commitments are made.
— get in touch
Have a question or want to reach out?