Disclosure Log

Enterprise Resource Planning (FOI/5677)

Message from Nottinghamshire County Council - 24 April 2025


Dear ***** *****,

 

 

FREEDOM OF INFORMATION ACT 2000 – REQUEST FOR INFORMATION REFERENCE FOI/5677

Thank you for your request for information relating to Enterprise Resource Planning.

We are now able to provide the following information:

  1. Which enterprise resource planning (ERP) platforms you use (if any) in the execution of your duties.
    1. [ERP platforms such as SAP, Oracle, or Microsoft Dynamics 365, are software systems that collect data from multiple sources and create a single source of truth helping organisations manage their core business processes such as finance, HR, manufacturing, supply chain, sales, and procurement.] Exempt – see exemption below
  2. What version of the Enterprise Resource Planning you are utilising. As an example, you may utilise SAP ECC 6 or Oracle Fusion Cloud. Exempt – see exemption below
  3. Whether you are planning major projects such as an upgrade or a re-platforming of your ERP platforms in the next 24 months. Yes

    For this FOI we are not releasing any contract information on ICT tools or software used by NCC. This is exemption information under section 31 of Freedom of Information Act. The public interest in disclosure for transparency, scrutiny and accountability of public bodies is outweighed by the public interest in ensuring the risks to operations and assets of public authorities are not exposed to malicious actors. 
This is due to the following: 
  1. Any information that could be used by hackers, scammers, and other malicious actors to compromise the Council’s ICT systems and cyber security should not be disclosed to external organisations, partners or members of the public. 
  1. Examples of information which could be used by malicious actors, particularly if comprised of details relating to short time periods of less than a year, include: 
  • Use of external cyber/online security contractors, firms; and 
  • Details of ICT and cyber security systems, procedures, policies and contracts particular to the Council 

We trust this now satisfies your request and that you find this information to be helpful, however if you are unhappy with the way in which your request has been handled, then please email us at [email protected] quoting the reference FOI/5677 and we will be happy to review your request

For future reference, Nottinghamshire County Council regularly publishes previous FOI requests and answers on its website, under Disclosure logs, that may provide details relating to your query. (see link) Your privacy: we use your personal information such as name and address so that we can comply with our legal obligations to respond to FOI requests.  For further details about the use of information about you, please see the information handling privacy notice on our website at https://www.nottinghamshire.gov.uk/media/4323566/informationgovernanceandinformationrightsprivacynotice.pdf

If you are dissatisfied with the handling of your request, you have the right to ask for an internal review.   Requests should be submitted within 40 working days of the date of receipt of the response to your original request and should be addressed to: Complaints and Information Team, Nottinghamshire County Council, County Hall, Loughborough Road, West Bridgford, NOTTINGHAM, NG2 7QP or [email protected].

Please remember to quote the reference number above in any future communications.

If you are not content with the outcome of the internal review, you have the right to apply directly to the Information Commissioner for a decision.  The Information Commissioner can be contacted at: Information Commissioner’s Office, Wycliffe House, Water Lane, WILMSLOW, SK9 5AF or  

Section 31 only applies to information that does not fall into the categories in section 30. For this reason sections 30 and 31 are sometimes referred to as being mutually exclusive. Section 31 applies where complying with the request would prejudice or would be likely to prejudice various law enforcement purposes (listed in the Act) including preventing crime, administering justice, and collecting tax. It also protects certain other regulatory functions, for example those relating to health and safety and charity administration. Note: Section 31(1)(a)  can protect information on a public authority’s systems which would make it more vulnerable to crime . Can also be used by a public authority with no law enforcement function to protect the work of another.



Both exemptions are qualified by the public interest test.



https://ico.org.uk/media/for-organisations/documents/1207/law-enforcement-foi-section-31.pdf




Disclosure would prejudice one of the following:



(a) the prevention or detection of crime,

(b) the apprehension or prosecution of offenders,

(c) the administration of justice,

(d) the assessment or collection of any tax or duty or of

any imposition of a similar nature,

(e) the operation of immigration controls,

(f) the maintenance of security and good order in prisons or in other institutions where persons are lawfully detained,

(g) the exercise by any public authority of its functions for any of the purposes specified in subsection (2) [the purposes are establishing failure to comply with the law, improper conduct, what regulatory action to take, a person’s fitness or competence, the cause of an accident/protecting charities/securing health and safety at work],

(h) any civil proceedings which are brought by or on behalf of a public authority and arise out of an investigation conducted, for any purposes specified in subsection (2) [see above], by or on behalf of the authority by virtue of Her Majesty’s prerogative or by virtue of powers conferred by or under an enactment,