Bounded implementation investigation, 9 September 2026. The anchor remains DSIT's published 5 February 2025 payment, GBP 56,736, transaction 654609, to Crisp Thinking (UK) Ltd. No record inspected here joins that payment to a particular report, monitoring specification or older contract. See the preceding commercial-participant.md and its retained original CSV; the payment is not counted again.
The newly visible mechanism is ministerial scope-setting, departmental commissioning and assessment, supplier analysis, then platform review under private terms. An acquired draft policy specifies documented instructions and agreed search methods for contractors. Contemporary parliamentary testimony describes both referrals and warnings about lawful content. The exact escalation approvals and classification thresholds remain partly redacted, and an executed Crisp SOW remains unestablished.
A public FOI-associated copy of the National Security and Online Information Team Data Protection and Compliance Policy supplies detailed instructions. It is hosted by Big Brother Watch at a path identifying FOI2024-00576 and May 2024. Every page is marked DRAFT, OFFICIAL-SENSITIVE. No approval date, signed adoption, final revision or incorporation into the February 2025 engagement was established. Describe the following as provisions of this acquired draft, rather than proof every analyst or supplier followed them. [Publicly hosted policy copy](http[local research file]
| Who / decision | Draft provision | Exact PDF locator and limit |
|---|---|---|
| NSOIT or central government: commission work | NSOIT may commission within its remit or be tasked through central command structures, with Cabinet Office National Security Secretariat given as an example. Sustained monitoring requires appropriate ministerial agreement. | §3.2, PDF 4. This is a route for tasking, not an actual task order. |
| NSOIT Analysis team: assess a task | Every collection activity must have a legitimate policy objective, be proportionate, meet data-protection requirements and avoid directed surveillance. | §3.3, PDF 4; §§3.7–3.9, PDF 5. |
| DSIT: instruct and onboard suppliers | Delivery partners must follow NSOIT instructions. DSIT takes controller responsibility where it processes personal data; third parties are to be processors under Article 28, operating on documented instructions. Legal, Commercial and Operational Data teams participate in onboarding. | §§3.4–3.6, PDF 4–5. This does not identify which Crisp entity signed any agreement. |
| NSOIT and partner: agree methods | Case-specific methodology must cover data sources, search terms, task subject/purpose and minimisation. Contractual assurance and periodic review are specified. | §3.6(b)–(d), PDF 5. The actual search dictionary, classification specification and completed assurance record were not acquired. |
| Analysts: collection limits | Publicly accessible sources only; no name-based searching or building a picture of private individuals/groups by following activity. These instructions are to be communicated to partners. | §3.1, PDF 4; Schedule 1, PDF 9. The draft permits access to public sites requiring login, while prohibiting fake personas. Schedule 2 Part B §§1.4–1.6, PDF 15. |
| NSOIT: decide on referral | Teams identify potentially harmful material within ministerially agreed remit. NSOIT reviews against agreed thresholds. Authorized content may be shared for platforms to act at their discretion, with information minimised. | §§4.1–4.2, PDF 7. The threshold and authorization detail is partly blacked out: do not invent a named approving officer or automatic approval rule. |
| Politicians, news sources and journalists: an exclusion | The draft excludes their content from platform referrals; its journalist definition depends on a news-publishing entity, editorial control and other institutional criteria. | §§1.6–1.7, PDF 3; §4.2(b), PDF 7; Schedule 1, PDF 9. This is not a blanket exemption for every citizen publishing commentary. |
| Head of NSOIT and DPO: exceptional retention | Raw samples normally up to three months; output retention/review and justified extensions involve the Head and Data Protection Officer. Thematic leads manage expiry of escalation links. | §3.13, PDF 6; §4.4(A), PDF 7; Schedule 2 §2.5, PDF 13. It does not show retention complied with in an actual case. |
| Legal advisers: surveillance boundary | The draft says DSIT has no directed-surveillance RIPA authorization; activity risking that threshold must not be authorized and uncertainty goes to legal advisers. | Schedule 2 Part B §§1.5–1.6, PDF 15. This is the draft's legal/operational account, not an independent determination about each collection. |
The data-collection checklist, Schedule 3, PDF 16–19, is almost entirely redacted. PDF 7 also visibly blacks out portions of escalation and review procedure. These are real redactions, confirmed visually at PDF 7 and 16, not merely failed text extraction. The draft says a DPIA has been completed and is regularly reviewed (Schedule 2 Part A §2.2(d), PDF 11); the actual DPIA and its conclusions were not acquired. No attempt was made to recover redacted text.
In HL3811, answered 30 April 2024, the government says DSIT has platform trusted-flagger status and may refer material within ministerial steers/remit that appears to violate platform terms; platforms decide the outcome. This establishes the department's publicly described referral channel, without proving a DSA statutory designation. [Answer](http[local research file]
HL7610, answered 3 June 2025, identifies foreign-state threats, election risks and AI/deepfakes among the team's subjects, with ministers agreeing high-risk work. 9335, answered 22 June 2026, restates the public-safety/national-security remit and continuing ministerial review. Neither answer publishes a commissioned topic list, the exact search terms or referral threshold scores. [2025 answer](http[local research file] [2026 answer](http[local research file]
The current official privacy notice names DSIT as controller. It describes aggregate analysis of public information, incidental personal/special-category data, minimisation, no private-page review and no automated decision-making/profiling. It describes platform referrals, public-interest processing bases, retention limits and DPO/ICO complaint routes. It now names The Global Strategy Network Limited as an appointed analysis contractor. This is not an exclusive-provider statement, proof Crisp was replaced, or a specification for the February 2025 payment. The page displays publication on16 April 2024, but a revision date for this contractor paragraph was not established. Do not backdate the current wording. [Notice, controller, purpose, sharing, retention and rights sections](http[local research file]
The distinction between public trend analysis and processing individual posts must stay visible: the policy's stated restrictions do not mean personal data is never processed. Equally, the existence of handles, links or political opinions in collected public content does not alone prove an individualized surveillance programme.
ICO decision IC-374825-D9K4, 11 November 2025, confirms a request for Crisp reports within the week beginning 24 June 2024. DSIT said all but one had been deleted under retention policy; on 24 October 2025 it partially disclosed the remaining report and released a June referral count of ten (§§8–14, PDF 2–3). The ICO inspected the unredacted report (§18). DSIT described keyword tracking, behavioural analytics, platform strategies and threat-identification criteria (§36, PDF 11–14). Those are attributed submissions, not methods personally inspected here. The Commissioner upheld the remaining national-security redactions after considering public interest (§§39–43, PDF 15), with tribunal appeal available (§44, PDF 16). This is independent review of disclosure, not certification of NSOIT's operating legality. The underlying report, its exact date and any invoice linkage remain unread. Paragraph 36 calls it the week of the general election; that wording must not silently replace the request's week beginning 24 June 2024. [Original decision](http[local research file]
The 14 April 2026 parliamentary hearing, Q25–30, PDF 8–11, supplies an unusually explicit operating account. Minister Kanishka Narayan described a public-safety/national-security threshold, declined the requested activity/removal figures, and offered future briefings subject to security constraints. At Q29, Talitha Rowland described Southport-era monitoring of lawful but harmful narratives, early warnings even before content appeared on a platform, and requests for review against each platform's own terms. She distinguished that work from law enforcement's illegal-content response. At Q30 she said they lacked specific foreign-interference indicators at the time; do not recast this example as proven foreign-state content. This supports a government-to-platform influence channel affecting lawful material, while platforms retain the described action decision. It does not demonstrate a removal order, Crisp's role in that example, or the resulting removal rate. [Hearing, Q25–30](http[local research file]
The Science, Innovation and Technology Committee's July 2025 report, §§60–62, recommended statutory footing and Intelligence and Security Committee oversight. Its October government response, received 18 September and published 17 October 2025, instead defended ministerial oversight, existing parliamentary questioning, FOI and subject-access routes; it did not commit to the requested statutory/ISC reform. A general commitment to accountability is therefore not acceptance of that institutional safeguard. [Committee §62](http[local research file] [response, Appendix 1, Disinformation Campaigns, reply to §62](http[local research file]
This is not an absence-of-all-review finding: MPs questioned ministers, the ICO examined withheld material, and stated data-rights routes exist. The missing layer is a published independent operational audit and the actual task/approval records needed to test compliance. Nor does the government's statement that platforms decide action settle the separate question of how official flagging, privileged access and regulatory relationships influence those decisions.
| Candidate ID | Typed relation | Evidence stage |
|---|---|---|
| commission-e-ministers | DSIT ministers → NSOIT: set/review remit | Public ministerial account, 2025 and 2026. |
| commission-e-tasking | NSOIT / Cabinet Office NSS → collection activity: proposed tasking route | Acquired disclosed draft §3.2; no actual order. |
| commission-e-partner-instructions | DSIT/NSOIT → delivery partners: documented instruction/method agreement | Draft §§3.5–3.6; applicability to paid Crisp engagement unestablished. |
| commission-e-crisp-report | Crisp → NSOIT: produced report | Independent disclosure adjudication; report itself unread. |
| commission-e-platform-referral | NSOIT → platforms: flags or warns for terms review | Departmental accounts, 2024 and 2026; voluntary action described. |
| commission-e-ico-review | ICO → DSIT disclosure decision: upheld remaining redactions | 11 November 2025; not an operational audit. |
| commission-e-oversight-request | Committee → government: requests statutory/ISC oversight | July 2025 recommendation; response offers existing channels without commitment to requested reform. |
| commission-e-current-contractor | NSOIT → Global Strategy Network Ltd: reports appointment for analysis | Current notice; appointment date and exact contract unestablished. |
The strongest rival to a private supplier choosing what citizens may say is an instructed contractor performing bounded public-source analysis, with government retaining tasking/referral responsibility and platforms retaining action. The strongest concern supported by these records is more specific: a government-selected monitoring and privileged referral process can reach lawful material, while precise criteria and authorization steps are not fully visible and a proposed stronger oversight structure was not adopted in the inspected response.
The next discriminating record is the executed SOW/data-processing schedule/tasking instruction and completed assessment matching transaction 654609, followed by the escalation log and platform response for a specified case. A published final compliance policy, its adoption/version history, the DPIA and an independent assurance report would test whether the draft's constraints actually governed delivery. Likely holders are DSIT Commercial, NSOIT, the Operational Data/DPO team and the actual supplier. These are precise public-record gaps, not a claim that the records do not exist. No outreach was undertaken. Acquisition stops here for forest review.
The original payment remains in the prior wave. This wave retained the following bytes; .txt files are extraction derivatives, not originals. The capture manifest is commission-captures.json.
| Source/file | Capture and SHA-256 | Reading scope / state |
|---|---|---|
| commission-ico-decision.pdf | 2026-09-09T09:01:46Z; 172637 bytes;1e33d2fcaa65f09cb4d045b04f85689e65db3779604fdcaa2e175477acd3ae56 | Full 16-page original text read, scoped findings above. |
| commission-privacy.html | 2026-09-09T09:01:46Z; 96332 bytes;5891f9aa42d6c159d0c1a8b34ad286bbe536a53d93c94dcada1f3c46d3f5690c | Complete substantive current notice read through official reader; original HTML retained. |
| commission-compliance-redacted.pdf | 2026-09-09T09:03:33Z; 264507 bytes;af10011b6bab2a29cc2c59225b9100aa37a9a9df3e14176dea5abcfbe8b26a79 | Full 19-page available text read; PDF 7 and 16 visually inspected. Public FOI-associated custodian copy; marked draft; no underlying DSIT file comparison. |
| 2026 oral hearing | Exact parliamentary URL above; reader turn985view2 / turn987view1–4 | Q25–30 plus institutional context Q7 read. Ordinary GET 403; no original retained and no retry. |
| 2025 committee report / response | Exact URLs above; report §§60–62; response metadata and relevant reply | Primary reader text read; response ordinary GET 403. No original retained, no retry. |
| Parliamentary answers | HL3811, HL7610, 9335 exact URLs above | Complete question and answer text read through official reader. |
The BBW PDF reader initially returned a one-line 'One moment, please...' page. One ordinary GET substitute succeeded with an actual PDF; no challenge solving or access-control evasion occurred. The prior Contracts Finder 403, ACNC restriction and other closed routes were not retried. Searches also surfaced unrelated MOD 'New Style of IT' records; these were excluded because the acronym denotes a different programme. Additional spending months were not opened or totalled. No WEF taxonomy specification, supplier-controlled censorship right or February 2025 invoice match was found in the inspected material.