← Red Threads

Who instructs NSOIT's monitoring suppliers?

Bounded implementation investigation, 9 September 2026. The anchor remains DSIT's published 5 February 2025 payment, GBP 56,736, transaction 654609, to Crisp Thinking (UK) Ltd. No record inspected here joins that payment to a particular report, monitoring specification or older contract. See the preceding commercial-participant.md and its retained original CSV; the payment is not counted again.

The newly visible mechanism is ministerial scope-setting, departmental commissioning and assessment, supplier analysis, then platform review under private terms. An acquired draft policy specifies documented instructions and agreed search methods for contractors. Contemporary parliamentary testimony describes both referrals and warnings about lawful content. The exact escalation approvals and classification thresholds remain partly redacted, and an executed Crisp SOW remains unestablished.

The instruction instrument, with its status intact

A public FOI-associated copy of the National Security and Online Information Team Data Protection and Compliance Policy supplies detailed instructions. It is hosted by Big Brother Watch at a path identifying FOI2024-00576 and May 2024. Every page is marked DRAFT, OFFICIAL-SENSITIVE. No approval date, signed adoption, final revision or incorporation into the February 2025 engagement was established. Describe the following as provisions of this acquired draft, rather than proof every analyst or supplier followed them. [Publicly hosted policy copy](http[local research file]

Who / decision Draft provision Exact PDF locator and limit
NSOIT or central government: commission work NSOIT may commission within its remit or be tasked through central command structures, with Cabinet Office National Security Secretariat given as an example. Sustained monitoring requires appropriate ministerial agreement. §3.2, PDF 4. This is a route for tasking, not an actual task order.
NSOIT Analysis team: assess a task Every collection activity must have a legitimate policy objective, be proportionate, meet data-protection requirements and avoid directed surveillance. §3.3, PDF 4; §§3.7–3.9, PDF 5.
DSIT: instruct and onboard suppliers Delivery partners must follow NSOIT instructions. DSIT takes controller responsibility where it processes personal data; third parties are to be processors under Article 28, operating on documented instructions. Legal, Commercial and Operational Data teams participate in onboarding. §§3.4–3.6, PDF 4–5. This does not identify which Crisp entity signed any agreement.
NSOIT and partner: agree methods Case-specific methodology must cover data sources, search terms, task subject/purpose and minimisation. Contractual assurance and periodic review are specified. §3.6(b)–(d), PDF 5. The actual search dictionary, classification specification and completed assurance record were not acquired.
Analysts: collection limits Publicly accessible sources only; no name-based searching or building a picture of private individuals/groups by following activity. These instructions are to be communicated to partners. §3.1, PDF 4; Schedule 1, PDF 9. The draft permits access to public sites requiring login, while prohibiting fake personas. Schedule 2 Part B §§1.4–1.6, PDF 15.
NSOIT: decide on referral Teams identify potentially harmful material within ministerially agreed remit. NSOIT reviews against agreed thresholds. Authorized content may be shared for platforms to act at their discretion, with information minimised. §§4.1–4.2, PDF 7. The threshold and authorization detail is partly blacked out: do not invent a named approving officer or automatic approval rule.
Politicians, news sources and journalists: an exclusion The draft excludes their content from platform referrals; its journalist definition depends on a news-publishing entity, editorial control and other institutional criteria. §§1.6–1.7, PDF 3; §4.2(b), PDF 7; Schedule 1, PDF 9. This is not a blanket exemption for every citizen publishing commentary.
Head of NSOIT and DPO: exceptional retention Raw samples normally up to three months; output retention/review and justified extensions involve the Head and Data Protection Officer. Thematic leads manage expiry of escalation links. §3.13, PDF 6; §4.4(A), PDF 7; Schedule 2 §2.5, PDF 13. It does not show retention complied with in an actual case.
Legal advisers: surveillance boundary The draft says DSIT has no directed-surveillance RIPA authorization; activity risking that threshold must not be authorized and uncertainty goes to legal advisers. Schedule 2 Part B §§1.5–1.6, PDF 15. This is the draft's legal/operational account, not an independent determination about each collection.

The data-collection checklist, Schedule 3, PDF 16–19, is almost entirely redacted. PDF 7 also visibly blacks out portions of escalation and review procedure. These are real redactions, confirmed visually at PDF 7 and 16, not merely failed text extraction. The draft says a DPIA has been completed and is regularly reviewed (Schedule 2 Part A §2.2(d), PDF 11); the actual DPIA and its conclusions were not acquired. No attempt was made to recover redacted text.

What current public accounts corroborate

In HL3811, answered 30 April 2024, the government says DSIT has platform trusted-flagger status and may refer material within ministerial steers/remit that appears to violate platform terms; platforms decide the outcome. This establishes the department's publicly described referral channel, without proving a DSA statutory designation. [Answer](http[local research file]

HL7610, answered 3 June 2025, identifies foreign-state threats, election risks and AI/deepfakes among the team's subjects, with ministers agreeing high-risk work. 9335, answered 22 June 2026, restates the public-safety/national-security remit and continuing ministerial review. Neither answer publishes a commissioned topic list, the exact search terms or referral threshold scores. [2025 answer](http[local research file] [2026 answer](http[local research file]

The current official privacy notice names DSIT as controller. It describes aggregate analysis of public information, incidental personal/special-category data, minimisation, no private-page review and no automated decision-making/profiling. It describes platform referrals, public-interest processing bases, retention limits and DPO/ICO complaint routes. It now names The Global Strategy Network Limited as an appointed analysis contractor. This is not an exclusive-provider statement, proof Crisp was replaced, or a specification for the February 2025 payment. The page displays publication on16 April 2024, but a revision date for this contractor paragraph was not established. Do not backdate the current wording. [Notice, controller, purpose, sharing, retention and rights sections](http[local research file]

The distinction between public trend analysis and processing individual posts must stay visible: the policy's stated restrictions do not mean personal data is never processed. Equally, the existence of handles, links or political opinions in collected public content does not alone prove an individualized surveillance programme.

Actual supplier output and disclosure review

ICO decision IC-374825-D9K4, 11 November 2025, confirms a request for Crisp reports within the week beginning 24 June 2024. DSIT said all but one had been deleted under retention policy; on 24 October 2025 it partially disclosed the remaining report and released a June referral count of ten (§§8–14, PDF 2–3). The ICO inspected the unredacted report (§18). DSIT described keyword tracking, behavioural analytics, platform strategies and threat-identification criteria (§36, PDF 11–14). Those are attributed submissions, not methods personally inspected here. The Commissioner upheld the remaining national-security redactions after considering public interest (§§39–43, PDF 15), with tribunal appeal available (§44, PDF 16). This is independent review of disclosure, not certification of NSOIT's operating legality. The underlying report, its exact date and any invoice linkage remain unread. Paragraph 36 calls it the week of the general election; that wording must not silently replace the request's week beginning 24 June 2024. [Original decision](http[local research file]

Referral, lawful speech and the limits of oversight

The 14 April 2026 parliamentary hearing, Q25–30, PDF 8–11, supplies an unusually explicit operating account. Minister Kanishka Narayan described a public-safety/national-security threshold, declined the requested activity/removal figures, and offered future briefings subject to security constraints. At Q29, Talitha Rowland described Southport-era monitoring of lawful but harmful narratives, early warnings even before content appeared on a platform, and requests for review against each platform's own terms. She distinguished that work from law enforcement's illegal-content response. At Q30 she said they lacked specific foreign-interference indicators at the time; do not recast this example as proven foreign-state content. This supports a government-to-platform influence channel affecting lawful material, while platforms retain the described action decision. It does not demonstrate a removal order, Crisp's role in that example, or the resulting removal rate. [Hearing, Q25–30](http[local research file]

The Science, Innovation and Technology Committee's July 2025 report, §§60–62, recommended statutory footing and Intelligence and Security Committee oversight. Its October government response, received 18 September and published 17 October 2025, instead defended ministerial oversight, existing parliamentary questioning, FOI and subject-access routes; it did not commit to the requested statutory/ISC reform. A general commitment to accountability is therefore not acceptance of that institutional safeguard. [Committee §62](http[local research file] [response, Appendix 1, Disinformation Campaigns, reply to §62](http[local research file]

This is not an absence-of-all-review finding: MPs questioned ministers, the ICO examined withheld material, and stated data-rights routes exist. The missing layer is a published independent operational audit and the actual task/approval records needed to test compliance. Nor does the government's statement that platforms decide action settle the separate question of how official flagging, privileged access and regulatory relationships influence those decisions.

Candidate relations and the discriminating gap

Candidate ID Typed relation Evidence stage
commission-e-ministers DSIT ministers → NSOIT: set/review remit Public ministerial account, 2025 and 2026.
commission-e-tasking NSOIT / Cabinet Office NSS → collection activity: proposed tasking route Acquired disclosed draft §3.2; no actual order.
commission-e-partner-instructions DSIT/NSOIT → delivery partners: documented instruction/method agreement Draft §§3.5–3.6; applicability to paid Crisp engagement unestablished.
commission-e-crisp-report Crisp → NSOIT: produced report Independent disclosure adjudication; report itself unread.
commission-e-platform-referral NSOIT → platforms: flags or warns for terms review Departmental accounts, 2024 and 2026; voluntary action described.
commission-e-ico-review ICO → DSIT disclosure decision: upheld remaining redactions 11 November 2025; not an operational audit.
commission-e-oversight-request Committee → government: requests statutory/ISC oversight July 2025 recommendation; response offers existing channels without commitment to requested reform.
commission-e-current-contractor NSOIT → Global Strategy Network Ltd: reports appointment for analysis Current notice; appointment date and exact contract unestablished.

The strongest rival to a private supplier choosing what citizens may say is an instructed contractor performing bounded public-source analysis, with government retaining tasking/referral responsibility and platforms retaining action. The strongest concern supported by these records is more specific: a government-selected monitoring and privileged referral process can reach lawful material, while precise criteria and authorization steps are not fully visible and a proposed stronger oversight structure was not adopted in the inspected response.

The next discriminating record is the executed SOW/data-processing schedule/tasking instruction and completed assessment matching transaction 654609, followed by the escalation log and platform response for a specified case. A published final compliance policy, its adoption/version history, the DPIA and an independent assurance report would test whether the draft's constraints actually governed delivery. Likely holders are DSIT Commercial, NSOIT, the Operational Data/DPO team and the actual supplier. These are precise public-record gaps, not a claim that the records do not exist. No outreach was undertaken. Acquisition stops here for forest review.

Source custody and access limits

The original payment remains in the prior wave. This wave retained the following bytes; .txt files are extraction derivatives, not originals. The capture manifest is commission-captures.json.

Source/file Capture and SHA-256 Reading scope / state
commission-ico-decision.pdf 2026-09-09T09:01:46Z; 172637 bytes;1e33d2fcaa65f09cb4d045b04f85689e65db3779604fdcaa2e175477acd3ae56 Full 16-page original text read, scoped findings above.
commission-privacy.html 2026-09-09T09:01:46Z; 96332 bytes;5891f9aa42d6c159d0c1a8b34ad286bbe536a53d93c94dcada1f3c46d3f5690c Complete substantive current notice read through official reader; original HTML retained.
commission-compliance-redacted.pdf 2026-09-09T09:03:33Z; 264507 bytes;af10011b6bab2a29cc2c59225b9100aa37a9a9df3e14176dea5abcfbe8b26a79 Full 19-page available text read; PDF 7 and 16 visually inspected. Public FOI-associated custodian copy; marked draft; no underlying DSIT file comparison.
2026 oral hearing Exact parliamentary URL above; reader turn985view2 / turn987view1–4 Q25–30 plus institutional context Q7 read. Ordinary GET 403; no original retained and no retry.
2025 committee report / response Exact URLs above; report §§60–62; response metadata and relevant reply Primary reader text read; response ordinary GET 403. No original retained, no retry.
Parliamentary answers HL3811, HL7610, 9335 exact URLs above Complete question and answer text read through official reader.

The BBW PDF reader initially returned a one-line 'One moment, please...' page. One ordinary GET substitute succeeded with an actual PDF; no challenge solving or access-control evasion occurred. The prior Contracts Finder 403, ACNC restriction and other closed routes were not retried. Searches also surfaced unrelated MOD 'New Style of IT' records; these were excluded because the acronym denotes a different programme. Additional spending months were not opened or totalled. No WEF taxonomy specification, supplier-controlled censorship right or February 2025 invoice match was found in the inspected material.