Thirlwall's cot cam recommendations: Procurement and the supply chain
Following Lady Justice Thirlwall's recommendation that every neonatal cot and incubator in the NHS should be fitted with a live-streaming camera, the UK Government has committed to developing plans.
Health Secretary Yvette Cooper was swift in putting ‘cot cams’ at the heart of her response to the Thirlwall Report, which examined the circumstances in which Lucy Letby, a neonatal nurse at the Countess of Chester Hospital, was able to murder seven babies and attempt to murder six others between June 2015 and June 2016.
The precise policy hasn’t been set out in detail just yet, but with 200 neonatal units in the UK, this will be a large-scale technology project.
For NHS procurement teams and the suppliers bidding for these contracts, the legal and commercial questions are significant. Here is what you need to be thinking about now.
The fragmented procurement trap
When police forces across England and Wales began rolling out body-worn cameras in the 2010s following small-scale pilots, most went their own way. Forces procured different kit, from different suppliers, on different contractual terms, with different data standards. The result was a patchwork of incompatible systems that struggled to share footage across force boundaries – an operational problem that took years and considerable expense to address.
The Thirlwall Inquiry report's recommendation for centrally managed, ring-fenced funding makes sense for financial, legal and governance reasons. A national procurement framework, with standardised technical and contractual requirements, would help to ensure consistency, avoid duplication, and maintain coherent data governance at scale. In our view, NHS trusts should be pushing for that framework rather than going it alone.
The Procurement Act 2023 would apply in full
This kind of procurement wouldn't sit outside the usual rules. The Procurement Act 2023 would apply in full, bringing with it enhanced transparency obligations, stronger value for money requirements, and new rules on supplier exclusion and debarment.
Supplier due diligence would need to go further than price and technical specification. Procurement teams should be scrutinising data security credentials, any prior ICO enforcement action, and – critically – whether a supplier's infrastructure is UK-hosted or held overseas. Data transfers outside the UK carry distinct obligations under the UK General Data Protection Regulation (GDPR), and a supplier whose servers sit outside the UK creates a compliance problem that no contract clause can fully resolve after the fact.
Article 28: Not an afterthought
Under Article 28 of UK GDPR, any supplier processing personal data on behalf of an NHS trust must do so under a compliant data processing agreement. For cot cam suppliers, that means a detailed, legally robust contract covering, at minimum, the specific purposes for which footage can be processed, security obligations, sub-processor restrictions, breach notification timelines aligned with the trust's 72-hour Information Commissioner’s Office (ICO) reporting obligation, and the deletion or return of data at contract end.
These agreements are non-negotiable, and the ICO isn't sympathetic to trusts that treat them as a formality. For suppliers that haven't previously contracted with the NHS, the standard expected is high. Getting specialist advice before entering a competitive tender process, not during it, puts you in a materially stronger position.
Who owns the footage? Who owns what AI sees in it?
As AI analytics layers are added to camera systems – automated monitoring of a baby's condition, movement detection, early deterioration alerts – the insights generated from neonatal footage could become genuinely valuable data assets. Without a well-drafted IP assignment clause, those insights could vest in the supplier and be exploited commercially, with no return to the NHS. Procurement teams would need to address this explicitly in contract negotiations. Suppliers should expect it to come up and take legal advice on their position early.
A warning from the police body cam rollout
In 2025, the ICO reprimanded South Yorkshire Police after a significant volume of body-worn camera footage, including material relevant to a number of criminal cases, was accidentally deleted following a routine system upgrade. The root cause wasn't a cyberattack. It was inadequate backup policies, poor third-party data management, and the absence of clear escalation routes when problems first emerged years earlier.
A neonatal camera rollout, if poorly governed, could create similar risks at considerable scale. The footage lost might not be criminal evidence, but in a system already carrying significant neonatal clinical negligence liabilities, it could easily be the footage that determines the outcome of a claim.
Start the conversation now
The policy detail is still being developed. That is precisely why now is the right moment for procurement teams to help shape the framework rather than inherit it, and for suppliers to understand what NHS clients are likely to require before anyone is sitting across a negotiating table.
Our procurement and healthcare teams advise both NHS bodies and suppliers on all the issues a rollout like this would raise. Get in touch to talk through where you stand.