When our small unit ran its first proper inventory of digital tools, the official register said we used six. The credit-card statements and procurement records said nineteen. The gap between those two numbers is a story every small public-sector team in Europe will recognise.
Nobody plans SaaS sprawl. It arrives one reasonable decision at a time: a survey tool for one consultation exercise, a diagramming app someone needed for a workshop, a transcription service bought during a deadline week. Each purchase made sense. Together they added up to a shadow inventory of tools nobody owned, nobody reviewed, and — this is the part that should worry a public body — nobody had assessed for data protection.
Why this is worse for public bodies than for startups
A startup with tool sprawl wastes money. A public-sector team with tool sprawl has a compliance problem:
- GDPR roles were never assigned. Half our unregistered tools processed personal data — participant names in survey tools, voices in transcription services — with no data processing agreement in place and no entry in the processing register.
- Data residency was unknown. For several tools, nobody could say whether data was stored inside the EU. For a team whose whole mandate touches public-sector information, that’s an uncomfortable admission.
- Knowledge was locked in personal accounts. Two colleagues had left in the previous year. Their workshop boards and survey results lived in accounts nobody could access anymore. Public information, effectively lost to the public body that produced it.
The inventory method that actually worked
Asking people “what tools do you use?” produced the same incomplete answers as always. What worked was triangulating three boring sources:
- Finance records — every recurring payment and every one-off software purchase over 24 months, however small.
- The email domain — IT searched for registration and invoice emails arriving at our domain. This found the free-tier accounts that finance never sees.
- Browser SSO grants — the list of third-party services connected to our organisational accounts. The longest and most surprising list of the three.
Every tool went into a single register with four fields: what it does, who owns it, what data goes into it, and where that data physically sits.
The keep / migrate / kill triage
We scored each tool against three questions. Does it process personal data? Is there an existing approved tool that does the same job? Would we lose anything permanent if it disappeared tomorrow?
The outcome surprised us:
- Seven tools were killed outright. Most were barely used. Cancelling them funded the licences we actually needed.
- Five were migrated into two approved platforms. The painful discovery: exporting data out of “easy” tools is rarely easy. One popular workshop tool exports boards only as flat images — years of structured input reduced to pixels.
- Seven were kept and legalised: processing agreements signed, entries added to the register, ownership assigned to a named person rather than “the team”.
The rule that keeps it clean
Inventories decay. What keeps ours honest is one lightweight rule: any new tool, free or paid, needs a two-line entry in the register and a named owner before first use. Not a procurement process — literally two lines and a name. Low enough friction that people comply, enough structure that the shadow inventory can’t rebuild itself.
Twice a year, the register gets a 30-minute review: is every tool still used, still owned, still compliant? Tools whose owner has left the organisation get reassigned or retired on the spot.
What we’d tell other small teams
The lesson wasn’t about money, although we now spend about a third less on tools. It was that in a public body, every unregistered tool is a small hole in your accountability. Citizens’ data, consultation responses, even internal drafts — public-sector information deserves to be traceable, exportable and properly held. You can’t share what you’ve lost track of.
Start with the finance records and the SSO grants. The rest follows.