Shared IT Services should not mean merging the data of multiple Councils
A shared IT Service for multiple Councils should mean combined teams for the service desk functions (incidents and service requests) and for specific service areas (network, security, server, desktop, mobile device management, development and test, project management, change management …),
This should not imply that the data / storage is also all mushed together such that an intrusion in one Council affects all of them.
Presume things should be setup as multi-tenant with horizontal isolation, and that data is only exchanged between Councils where legal, appropriate and authorised.
But perhaps the { service desk | database | communications } system within the IT service is what's affected.