PPN 020: Guidance on data protection legislation · first published 24 April 2025
PPN 020 is the UK government's updated guidance on data protection requirements for public contracts. It replaces the previous PPN 03/22 and is published as part of the Procurement Act 2023 suite of policy notes. The document sets out mandatory contract clauses (at Annex A) that central government buyers must include in any contract where a supplier processes personal data on their behalf — which covers the vast majority of supplier relationships. As a supplier (processor), you have direct legal obligations under UK General Data Protection Regulation (UK GDPR), including your own exposure to fines from the Information Commissioner's Office (ICO) and civil claims from individuals. The policy also clarifies rules on sending personal data outside the UK, requiring a recognised legal gateway such as an adequacy decision or a UK International Data Transfer Agreement (IDTA). This is a guidance update, not a new policy change — but the clauses in new contracts awarded after April 2025 must use the refreshed Annex A wording.
WHO THIS APPLIES TO
THE ENKII VIEW
SMEs acting as processors face direct legal liability under UK GDPR — you can be fined by the ICO and sued by individuals independently of your buyer, so treating data protection as purely the buyer's problem is a compliance risk. The document explicitly states that buyers are advised not to routinely accept supplier price increases for compliance costs, meaning SMEs need to build data protection overhead into bids from the outset rather than negotiating it in later. The security annex (Annex B) signals that Cyber Essentials Plus and ISO 27001 certifications may be expected, giving already-certified SMEs a meaningful differentiator.
1. Check your current contract data protection clauses: if awarded before April 2025 under PPN 03/22, confirm they are still compliant; for any new bid or contract award, ensure the buyer's contract uses the PPN 020 Annex A clauses and that your internal processes can meet every obligation in them.
All SMEs bidding for or holding central government contracts involving personal data — The document states buyers must use updated Annex A clauses for all contracts awarded after PPN 020's issue date (April 2025), replacing PPN 03/22.
2. Price data protection compliance into your bids from day one — staff training, security tooling, breach notification processes — rather than seeking a price increase later.
All SMEs acting as processors on central government contracts — The PPN explicitly states: 'In-scope organisations are advised not to routinely accept contract price increases from suppliers as a result of work associated with compliance.' You are unlikely to recover these costs post-award.
3. Build and document a breach notification procedure so you can alert the buyer immediately on any data loss event or ICO communication — check it covers all triggers in Annex A clause 1.5.
All SMEs acting as processors on central government contracts — Annex A requires the processor to 'notify the Controller immediately' across a wide range of events including data loss, data subject requests and ICO contact — failure exposes you to direct ICO fines.
4. Confirm with your buyer whether your processing is 'occasional' or involves special category data — if not occasional, or if special/criminal-record data is involved, you must maintain full processing records even as a small firm.
SMEs with fewer than 250 employees processing personal data on central government contracts — The Annex A record-keeping exemption for sub-250-employee processors disappears if the controller determines processing is not occasional or involves Article 9/10 data.
5. Before engaging any sub-processor, get written consent from the buyer, sign a written sub-processing agreement that mirrors the Annex A obligations, and check you have flow-down clauses — then confirm your supply chain can meet Annex B security requirements.
SMEs using sub-contractors or cloud providers to deliver data processing on central government contracts — Clause 1.11 requires prior written Controller consent for sub-processors, and clause 1.12 makes you 'fully liable for all acts or omissions' of sub-processors.
6. Identify which legal gateway covers any non-UK data flows (adequacy decision or UK IDTA) and annex the IDTA to your contract for all arrangements concluded after 22 September 2022 — EU SCCs are no longer valid for post-September 2022 contracts.
SMEs processing or storing personal data outside the UK (including cloud hosting in non-UK regions) — 'For contracts concluded after 22 September 2022 you must use one of the two forms of IDTA' and EU SCCs expired as a valid gateway on 21 March 2024.
7. Obtain Cyber Essentials Plus and ISO 27001:2013 certifications if not already held, and reference them explicitly in bid responses referencing Annex B security expectations.
SMEs seeking to differentiate on security in central government bids — Annex B states: 'Buyers should ensure that Suppliers hold at least Cyber Essentials Plus certification and ISO 27001:2013 certification if proportionate to the service being procured' — holding these removes a potential evaluation risk.
8. Do not propose — and do not accept — liability clauses that cap or indemnify you against ICO regulatory fines; instead, negotiate a realistic separate data protection liability cap reflecting the risk profile of the data involved.
SMEs reviewing or negotiating liability terms on central government data contracts — The document states buyers 'should not accept liability clauses where processors are indemnified against fines or claims under UK GDPR' and lists a standalone £17.5m cap as one structural option — demonstrating awareness of this in negotiations shows commercial maturity.
Every rule below quotes the official document verbatim.
PPN 020 applies to all central government departments, their executive agencies and non-departmental public bodies (NDPBs), referred to as 'in-scope organisations'. (All central government departments, executive agencies and NDPBs — all contract values, all sectors.)
“This PPN applies to all central government departments, their executive agencies and non-departmental public bodies. Such bodies are referred to as 'in-scope organisations'.”
For contracts awarded after publication of PPN 020, buyers must use the updated data protection clauses at Annex A; the old PPN 03/22 clauses are superseded. (Central government contracts awarded after 24 April 2025 involving personal data processing.)
“For contracts to be awarded after the issue of this PPN, in-scope organisations should use the updated clauses at Annex A to this PPN.”
In most public sector contracts the buyer is the data controller and the supplier is the data processor — the Annex A clauses govern that controller-processor relationship. (All central government contracts involving personal data processing.)
“In most cases in public sector contracts, the public body letting a contract or calling-off from a framework agreement will be the controller, and the supplier will be the processor.”
Processors (suppliers) have direct legal obligations under UK GDPR and can be fined by the ICO and face private compensation claims independently. (All suppliers acting as processors on central government contracts.)
“Under the UK GDPR, processors have direct legal obligations to comply with data protection law, and they can be fined by the ICO. Both controllers and processors can also face private claims for compensation where they have not complied with their obligations under UK GDPR.”
Buyers are advised not to routinely accept supplier price increases for data protection compliance costs. (All central government contracts involving personal data processing.)
“In-scope organisations are advised not to routinely accept contract price increases from suppliers as a result of work associated with compliance but should apply commercial judgement in individual discussions on this with suppliers.”
Buyers must not accept liability clauses that indemnify suppliers (processors) against ICO fines or data subject compensation claims. (All central government contracts involving personal data processing.)
“In-scope organisations should not accept liability clauses where processors are indemnified against fines or claims under UK GDPR.”
One liability cap option available to buyers is a separate £17.5 million cap specifically for regulatory fines arising from data protection breach. (Central government contracts — buyer's choice of liability structure where data protection breach risk exists.)
“introducing a separate £17.5 million cap on liability for regulatory fines arising out of data protection breach”
Processors must implement appropriate technical and organisational 'Protective Measures'; buyers may reject measures they consider insufficient and require alternatives. (All suppliers acting as processors on central government contracts.)
“processors must implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk and these are defined as 'protective measures' within Annex A.”
Suppliers must not transfer personal data outside the UK without the buyer's prior written consent and a recognised legal gateway (e.g. adequacy decision or UK IDTA). (All central government contracts where personal data may be processed or stored outside the UK.)
“Article 44 of UK GDPR prohibits the off-shoring of personal data outside the UK unless a legal gateway is in place.”
For contracts concluded after 22 September 2022, suppliers must use one of the two forms of the UK International Data Transfer Agreement (IDTA) for international data transfers; reliance on old EU Standard Contractual Clauses (SCCs) ended on 21 March 2024. (All central government contracts involving transfer of personal data outside the UK.)
“For contracts concluded after 22 September 2022 you must use one of the two forms of IDTA. For existing contracts or those concluded on or before 21 September 2022 you may have continued to rely on the EU SCCs, but only until 21 March 2024.”
Suppliers must notify the buyer immediately upon becoming aware of a data loss event, receiving a data subject request, or receiving any communication from the ICO relating to data processed under the contract. (All suppliers acting as processors on central government contracts (Annex A clause 1.5).)
“The Processor shall notify the Controller immediately if it: receives a Data Subject Request (or purported Data Subject Request)... becomes aware of a Data Loss Event.”
The record-keeping obligation in Annex A does not apply to processors with fewer than 250 staff unless the processing is not occasional, involves special category or criminal conviction data, or is likely to risk data subjects' rights. (Processors with fewer than 250 employees on central government contracts.)
“This requirement does not apply where the Processor employs fewer than 250 staff, unless: a) the Controller determines that the processing is not occasional; b) the Controller determines the processing includes special categories of data as referred to in Article 9(1) of the UK GDPR or Personal Data relating to criminal convictions and offences referred to in Article 10 of the UK GDPR; or c) the Controller determines that the processing is likely to result in a risk to the rights and freedoms of Data Subjects.”
Annex B indicates that buyers should consider requiring suppliers to hold at least Cyber Essentials Plus and ISO 27001:2013 certification where proportionate to the service. (Suppliers processing personal data on central government contracts — security schedule guidance.)
“Buyers should ensure that Suppliers hold at least Cyber Essentials Plus certification and ISO 27001:2013 certification if proportionate to the service being procured.”
Suppliers must obtain the buyer's prior written consent and enter a written sub-processor agreement before allowing any third party to process personal data under the contract. (All suppliers acting as processors who use sub-contractors or sub-processors on central government contracts.)
“Before allowing any Sub-processor to process any Personal Data related to this Agreement, the Processor must: a) notify the Controller in writing of the intended Sub-processor and processing; b) obtain the written consent of the Controller; c) enter into a written agreement with the Sub-processor which give effect to the terms set out in this clause.”
Suppliers remain fully liable for all acts or omissions of any sub-processors they appoint. (All suppliers acting as processors on central government contracts.)
“The Processor shall remain fully liable for all acts or omissions of any of its Sub-processors.”
This briefing is enkii's interpretation of the official document — the official text always governs.
Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.