PPN 03/22 – Updated guidance on data protection legislation · first published 30 November 2022
PPN 03/22 updates and replaces the previous data protection procurement guidance (PPN 02/18) to reflect changes in the UK data protection legal framework. It formally applies to central government departments, their Executive Agencies, and Non-Departmental Public Bodies (NDPBs). Other public bodies are encouraged to follow the same approaches but are not formally bound. For small businesses bidding on public contracts, this means data protection compliance requirements in contract terms and evaluation criteria may have been updated since the old 2018 guidance. Because only the summary text was available (not the full PDF), the specific contractual or evaluation changes cannot be detailed here — businesses should read the full document on GOV.UK.
WHO THIS APPLIES TO
THE ENKII VIEW
Data protection clauses are a common pass/fail gate in public contracts, so any update to the framework directly affects what SMEs must demonstrate when bidding. The replacement of PPN 02/18 signals that outdated compliance postures (e.g. references to pre-Brexit EU GDPR rather than UK GDPR) could now be a red flag to buyers. SMEs should treat this as a prompt to audit their data protection documentation and ensure it references the current UK legal framework.
1. Review and update your data protection documentation (e.g. Data Processing Agreements, privacy notices, Data Protection Impact Assessment templates) to ensure they reference the current UK data protection legal framework rather than pre-Brexit EU GDPR or the superseded PPN 02/18 requirements.
All SMEs bidding for central government contracts involving personal data — PPN 03/22 replaces PPN 02/18 to reflect changes in the UK data protection legal framework — buyers will now apply the updated standard when assessing suppliers.
2. Download and read the full PPN 03/22 PDF from GOV.UK to identify any specific new contractual clauses, evaluation criteria, or compliance requirements you will need to meet.
All SMEs bidding for central government contracts — Only the summary text was available for this brief — the full document likely contains specific obligations, model clauses, or thresholds that will affect your bid.
3. Check whether your buyer has adopted PPN 03/22 approaches voluntarily, as the note encourages wider public bodies to do so even though they are not formally bound.
SMEs bidding for wider public sector contracts (e.g. local authorities, NHS trusts) — The PPN states other public bodies 'may wish to apply the approaches set out in this note', meaning requirements could vary by buyer — confirm at pre-market engagement or tender stage.
Every rule below quotes the official document verbatim.
The PPN applies to all central government departments, their Executive Agencies, and Non-Departmental Public Bodies (NDPBs). (All central government departments, Executive Agencies, and NDPBs.)
“This note applies to all Central Government Departments, their Executive Agencies and Non Departmental Public Bodies.”
Other public bodies (e.g. local authorities, NHS) are not formally bound but are encouraged to apply the same approaches. (Wider public sector beyond central government.)
“Other public bodies will also be subject to the new Data Protection Legislation and may wish to apply the approaches set out in this note.”
PPN 03/22 updates and fully replaces the previous data protection procurement guidance, PPN 02/18. (All in-scope organisations previously following PPN 02/18.)
“This PPN updates and replaces PPN 02/18 and reflects changes to the data protection legal framework which impacts government procurement.”
This briefing is enkii's interpretation of the official document — the official text always governs.
Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.