LIVE · UK MARKET INDEXED
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
NEWNHS Mersey · Compliance audit Q2 2026·£85k·Manchester
GRANTInnovate UK · SME R&D·£250k·UK-wide
NEWTfL · Cybersecurity SOC·£1.2M·London
INVMercia · Series A · ClimateTech·£3M·Birmingham
CORPBarclays · Diverse supplier programme·Invite·Nationwide
NEWCardiff CC · Schools refurbishment·£420k·Wales
GRANTHorizon EU · Energy transition·€800k·EU
NEWManchester CC · Social housing fire doors·£240k·Manchester
CORPKPMG · Digital procurement partner·£600k·UK
INVNorthwest Growth · Seed fund·£500k·NW England
NEWFind a Tender · Rail signalling·£3.6M·Frankfurt
NEWGovTech Singapore · Public services·SGD 1.1M·Singapore
PPN 02/18 · UPDATED 18 MAY 2018

Central government departments must update contracts and supplier arrangements to comply with the new UK data protection legislation and the General Data Protection Regulation (GDPR).

Procurement Policy Note 02/18: Changes to Data Protection Legislation & General Data Protection Regulation · first published 18 May 2018

What it says, in plain English

This Procurement Policy Note (PPN 02/18), published in May 2018, updates and replaces the earlier PPN 03/17. It guides central government buyers on how to handle changes to UK data protection law, including the General Data Protection Regulation (GDPR), which came into force in May 2018. It applies directly to central government departments, their Executive Agencies, and Non-Departmental Public Bodies (NDPBs), though other public bodies are encouraged to follow the same approach. For small businesses supplying public sector contracts, this signals that buyers will expect suppliers to be GDPR-compliant — contracts are likely to contain updated data protection clauses reflecting the new law. Because we only have the summary text and not the full document, the specific contractual requirements and obligations on suppliers are not confirmed here.

WHO THIS APPLIES TO

Who it binds
Central government buyers
Contract values
any value
Applies from
18 May 2018
Sectors
All sectors where suppliers handle personal data on behalf of public sector buyers.

THE ENKII VIEW

GDPR compliance has become a baseline expectation for any supplier handling personal data on behalf of a public sector buyer — failing to demonstrate it is likely an exclusion risk. SMEs that process personal data as part of their service delivery should treat GDPR readiness as a bidding prerequisite, not an afterthought. Because the full document has not been parsed, the precise contractual clauses or supplier obligations are unknown — SMEs should obtain and read the full PDF directly from GOV.UK.

What a small business should do about it

1. Confirm your business is GDPR-compliant and can evidence it — review your privacy notices, data processing agreements, and data security measures before bidding.

All SMEs supplying or bidding for central government contracts involving personal dataCentral government buyers are required to follow this PPN, meaning contracts will reflect updated data protection law. Suppliers handling personal data will need to demonstrate compliance.

2. Download and read the full PPN 02/18 PDF from GOV.UK to identify the specific contractual clauses and supplier obligations buyers will apply.

All SMEs supplying central governmentOnly the summary text was available for this brief — the full document contains the detailed guidance and contract requirements that suppliers will be held to.

3. Discard your PPN 03/17 guidance and update your compliance approach to reflect PPN 02/18, which supersedes it.

SMEs previously aware of PPN 03/17PPN 02/18 explicitly updates and replaces PPN 03/17, meaning older guidance is no longer current.

The rules, anchored to the text

Every rule below quotes the official document verbatim.

The PPN applies to all Central Government Departments, their Executive Agencies, and Non-Departmental Public Bodies (NDPBs). (All central government departments, Executive Agencies and NDPBs.)

This note applies to all Central Government Departments, their Executive Agencies and Non Departmental Public Bodies.

Other public bodies are not formally bound but are encouraged to apply the approaches set out in this note. (Wider public sector bodies (non-binding encouragement).)

Other public bodies will also be subject to the new Data Protection Legislation and may wish to apply the approaches set out in this note.

PPN 02/18 updates and replaces the earlier PPN 03/17 on data protection. (All in-scope organisations previously subject to PPN 03/17.)

This PPN updates and replaces PPN 03/17. It contains enhanced guidance and clarifications on a number of key areas as set out in the document.

This briefing is enkii's interpretation of the official document — the official text always governs.

Official document on GOV.UK

Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.