Procurement Policy Note 02/18: Changes to Data Protection Legislation & General Data Protection Regulation · first published 18 May 2018
This Procurement Policy Note (PPN 02/18), published in May 2018, updates and replaces the earlier PPN 03/17. It guides central government buyers on how to handle changes to UK data protection law, including the General Data Protection Regulation (GDPR), which came into force in May 2018. It applies directly to central government departments, their Executive Agencies, and Non-Departmental Public Bodies (NDPBs), though other public bodies are encouraged to follow the same approach. For small businesses supplying public sector contracts, this signals that buyers will expect suppliers to be GDPR-compliant — contracts are likely to contain updated data protection clauses reflecting the new law. Because we only have the summary text and not the full document, the specific contractual requirements and obligations on suppliers are not confirmed here.
WHO THIS APPLIES TO
THE ENKII VIEW
GDPR compliance has become a baseline expectation for any supplier handling personal data on behalf of a public sector buyer — failing to demonstrate it is likely an exclusion risk. SMEs that process personal data as part of their service delivery should treat GDPR readiness as a bidding prerequisite, not an afterthought. Because the full document has not been parsed, the precise contractual clauses or supplier obligations are unknown — SMEs should obtain and read the full PDF directly from GOV.UK.
1. Confirm your business is GDPR-compliant and can evidence it — review your privacy notices, data processing agreements, and data security measures before bidding.
All SMEs supplying or bidding for central government contracts involving personal data — Central government buyers are required to follow this PPN, meaning contracts will reflect updated data protection law. Suppliers handling personal data will need to demonstrate compliance.
2. Download and read the full PPN 02/18 PDF from GOV.UK to identify the specific contractual clauses and supplier obligations buyers will apply.
All SMEs supplying central government — Only the summary text was available for this brief — the full document contains the detailed guidance and contract requirements that suppliers will be held to.
3. Discard your PPN 03/17 guidance and update your compliance approach to reflect PPN 02/18, which supersedes it.
SMEs previously aware of PPN 03/17 — PPN 02/18 explicitly updates and replaces PPN 03/17, meaning older guidance is no longer current.
Every rule below quotes the official document verbatim.
The PPN applies to all Central Government Departments, their Executive Agencies, and Non-Departmental Public Bodies (NDPBs). (All central government departments, Executive Agencies and NDPBs.)
“This note applies to all Central Government Departments, their Executive Agencies and Non Departmental Public Bodies.”
Other public bodies are not formally bound but are encouraged to apply the approaches set out in this note. (Wider public sector bodies (non-binding encouragement).)
“Other public bodies will also be subject to the new Data Protection Legislation and may wish to apply the approaches set out in this note.”
PPN 02/18 updates and replaces the earlier PPN 03/17 on data protection. (All in-scope organisations previously subject to PPN 03/17.)
“This PPN updates and replaces PPN 03/17. It contains enhanced guidance and clarifications on a number of key areas as set out in the document.”
This briefing is enkii's interpretation of the official document — the official text always governs.
Source document © Crown copyright, reused under the Open Government Licence v3.0 via the GOV.UK Content API. enkii tracks every Procurement Policy Note and briefs changes the day they land — see all briefings.