eSourcingData - Source-to-Contract Procurement Software
PA2311 August 2026 · 9 min read · The eSourcing Data team

The data protection clauses in your contracts are not boilerplate. They decide who pays.

Data protection clauses are the part of the contract everyone skips. They arrive as a standard annex, they look like legal wallpaper, and they get signed unread. Then a supplier loses a laptop, or a sub-processor in another jurisdiction turns out to be training something on your citizens' records, and suddenly those clauses are the only thing standing between your organisation and the bill. PPN 020 exists because Parliament made these clauses a legal requirement, not a drafting preference, and because the details, liability caps, transfer gateways, expired contracts, are where public bodies actually get hurt.

Article 28 made procurement a data protection function

Here is the fact that reframes the whole subject: where your supplier processes personal data on your behalf, having a contract with specific data protection clauses is a legal obligation under Article 28 UK GDPR. Not best practice. Not a policy preference. A missing or defective clause set is itself a breach, before a single record is mishandled. PPN 020 supplies the required clauses at Annex A precisely so no public body has to draft them from scratch.

The clauses only bite if the roles are right. In most public contracts the buyer is the controller, deciding why and how data is processed, and the supplier is the processor, acting on instructions. But the analysis has to be done, not assumed. A supplier that determines purposes of its own is a controller, and the standard clauses are the wrong tool. The processing schedule matters just as much: the processor is only authorised to do what it describes, so a lazy schedule is an open-ended authorisation you never meant to give.

The liability clause nobody reads until the breach

The sharpest commercial guidance in PPN 020 is about indemnities. Suppliers will sometimes ask to be indemnified against ICO fines or data subject claims, folding their regulatory risk back onto you. The PPN says do not accept it. The penalty regime was deliberately extended to processors so they would have skin in the game; an indemnity quietly reverses Parliament's intent at your expense.

The other side of the coin is whether your caps let you recover when the processor is at fault. A general liability cap sized for service credits can be swallowed whole by a serious breach. The PPN's options are practical: exclude data protection breaches from the general cap, raise the cap, give data protection its own cap, or introduce a separate £17.5 million cap for regulatory fines arising from a breach. Which one fits depends on the data and the risk appetite, but the default of leaving the standard cap untouched is a decision too, and usually the worst one.

Offshoring: always ask which gateway

Every contract where data might leave the UK should be able to answer one question: what is the legal gateway? Article 44 prohibits transfers without one. Adequacy decisions cover the EU and EEA and a modest list of other countries, plus US companies registered under the Data Privacy Framework extension. For everywhere else, the UK International Data Transfer Agreement does the work, either stand-alone or as an addendum to the EU clauses, and it has been mandatory for new contracts concluded after 22 September 2022.

The history explains the caution. The Schrems 2 judgment struck down a whole adequacy arrangement with the US and told controllers that even standard clauses may need supplementing in risky jurisdictions. The ICO now expects transfer risk to be assessed, looking at surveillance laws, courts and enforcement in the destination. In practice: find where the data actually sits, including disaster recovery copies and sub-processors, and get your data protection team involved before the contract is signed, not after.

The expired contract trap

The most overlooked paragraph in PPN 020 concerns contracts that have ended while the supplier still holds the data. Storage is processing. Processing without a contract is a breach, and keeping data that is no longer necessary breaches the processing principles on top. Every procurement function has these ghosts: a decommissioned system whose backups sit with the old supplier, a service that changed hands with data never returned.

The remedy is unglamorous: an interim contract if terms have not survived, then immediate return or deletion of anything no longer needed. The prevention is better: make data return and destruction a tracked contract management milestone, not a hope. If your contract records cannot tell you today which expired contracts still have live data, that is the audit finding waiting to happen.

The takeaways

  • Processor contracts with the Article 28 clauses are a legal requirement, and the Annex A clauses exist so you never draft from scratch.
  • Never indemnify processors against ICO fines; fix your caps so a real breach is recoverable.
  • Every offshore transfer needs a named legal gateway, and post-September 2022 contracts need the IDTA where adequacy does not apply.
  • The processing schedule defines what the supplier may do: write it precisely.
  • Track data return and destruction at contract expiry, because stored data without a contract is a live breach.

Want the full breakdown?

The complete explainer covers the key facts, the requirements in detail and a practical action list, free and printable in the Procurement Library.

Browse the Procurement Library →All articles