eSourcingData - Source-to-Contract Procurement Software

Procurement Policy Note · explained by eSourcing Data

Data protection clauses in public contracts: PPN 020 explained

PPN 020 explained: the data protection clauses public contracts must include, controller and processor duties, liability caps and overseas transfers.

Central government commercial and procurement teamsData protection officers and information assurance leadsContract managers overseeing suppliers that process personal dataSuppliers acting as processors on public contracts9 min read

Source document: Procurement Policy Note 020: Guidance on data protection legislation

The key facts

  • PPN 020 replaces PPN 03/22 as part of the Procurement Act 2023 suite of republished PPNs. PPN 03/22 had itself replaced PPN 02/18 following the UK's exit from the EU.
  • It applies to all central government departments, their executive agencies and non-departmental public bodies, with immediate effect. It was previously issued in November 2022 and updated in April 2025.
  • The primary UK data protection framework is the UK GDPR, which must be read alongside the Data Protection Act 2018.
  • Where a supplier processes personal data on the buyer's behalf, Article 28 UK GDPR makes it a legal obligation to have a contract containing specific data protection clauses. The PPN provides the required clauses at Annex A.
  • In the vast majority of public sector contracts the buyer is the controller and the supplier is the processor. Joint or independent controller situations need specialist advice and different provisions.
  • Buyers should not accept clauses that indemnify processors against ICO fines or data protection claims. Options include a separate £17.5 million liability cap for regulatory fines arising from data protection breach.
  • Article 44 UK GDPR prohibits transferring personal data outside the UK without a legal gateway, such as an adequacy decision or the UK International Data Transfer Agreement. Contracts concluded after 22 September 2022 must use one of the two forms of IDTA.
  • Personal data still held by a supplier after a contract has expired is being processed in breach of the legal requirement for a contract, and an interim contract with immediate return or deletion is likely to be needed.

What PPN 020 is and who it applies to

PPN 020 covers data protection requirements under UK GDPR and the UK International Data Transfer Agreement, which governs the export of personal data from the UK. It replaces PPN 03/22 as part of the Procurement Act 2023 suite of republished PPNs; PPN 03/22 had in turn replaced PPN 02/18, streamlining the guidance and updating the legal clauses after the UK's exit from the EU.

The note applies to all central government departments, their executive agencies and non-departmental public bodies, with immediate effect. In-scope organisations are asked to circulate it widely and to work closely with their data protection and information assurance leads on implementation. The update does not change policy: organisations that applied the earlier clauses do not need to repeat completed actions, but ongoing obligations continue.

The core action is contractual. Organisations should already have identified existing contracts involving personal data and included the clauses from earlier PPNs. For contracts awarded after this PPN was issued, the updated clauses at Annex A should be used, and buyers should ensure that call-off contracts under wider agreements are suitably covered as well.

Controllers, processors and the mandatory clauses

UK GDPR applies to controllers and processors, and the distinction drives everything else. A controller determines the purposes and means of processing: it makes the key decisions, usually decides to collect the data in the first place, and settles the legal basis, retention and sharing. A processor processes personal data on the controller's behalf, under its instructions, with no interest of its own in the data. In the vast majority of public sector buyer and supplier relationships, the public body is the controller and the supplier is the processor.

Where the supplier is a processor, Article 28 UK GDPR imposes a legal obligation to have a contract containing specific data protection clauses. Part 2 of Annex A to the PPN contains the clauses required by law. They oblige the processor to process only as instructed in the processing schedule, maintain protective measures, control and train its personnel, notify the controller immediately of data subject requests, regulator contact or any data loss event, assist with data protection impact assessments, allow audits, and obtain written consent before appointing any sub-processor, for whose acts it remains fully liable.

Two special cases are worth knowing. Where one Crown department processes for another, the Crown cannot contract with itself, so section 209(3) of the Data Protection Act 2018 allows a memorandum of understanding containing the Annex A clauses instead. And in the limited situations where a supplier is a joint controller or a controller in its own right, the standard clauses are unlikely to be appropriate: the PPN directs buyers to their data protection team or data protection officer for bespoke provisions.

Liability, fines and the cost of getting it wrong

Non-compliance is not theoretical. Organisations that fail to comply with data protection law risk fines or enforcement orders from the Information Commissioner's Office, and under UK GDPR processors carry direct legal obligations and can be fined in their own right. Both controllers and processors can also face private compensation claims from data subjects.

That is why the PPN takes a firm line on liability drafting. Buyers should not accept clauses that indemnify processors against ICO fines or claims: the penalty regime was extended to processors precisely to sharpen their performance, and a full indemnity undermines it. Instead, buyers should review liability and indemnity provisions contract by contract, considering options such as excluding data protection breaches from the general liability cap, increasing the general cap, applying a separate cap for data protection breaches, or introducing a separate £17.5 million cap for regulatory fines arising from a breach.

On costs, suppliers are expected to manage their own compliance costs. The PPN advises buyers not to routinely accept price increases attributed to data protection compliance, applying commercial judgement in individual discussions.

Sending personal data outside the UK

Article 44 UK GDPR prohibits offshoring personal data outside the UK unless a legal gateway is in place. The gateways include an adequacy decision by the UK government for the destination country, standard contractual clauses or the UK International Data Transfer Agreement, binding corporate rules within a corporate group, a legally binding instrument between public authorities, and approved codes of conduct or certification mechanisms. If a contract involves offshoring, the buyer must identify which gateway the supplier is relying on.

Adequacy covers the easy cases. The UK has declared the EU and EEA adequate, and the EU has reciprocated, so data flows freely in both directions. A UK Extension to the EU-US Data Privacy Framework provides partial adequacy for US companies registered under that framework, and the UK has provisionally recognised countries the EU considers adequate, including New Zealand, Israel, Switzerland and Argentina, with limited decisions for Japan and Canada.

Everywhere else needs contractual protection. The International Data Transfer Agreement, commenced on 21 March 2022, is the UK's version of standard contractual clauses and comes in two forms: a stand-alone agreement, and an addendum that plugs into the EU clauses where data leaves both the UK and the EU. For contracts concluded after 22 September 2022, one of the two forms of IDTA must be used; transitional reliance on the old EU clauses ended on 21 March 2024. Following the Schrems 2 judgment, which struck down the US Privacy Shield, the ICO also asks controllers to assess risk factors in non-adequate destinations, including surveillance laws and the legal system, before transferring; the PPN advises consulting your data protection team for these assessments.

Practical application: schedules, security and edge cases

The clauses only work if the processing schedule behind them is completed properly. Annex A includes a schedule, completed by the controller, describing the subject matter, duration, nature and purposes of processing, the types of personal data, the categories of data subject, any international transfers and their legal gateway, and the plan for return or destruction of the data. Vague schedules weaken the controller's position, because the processor is only authorised to do what the schedule describes.

Processors must also implement protective measures: appropriate technical and organisational security under Article 28(3)(c), which the controller may reject as insufficient. The PPN suggests security schedules for contracts involving personal data, and Annex B offers examples, from certifications such as Cyber Essentials Plus and ISO 27001 where proportionate, through encryption, penetration testing and personnel vetting, to audit logging and secure data destruction.

Two edge cases deserve attention. Where personal data is still held by a supplier after contract expiry, that processing is in breach of the requirement for a contract, and an interim contract is likely to be needed while the data is returned or deleted. And where processing is for law enforcement purposes under Part 3 of the Data Protection Act 2018, the generic clauses are compliant but more specific drafting may be needed to flow obligations down to processors, with legal advice.

How eSourcing Data helps

PPN 020 is ultimately about knowing which contracts involve personal data and proving the right clauses are in them. eSourcing Data gives procurement teams a structured record of every contract and call-off, so data processing contracts can be identified, the presence of current clauses evidenced, and reviews tracked rather than rediscovered at renewal.

The platform's audit trail supports the judgement calls the PPN requires: recording the controller and processor analysis, the liability approach taken on each contract, and the legal gateway relied on for any offshore processing. When the ICO or an internal review asks why a position was taken, the reasoning is on the record.

Contract and supplier management workflows also help with the lifecycle risks the PPN highlights: expiry dates and data return obligations can be tracked against each supplier, reducing the chance of personal data quietly outliving its contract.

What to do about it

  1. 1Identify every contract and call-off involving personal data processing and confirm it contains the current clauses from Annex A of the PPN.
  2. 2Complete the processing schedule properly for each new contract: data types, data subjects, duration, transfers and the plan for return or destruction.
  3. 3Map the controller and processor relationship at planning stage, and take specialist advice wherever a supplier may be a joint or independent controller.
  4. 4Review liability provisions contract by contract and refuse clauses that indemnify processors against ICO fines or data subject claims.
  5. 5Identify the legal gateway for any processing outside the UK, and use the IDTA for contracts concluded after 22 September 2022 where no adequacy decision applies.
  6. 6Sweep expired contracts where suppliers may still hold personal data, put interim terms in place and secure prompt return or deletion.
  7. 7Apply a proportionate security schedule to contracts involving personal data, using the Annex B examples as a starting point.

Put this into practice on the platform

eSourcing Data runs compliant notices, evaluation, supplier management and audit trails out of the box, so meeting this guidance is the workflow, not extra work.

Read our take on the blog →Back to the Procurement Library

This explainer summarises and interprets an official document for general information; it is not legal advice. Contains public sector information licensed under the Open Government Licence v3.0. Nothing here implies endorsement of eSourcing Data by any government body.

All documents