Definition

UK GDPR

The UK's data protection regime.

UK GDPR is the United Kingdom's data protection law, derived from the EU GDPR and sitting alongside the Data Protection Act 2018. Public sector tenders routinely require suppliers to confirm compliance and describe how personal data will be handled, particularly where the contract involves processing citizen or staff data.

Where it appears in a tender

Many ITTs include a data protection question or schedule asking bidders to describe their approach to data protection by design, data subject rights, breach notification, and international data transfers. Where the supplier will process personal data on the buyer's behalf, the contract will usually include a Data Processing Agreement setting out the supplier's obligations as a data processor.

This is a legally complex area, particularly where special category data (such as health or criminal records data) is involved, and suppliers with any doubt about their obligations should take specific advice from a data protection professional or the organisation's Data Protection Officer rather than relying on generic assurances.

What buyers commonly ask suppliers to evidence

  • A named Data Protection Officer or lead responsible for compliance
  • Data protection policies covering staff training, access controls and retention
  • A track record of data breach reporting procedures, including notification timescales
  • Certifications or standards relevant to information security, such as Cyber Essentials or ISO 27001

Frequently asked questions

Do all suppliers need a Data Protection Officer?
Only certain organisations are legally required to appoint one, generally public authorities and organisations carrying out large-scale monitoring or processing of special category data. Many suppliers instead nominate a data protection lead, which is usually acceptable if clearly described in the tender response.
What is the difference between a data controller and a data processor?
A controller decides the purposes and means of processing personal data, while a processor acts on the controller's instructions, typically the case for a supplier delivering a service using the buyer's data. The distinction affects legal responsibilities and should be clarified in the contract's Data Processing Agreement.
What happens if a supplier has a data breach during a public contract?
Contracts typically require immediate notification to the buyer, often within a specified short timescale, alongside the supplier's own obligations to notify the Information Commissioner's Office where required. Breach response processes should be tested in advance rather than worked out during an actual incident.

Related terms

Free tools for costing and planning your bid

See all free tender tools