Live tenders / Yorkshire Purchasing Organisation
Digital Marketplace
What the buyer is asking for
YPO are looking for a Provider to be appointed onto a Framework Agreement for the provision of a Digital Marketplace. The Framework is designed to meet the needs of all public sector organisations which includes YPO’s internal requirements. This Framework is designed to meet the needs of YPO and Other Contracting Authorities by establishing an agreement where the end customer will place the order via the Provider’s digital marketplace to purchase goods with the resultant order being delivered directly to the end customer.
How this is scored
Published by the buyer. A winning response is written to these weightings, not to the question.
- 20%qualityCost
- 20%qualityDigital Platform
- 20%qualityPolicies and Procedure
- 20%qualityContinuous Improvement and Innovation
- 20%qualitySocial Value
What you must already have
Conditions of participation. These are pass or fail, so check them before writing anything.
- economic
• GDPR: UK General Data Protection Regulation and the Data Protection Act 2018. Data, cyber security, and cloud services must be compliant with the UK GDPR. It is expected that all products and services provided within the remit of this Framework and any Call-off Contract have sufficient security measures in place to ensure the security of this data for the extent of its lifecycle, including safe disposal, archiving and back-up systems. • FOI: Freedom of Information Act 2000 – YPO and our permissible users as public bodies are covered by the Freedom of Information Act 2000 which provides access to information held by public authorities. The Provider may be required to support YPO, and/or the customer in providing data to respond to these requirements within the legal time frames. Further information, including exclusions is available from the Information Commissioners Office (ICO) online. • All products supplied under this Framework must comply with relevant legislation and harmonized standards, including the General Product Safety Regulation and the UK REACH Regulation suite where applicable. • Ensure the relevant consents are gained in writing before acquiring or sharing sensitive personal data in compliance with UK GDPR 2018. Recommend a focus on GDPR and data security type questions (covering, all aspects of data handling such as storage, accuracy and deletion) • Evidence of customer care procedures, including the handling of customer complaints. • All suppliers should comply with existing YPO security standards which are driven by ISO2700[SR3.1]1 • Business continuity management and disaster recovery policies and procedures - such as in the event of a cyber-attack. • UK GDPR and Data Protection Act 2018 compliant - Compliance with all UK data protection legislation including the UK General Data Protection Regulation and the Data Protection Act 2018 and applicable amends following the UK withdrawal from the EU. Where personal data is transferred between countries, applicable legislations must be adhered to, and security maintained. Electronic Management Systems (if applicable): • Should be compliant with storage requirements for personal sensitive data and be in compliance with UK GDPR. It is expected that this system would have sufficient firewalls and/or other security measures in place to ensure the security of this data for the extent of its lifecycle, including safe disposal. This might include certification to the Cyber Essentials Scheme. https://www.gov.uk/government/publications/cyber-essentials-scheme-overview Data and cyber security and cloud services: • May require data transfer agreements etc., dependent on location of storage and whether there is any outsourcing. If stored or transferred outside of the UK, this should be compliant with storage requirements for and comply with UK GDPR. It is expected that this system would have sufficient firewalls and/or other security measures in place to ensure the security of this potentially sensitive data for the extent of its lifecycle, including safe disposal, archiving and back-up systems. Standards & Accreditations • ISO 9001 certification or evidence of an equivalent Quality Management System. • ISO 27001 certification or evidence of an equivalent data security management system. • ISO 14001 certification or evidence of an equivalent environmental management system. • ISO 45001 certification or evidence of an equivalent health and safety management system. Legislative requirements The Provider shall work in accordance with current and relevant industry quality and environment standards and have in place such policies, systems and processes. All goods and services provided within this Framework and any Call-off Contract must conform and comply to all relevant and/or equivalent up to date UK industry legislation and harmonised standards as a minimum including any recent or ongoing standards that are currently in the process of being updated. This includes, but is not limited to, the following legislation. • UK GDPR and Data Protection Act 2018 • Freedom of Information Act 2000 • Privacy and Electronic Communications Regulations (PECR) • Modern Slavery Act 2015 • UK Bribery Act 2010 • Equality Act 2010. • Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018 (where applicable) • Web Content Accessibility Guidelines (WCAG) WCAG 2.2 (where applicable) • Compliance with all current and applicable legislation must be maintained by the supplier for the duration of the contract. • All products must be traceable via batch number and must display expiry date where this applies to the product type. Financial - Must have an Experian Business Credit score of 51 or higher.
- technical
Must be ablo to meet product specifcation as outnlined in "Tender Particulars - Digital Marketplace".
- Value
- £500,000,000
- Submission deadline
- 04 Nov 2026, 14:00 GMT (33 days left)
- Enquiry deadline
- 28 Oct 2026, 14:00 GMT
- Award decision expected by
- 09 Dec 2026, 23:59 GMT
- Contract start
- Not stated
- Contract end
- Not stated
- Category
- services
- Lots
- 1
- Procedure
- Open procedure
- CPV codes
- 66151100
- Legal basis
- 2023/54
How contested is this?
Buyers publish how many bids they received. Across 78 comparable procurements we can tell you the typical field size, how often one of these goes uncontested, and whether the buyer awards on price or on quality.
Timeline
4 published dates · Europe/London
- Tender notice publishedyesterday30 Sept 2026, 15:03 BST
- Clarification questions byin 27 days28 Oct 2026, 14:00 GMT
- Submission deadlinein 34 days4 Nov 2026, 14:00 GMT
- Award decision expected byin 69 days9 Dec 2026, 23:59 GMT
Commercial outcome and contract awards
Nothing awarded yet
Awards (0)
No award published
Contracts (0)
No contract published
Bid statistics
No aggregate bid statistics published
Notice history
3 events · 3 releases on Find a Tender
- Pipeline or early engagement notice24 Apr 2026, 10:54 BST037457-2026
- Tender notice30 Sept 2026, 10:37 BST092214-2026
- Tender updated30 Sept 2026, 15:03 BST092463-2026
Documents
How to bid
https://ypo2.my.site.com/s/Welcome
Submission happens on the buyer's own portal, which needs an account with them. We never handle your portal credentials.