Empowering Your Business with a Comprehensive Data Security and Protection Toolkit

DSPT Support from our Expert Team

Understanding the Data Security and Protection Toolkit

The Data Security and Protection Toolkit (DSPT) is an online self-assessment toolkit that any public or private organisation with access to NHS patient data or systems in England must complete. This includes care providers, GP practices, social care organisations, and third party suppliers.

Meeting the DSPT’s requirements and providing the necessary evidence can be complex and time-consuming. However, for organisations required to complete the DSPT, it is a legal obligation and must not be overlooked. For this reason, it’s essential that you assess your current status against the DSPT criteria as early as possible. Doing so gives you the maximum amount of time necessary to address any gaps and risks to ensure you remain compliant.

Cases of data breaches, cyberattacks, and regulatory fines are on the rise, and Given the sensitive nature of the data your organisation most likely processes, even a small breach could lead to serious issues, both for you and your data subjects.

 

Why Choose Privacy Helper for Support on your DSPT Submission?

Privacy Helper can provide comprehensive, support to organisation for your DSPT submission that’s tailor made to suit the needs of your organisation.

Completing the DSPT can be zero-fuss with support from Privacy Helper. Our independent, expert guidance helps ensure your submission is accurate, complete, and aligned with current requirements, saving you time and reducing stress. We’ll also help you implement any necessary changes required as a result of this task, which will be designed to integrate within your existing operations.

Let us handle the heavy lifting, so you and your team can stay focused on running your services, knowing your data protection obligations are being met with confidence. Independent support also brings a fresh, objective perspective, helping identify potential gaps or risks that may otherwise be overlooked.

Get a privacy consultation

Contact usCall us




Is my organisation required to complete the DSPT?


Any organisation that accesses, processes, stores, or shares NHS patient data must complete the Data Security and Protection Toolkit (DSPT). This includes those connecting to NHS systems such as NHSmail or the Summary Care Record.

It’s mainly organisations such as hospitals, GP surgeries, and other health and care providers delivering services on behalf of the NHS that are required to complete the DSPT to demonstrate they meet national data security and protection standards.

Additionally, third-party suppliers, such as IT providers or data processors, must also complete the DSPT if they handle NHS patient data or support services involving access to NHS systems.



How often must the DSPT be completed?


The Data Security and Protection Toolkit must be completed and published annually. The deadline for submission is typically on the 30th June every year, including this year.



How long does a DSPT submission usually take?


The time it takes to complete a DSPT submission can vary depending on the size of your organisation, how much documentation you already have in place, and whether you’ve completed the DSPT before. For organisations new to the process, it can take a few weeks to gather the necessary evidence and work through each section of the toolkit.

With Privacy Helper’s support, we aim to make the process as efficient and straightforward as possible. We’ll begin by assessing where you currently stand and then guide you through what’s needed to meet the required standards. If much of your documentation is already in place, the submission can often be completed in a matter of days.

Throughout the process, we’ll keep you informed with regular updates. You’ll know what stage we’re at, what’s left to complete, and where we might need your input. We aim to give you the confidence that this process is in the right hands, and part of that includes keeping you in the loop.


 

Does the DSPT need updating if something changes?


In cases where significant changes occur within your organisation, you may decide that your DSPT submission should be reviewed and updated to reflect that. While not mandatory outside of the annual submission, keeping the DSPT up-to-date can help demonstrate accountability and commitment to a high standard of data protection practices.

Privacy Helper can help you identify which parts need updating and guide you through any necessary revisions. Just like with your annual submission, we’ll keep you informed every step of the way.



What are the categories the DSPT divides organisations into?


The DSPT divides organisations into four categories, each with specific requirements based on their size and role within the healthcare system.

Category 1: Includes large organisations such as hospitals and integrated care boards. These organisations must meet the full set of DSPT requirements and provide comprehensive evidence of their data security and protection measures.

Category 2: Covers smaller organisations like GP surgeries, dental practices, and pharmacies. They follow a simplified version of the DSPT with fewer mandatory evidence items, making compliance more manageable, while still maintaining a high-level of data protection standards.

Category 3: Consists of social care providers, including care homes and domiciliary care agencies. Many of DSPT requirements for this focuses on building data security appropriate to the adult social care sector.

Category 4: Refers to commercial third parties such as IT suppliers and data processors. These organisations must demonstrate they meet high standards of information security to ensure the protection of NHS patient data and compliance with contractual obligations.

Privacy Helper will tailor our approach to the DSPT based on the specific needs and category of your organisation. This means you can be confident that you are provided with the right level of support and guidance throughout your compliance journey.



What to do next?

Need support with your DSPT submission? Whether you’re completing it for the first time or need help reviewing an existing submission, Privacy Helper is here to make the process easier!

Get in touch with our expert team today, to discuss how we can support your organisation and take the stress out of DSPT submission.

 

why choose icon

Why choose us?

Find out more about us, and why we are a leading UK privacy consultancy.

what next icon

What next?

Get in touch via our contact us page, tell us about your business and a member of our team will get back to you.

Other services you may be interested in from PRIVACY HELPER

Security Icon

GDPR Consultancy

Our Privacy Team consists of expert data protection consultants in the fields of IT & Technical, Legal, Records Management and Marketing.

training courses icon

GDPR Training Courses

An effective, demonstrable training programme can be the difference between the ICO imposing monetary fines – or not, even if your data privacy programme has just started.

marketing compliance icon

Marketing

Is your marketing activity legal? We can make sure it is.