Ask a room of registered managers about the DSPT and you'll get a lot of nervous looks. The name — Data Security and Protection Toolkit — makes it sound like something for IT departments. In reality it's a self‑assessment about keeping the information you hold safe, and most of it is good practice you're probably already doing. This guide demystifies it.
Key takeaways
- The DSPT is a free, annual self‑assessment of how well you protect the data you hold.
- It's built on the 10 data security standards — grouped into people, processes and technology.
- You may need it for NHSmail, GP Connect, shared care records, and increasingly for commissioners.
- Free help exists through the Better Security, Better Care programme and local support organisations.
- It supports your CQC story — good data security is part of being safe and well‑led.
What the DSPT is
The Data Security and Protection Toolkit (DSPT) is a free online self‑assessment, published on the DSPT portal, that lets an organisation show how well it looks after the personal and health information it holds. It measures you against the National Data Guardian's 10 data security standards — a nationally recognised baseline for handling data safely in health and care.
You work through a set of questions (assertions), confirm and where needed evidence how you meet them, and then publish your assessment. It's renewed each year.
Do care providers actually need it?
It isn't a blanket legal requirement for every single provider — but in practice it's needed or expected in a growing number of situations, including:
- Using NHSmail — a completed DSPT is typically required to hold NHSmail accounts.
- Accessing NHS systems — such as GP Connect, proxy access, or your local shared care record.
- Digital social care records — being able to use assured supplier systems and related funding often depends on it.
- Commissioners and partners — councils and ICBs increasingly ask for it as a condition of contracts or data sharing.
Even where it isn't strictly required, completing it is fast becoming the expected sign that a provider takes data security seriously.
Think of the DSPT less as a hoop to jump through and more as a way to prove — to the NHS, commissioners and families — that people's information is safe with you.
What it covers — the 10 standards
The National Data Guardian's ten standards sound daunting as a list, but they group neatly into three plain ideas:
- Everyone understands their responsibilities for handling data.
- Staff are trained in data security and know how to spot and report risks.
- Clear accountability — someone senior owns data protection.
- Personal data is handled properly — collected, shared and stored lawfully.
- Records of what you hold and who you share it with are kept.
- Incidents are managed — you can spot, report and learn from a breach.
- Continuity plans exist so care isn't disrupted if systems fail.
- Systems are kept up to date and protected against known threats.
- Access is controlled — people only see what they need to.
- Suppliers are trustworthy — the technology partners you rely on meet the standards too.
Read like that, most of it is simply running a careful, well‑organised service — which you already do.
The levels you can reach
Your published assessment shows how far you've got. Providers commonly work toward "Standards Met" (you meet the expected baseline), with a lighter entry‑level route for smaller organisations getting started, and a "Standards Exceeded" level above. The exact labels and requirements are set on the portal and can change year to year, so check the current version when you start.
How to complete it — step by step
- Register your organisation on the DSPT portal (you'll need your ODS code).
- Choose your path — the entry‑level route if you're a small provider starting out, or the full standards route.
- Work through the assertions, confirming what you do and attaching evidence where asked (policies, training records, your incident process).
- Fill the gaps — anything you can't yet confirm becomes an action to sort before you publish.
- Publish, then diarise next year's review — it's an annual commitment.
Tips to make it painless
- Start early. Give yourself weeks, not days, before the deadline.
- Give it an owner. One named person keeps it moving; it stalls when it's "everyone's job".
- Reuse what you have. Your existing policies, training logs and incident procedures are most of the evidence.
- Keep the evidence together so next year's renewal is a review, not a rebuild.
How the DSPT fits your CQC readiness
Data security isn't a separate world from CQC — it's part of being safe (protecting confidential information) and well‑led (sound governance). A published DSPT is clean, ready‑made evidence that you manage information responsibly, so completing it does double duty: it satisfies the NHS/commissioner side and strengthens your inspection story.
Keep your compliance evidence in one place
Haverton Care Hub helps you organise the audits, actions and evidence behind your compliance — so the proof you need for CQC (and toolkits like the DSPT) is always to hand.
Register your interest →Frequently asked questions
Is the DSPT mandatory for care providers?
Not universally, but it's required or expected in many situations — to use NHSmail, to access NHS systems like GP Connect or shared care records, and increasingly by commissioners. It's widely treated as the standard way to evidence good data security.
Is the DSPT free?
Yes. It's a free online self‑assessment, and free support is available to adult social care providers through the Better Security, Better Care programme and its local support organisations.
How often do you complete it?
Annually — you review and republish each year by the published deadline. Always check the current year's deadline on the DSPT portal.
How long does it take?
For a small provider using the entry‑level route it can often be done in a few focused sessions, especially with free local support. Larger organisations aiming for Standards Met will need longer to gather evidence.
General guidance to help you understand the DSPT. Not legal advice. Requirements, levels and deadlines are set by NHS England and change from year to year — always work from the current DSPT portal and Better Security, Better Care guidance.