NHS DSPT: Data Security and Protection Toolkit Guide
The NHS Data Security and Protection Toolkit (DSPT) is the annual online self-assessment tool that enables health and social care organizations in the UK to measure and publish their performance against the National Data Guardian's 10 data security standards. Completing the DSPT to "Standards Met" status is a prerequisite for accessing NHS patient data and connecting to NHS systems.
What the NHS DSPT Covers
The DSPT is organized around 10 data security standards derived from the National Data Guardian's review. These cover personal confidential data handling, staff responsibilities, training, managing data access, process reviews, responding to incidents, continuity planning, unsupported systems, IT protection, and accountability. Organizations must provide evidence of meeting mandatory assertions within each standard.
The toolkit requires completion of specific evidence items depending on organization type. NHS trusts face the most extensive requirements, while GP practices and smaller social care providers have a streamlined assessment. Technology suppliers must complete the Data Security Standard for Technology Suppliers category.
Who Needs NHS DSPT Compliance
Any organization that has access to NHS patient data or connects to NHS systems must complete the DSPT. This includes NHS trusts, GP practices, clinical commissioning groups, local authorities providing social care, and — critically — technology suppliers and data processors working with NHS organizations. Software vendors, cloud providers, and data analytics companies serving the NHS must all publish a DSPT assessment.
Implementation Approach
Register on the DSPT portal and identify the correct assessment category for your organization. Review all mandatory assertions and evidence requirements. Implement required controls including staff training (95% completion target), incident reporting procedures, access management processes, and technical security measures. Collect and upload evidence throughout the year. Submit your completed assessment before the annual 30 June deadline.
Cost Considerations
The DSPT itself is free to access. Implementation costs range from $10,000 for smaller organizations with good existing practices to $100,000 for larger organizations requiring significant improvements. Key cost drivers include staff training programs, technical security controls, and evidence documentation. For technology suppliers, achieving "Standards Met" status is essential for maintaining NHS contracts.