If your organisation handles NHS patient data or connects to NHS systems, you are expected to complete the Data Security and Protection Toolkit, usually shortened to the DSPT, and publish it every year. For a dental practice, a small care provider, a pharmacy or an IT supplier, the first attempt can feel daunting: a long list of questions, unfamiliar terms and a hard deadline. The good news is that it becomes far more manageable once you break it into steps and gather your evidence as you go.
This guide walks through the process in the order we recommend. It is written for smaller organisations using the standards-based version of the toolkit. If you run a dental practice, our DSPT guide for dental practices covers the sector-specific points in more depth.
What the DSPT is, in one paragraph
The DSPT is an online self-assessment run by NHS England. It measures your organisation against the National Data Guardian's ten data security standards, which cover areas such as staff responsibilities, training, access to data, incident management, continuity planning, unsupported systems and supplier accountability. You answer a set of statements, called assertions, backed up by evidence items, and then publish the result. According to the official DSPT news page for version 8, the 2025-26 deadline was 30 June 2026, and the same late-June deadline has applied in previous years, so it is sensible to plan around it.
Since 2024-25, larger NHS bodies such as trusts and integrated care boards use a version aligned to the NCSC Cyber Assessment Framework. Smaller and non-NHS organisations, including dentists, GPs, pharmacies, opticians, social care providers and IT suppliers, continue to use the standards-based assertions and evidence format. Check which version applies to you when you log in.
Step 1: register and get your access sorted
You register on the DSPT website using your organisation's ODS code, the unique code the NHS uses to identify health and care organisations. If you do not know yours, your commissioner, local integrated care board or the NHS Organisation Data Service can help.
Decide early who will do the work. The toolkit lets you add several users, so the person who knows your IT can complete the technical sections while a practice manager handles policies and training. Make sure at least two people have access, so the submission does not stall if one of them is away in June.
Step 2: name the people responsible
The toolkit expects clear accountability. At a minimum you will need a senior person who takes overall responsibility for data security and protection, and someone who acts as the lead for day-to-day information governance. In a small practice these may be the same person. You will also need to confirm your arrangements for a Data Protection Officer where UK GDPR requires one. The ICO guidance on data protection officers explains when an organisation must appoint one. Public authorities, and organisations processing health data on a large scale, need one; if you are unsure, work it through and record your decision.
Write these roles down in a short document and have it signed off. That single page becomes evidence for several assertions.
Step 3: gather your policies and records
Much of the DSPT is about proving that sensible practices are written down and followed. Before you start answering questions, pull together what you already have:
- A data protection or information governance policy, and a privacy notice for patients or service users.
- A record of processing activities, sometimes called an information asset register or data flow map.
- Your information security policy, covering passwords, device use, remote working and access control.
- Your business continuity plan and any record of testing it.
- Contracts or data processing agreements with the suppliers who handle your data.
If some of these are missing, note the gap and move on. It is quicker to answer everything you can first and then return to the gaps than to stop at the first missing document.
Step 4: complete staff training
Every member of staff who handles personal data needs data security awareness training, refreshed annually. Training tends to be the slowest item because it depends on other people finding time. Start it early in the year, keep a simple record of who completed it and when, and chase stragglers well before June. Check the exact completion expectation in the current version of the toolkit, as it is set out in the evidence items.
Step 5: work through the technical controls
The technical assertions ask about the basics that stop most attacks: supported software and operating systems, security updates applied promptly, up-to-date anti-malware, firewalls, secure configuration, and controlled access to systems and data. If you have worked towards Cyber Essentials, much of this will look familiar, because the controls overlap heavily.
Pay particular attention to accounts. Remove leavers promptly, avoid shared logins, and protect email and remote access with multi-factor authentication. Our MFA rollout guide for small teams covers how to do this without locking anyone out. The NCSC small organisations guide is also a useful free checklist for this part.
Step 6: check your incident and continuity arrangements
You will be asked how you would spot, record and report a data security incident. Make sure staff know who to tell, keep an incident log even if it is empty, and understand the reporting rules. Under UK GDPR, a personal data breach that is likely to pose a risk to people's rights and freedoms must be reported to the ICO within 72 hours of becoming aware of it, as set out in the ICO breach reporting guidance. The DSPT also includes its own incident reporting tool for health and care organisations.
For continuity, you need a plan for keeping services running if systems fail, and evidence that you have tested it, even with a simple tabletop exercise.
Step 7: review, fix gaps and publish
Once every assertion is answered, go back over the gaps you noted. Some can be closed quickly, such as signing off a policy or finishing training records. If there are items you cannot complete in time, the toolkit allows you to submit an improvement plan setting out how and when you will meet them, rather than simply leaving them blank. The aim for most organisations is to reach Standards Met.
When you are satisfied, the senior responsible person confirms the submission and you publish. Do not leave this until the last day. The website can be busy near the deadline, and last-minute questions about evidence are common.
Common mistakes to avoid
Treating it as a one-off form
The DSPT is annual, and evidence goes stale. Keep a folder of evidence and update it through the year, so next year's submission is a review rather than a rebuild.
Answering yes without evidence
It is a self-assessment, but it may be audited, and some organisations are selected for independent review. Only confirm what you can demonstrate.
Forgetting your website and suppliers
Your public website, booking forms and third-party tools all handle personal data. Weak spots there are easy to overlook and are exactly what attackers look for first.
Where to get help
Completing the DSPT is manageable for a small organisation, but it rewards preparation. Start early, spread the work across two or three people, and keep your evidence in one place. If you would like an independent view of where you stand before the deadline, our audit service reviews your controls and web-facing risk against what the toolkit asks for, and you can book a free audit to get started.
Want to know where you stand on the DSPT?
We will review your controls and evidence and tell you plainly what to fix before you publish.
Book a free audit