If you run or manage a dental practice with any NHS work, the Data Security and Protection Toolkit is one of those jobs that arrives every year, feels bigger than it should, and usually lands on the person with the least spare time. This guide explains what it actually asks for, in plain terms, and what changed in the latest version that catches practices out.
On this page
What the DSPT is
The Data Security and Protection Toolkit, usually shortened to DSPT, is an annual online self-assessment run by NHS England. It asks your organisation to confirm, and evidence, that you are handling patient and staff data safely. It is built on the ten data security standards set out by the National Data Guardian, and it applies across health and care, not just to dental practices.
In practice it is a set of questions grouped under those ten standards. You answer each one, and for many of them you now have to attach or point to evidence that backs up your answer.
Which practices have to do it
The simplest way to think about it: if you touch NHS systems or hold an NHS contract, you are in scope.
| Practice type | DSPT required? |
|---|---|
| NHS dental practice | Yes |
| Mixed NHS and private | Yes |
| Uses NHSmail | Yes |
| Purely private, no NHS systems | No DSPT, but UK GDPR and PECR still apply |
Even where the DSPT itself does not apply, a private practice still processes special category health data and still has to meet UK data protection law. The DSPT is the NHS's way of checking it; the underlying obligations exist regardless.
The deadline
The annual submission deadline is 30 June. The toolkit reopens for the new assessment year in the autumn, so there is a long window to work in. The trap most practices fall into is leaving it until spring, when the evidence gathering collides with everything else and becomes a fortnight of evenings.
The ten standards
The DSPT is organised around the ten National Data Guardian standards. In plain terms:
| # | Standard, in plain English |
|---|---|
| 1 | Personal confidential data is handled, stored and sent securely |
| 2 | Staff understand their responsibilities for data security |
| 3 | All staff complete appropriate data security training each year |
| 4 | You manage who has access to which systems, and remove leavers promptly |
| 5 | Processes are reviewed at least annually, and after any incident |
| 6 | You can detect, respond to and report a data security incident |
| 7 | You have a tested plan for continuing if IT systems go down |
| 8 | No unsupported software, operating systems or browsers are in use |
| 9 | Your IT is protected against cyber threats |
| 10 | Suppliers who handle your data are held to account by contract |
What changed in version 8
This is the part that catches practices out, so it is worth being clear about.
Version 8, released in September 2025 and aligned to the National Cyber Security Centre's Cyber Assessment Framework, moved the DSPT to outcome-based evidence. Previously you could largely assert that you had a policy. Now you have to show the control actually operates.
If your answer says "all staff complete annual data security training," version 8 wants the completion records that prove they did, named individual by named individual. A policy document in a drawer is no longer enough on its own.
Version 8 also brought in, for Category 3 organisations (which includes dental practices), two things that trip people up in their first year:
- A digital asset register — a list of all the hardware and software you use. An existing information asset register can usually be extended rather than started from scratch.
- Multi-factor authentication — on remote access and on cloud systems that hold patient data. Most providers include this at no extra cost, but it has to be switched on and evidenced.
What happens if you do not do it
The consequences are concrete rather than theoretical:
- Practices that do not submit, or fail to meet the standard, can lose access to NHS systems including NHSmail.
- DSPT status is checked by CQC during inspections.
- It is increasingly expected by local commissioners and by anyone doing supplier due diligence on you.
- Failure to submit can attract enforcement action.
There is also a quieter benefit to getting it right: an organisation that can show a dated, evidenced record of its data security is in a far stronger position if it ever suffers a breach, because the Information Commissioner weighs demonstrable diligence when deciding how to respond.
How to reach Standards Met
The reassuring truth is that most practices already do six or seven of the ten standards in some form. The work is rarely putting new controls in place. It is finding and organising the evidence that the controls you already have actually operate, which is exactly what version 8 now asks for.
A sensible order:
- Build or update your digital asset register first, because several other answers depend on it.
- Turn on and evidence multi-factor authentication, since it is mandatory and quick.
- Gather your training records, named individual by named individual.
- Check nothing unsupported is still running (old Windows versions are the usual culprit).
- Confirm you have written contracts with the suppliers who touch your data.
- Work through the remaining standards, attaching evidence as you go.
Not sure where you stand?
We run a free external audit of your practice's public web and email setup, then show you exactly where you are against the ten standards. No charge, no obligation, and no access to your systems.
Request your free auditOr call 07749 941111
Common questions
Is the DSPT mandatory for dental practices?
Yes, for any practice with NHS work or that uses NHS systems such as NHSmail. Purely private practices are not required to complete the DSPT, but still have UK GDPR and PECR obligations.
What is the DSPT deadline?
30 June each year. The toolkit reopens for the new year in the autumn.
What changed in version 8?
It moved to outcome-based evidence, meaning you must prove controls operate rather than just having a policy. It also added a mandatory digital asset register and multi-factor authentication requirements.
What happens if we do not complete it?
You can lose access to NHS systems including NHSmail, it is checked at CQC inspection, and failure to submit can attract enforcement action.
How long does it take?
Most of the effort is evidence gathering rather than new work. For a first-time submission under version 8, that commonly takes several days of a practice manager's time. Keeping evidence current through the year reduces the next submission to a short review.
This guide is general information, accurate at the time of writing, and is not legal advice. Requirements are set by NHS England and can change; always check the current guidance on the DSP Toolkit website for your organisation category.