Guide · Updated 2026

DSPT for dental practices: a plain-English guide

The deadline, the ten standards, what changed in version 8, and how to reach Standards Met without losing a fortnight to it.

If you run or manage a dental practice with any NHS work, the Data Security and Protection Toolkit is one of those jobs that arrives every year, feels bigger than it should, and usually lands on the person with the least spare time. This guide explains what it actually asks for, in plain terms, and what changed in the latest version that catches practices out.

What the DSPT is

The Data Security and Protection Toolkit, usually shortened to DSPT, is an annual online self-assessment run by NHS England. It asks your organisation to confirm, and evidence, that you are handling patient and staff data safely. It is built on the ten data security standards set out by the National Data Guardian, and it applies across health and care, not just to dental practices.

In practice it is a set of questions grouped under those ten standards. You answer each one, and for many of them you now have to attach or point to evidence that backs up your answer.

Which practices have to do it

The simplest way to think about it: if you touch NHS systems or hold an NHS contract, you are in scope.

Practice typeDSPT required?
NHS dental practiceYes
Mixed NHS and privateYes
Uses NHSmailYes
Purely private, no NHS systemsNo DSPT, but UK GDPR and PECR still apply

Even where the DSPT itself does not apply, a private practice still processes special category health data and still has to meet UK data protection law. The DSPT is the NHS's way of checking it; the underlying obligations exist regardless.

The deadline

The annual submission deadline is 30 June. The toolkit reopens for the new assessment year in the autumn, so there is a long window to work in. The trap most practices fall into is leaving it until spring, when the evidence gathering collides with everything else and becomes a fortnight of evenings.

The ten standards

The DSPT is organised around the ten National Data Guardian standards. In plain terms:

#Standard, in plain English
1Personal confidential data is handled, stored and sent securely
2Staff understand their responsibilities for data security
3All staff complete appropriate data security training each year
4You manage who has access to which systems, and remove leavers promptly
5Processes are reviewed at least annually, and after any incident
6You can detect, respond to and report a data security incident
7You have a tested plan for continuing if IT systems go down
8No unsupported software, operating systems or browsers are in use
9Your IT is protected against cyber threats
10Suppliers who handle your data are held to account by contract

What changed in version 8

This is the part that catches practices out, so it is worth being clear about.

Version 8, released in September 2025 and aligned to the National Cyber Security Centre's Cyber Assessment Framework, moved the DSPT to outcome-based evidence. Previously you could largely assert that you had a policy. Now you have to show the control actually operates.

The practical difference

If your answer says "all staff complete annual data security training," version 8 wants the completion records that prove they did, named individual by named individual. A policy document in a drawer is no longer enough on its own.

Version 8 also brought in, for Category 3 organisations (which includes dental practices), two things that trip people up in their first year:

What happens if you do not do it

The consequences are concrete rather than theoretical:

There is also a quieter benefit to getting it right: an organisation that can show a dated, evidenced record of its data security is in a far stronger position if it ever suffers a breach, because the Information Commissioner weighs demonstrable diligence when deciding how to respond.

How to reach Standards Met

The reassuring truth is that most practices already do six or seven of the ten standards in some form. The work is rarely putting new controls in place. It is finding and organising the evidence that the controls you already have actually operate, which is exactly what version 8 now asks for.

A sensible order:

  1. Build or update your digital asset register first, because several other answers depend on it.
  2. Turn on and evidence multi-factor authentication, since it is mandatory and quick.
  3. Gather your training records, named individual by named individual.
  4. Check nothing unsupported is still running (old Windows versions are the usual culprit).
  5. Confirm you have written contracts with the suppliers who touch your data.
  6. Work through the remaining standards, attaching evidence as you go.

Not sure where you stand?

We run a free external audit of your practice's public web and email setup, then show you exactly where you are against the ten standards. No charge, no obligation, and no access to your systems.

Request your free audit

Or call 07749 941111

Common questions

Is the DSPT mandatory for dental practices?

Yes, for any practice with NHS work or that uses NHS systems such as NHSmail. Purely private practices are not required to complete the DSPT, but still have UK GDPR and PECR obligations.

What is the DSPT deadline?

30 June each year. The toolkit reopens for the new year in the autumn.

What changed in version 8?

It moved to outcome-based evidence, meaning you must prove controls operate rather than just having a policy. It also added a mandatory digital asset register and multi-factor authentication requirements.

What happens if we do not complete it?

You can lose access to NHS systems including NHSmail, it is checked at CQC inspection, and failure to submit can attract enforcement action.

How long does it take?

Most of the effort is evidence gathering rather than new work. For a first-time submission under version 8, that commonly takes several days of a practice manager's time. Keeping evidence current through the year reduces the next submission to a short review.

This guide is general information, accurate at the time of writing, and is not legal advice. Requirements are set by NHS England and can change; always check the current guidance on the DSP Toolkit website for your organisation category.