Where Care Excellence Meets Business Success. Transform your operations today - 0333 577 0877
Log in to CareSync Interview Preparation.

Would you like to receive update from CareSync Experts?

Duration: 00:00
Published: 22 Jul, 2026
Share this on:
DSPT, the Data Security and Protection Toolkit, is the official self-assessment tool for data protection and cyber security in adult social care in England. Care providers with access to personal information held in NHS systems must use it. Providers working under an NHS Standard Contract also have a contractual requirement to complete it each year. Other adult social care services are strongly recommended to complete it and aim for Standards Met.
The 2025 to 2026 deadline was 30 June 2026. If your service missed it, keep going. Digital Care Hub’s post-deadline guidance says the priority is to complete the work, publish the assessment and then make sure the commitments are reflected in daily practice. This guide gives you a practical recovery plan, an evidence matrix and a twelve-month maintenance cycle.
Data Security and Protection Toolkit work is not limited to software. The Data Security and Protection Toolkit covers the information you hold about people who use services, staff, visitors, commissioners and partners. That includes paper records, conversations, mobile devices, emails, care systems and information sharing.
The NHS Data Security and Protection Toolkit, usually shortened to DSPT, is a free online self-assessment. It helps health and care organisations measure how they manage data security and information governance against the National Data Guardian’s 10 data security standards.
The current NHS Adult Social Care Standards Directory records DSPT version 8 as active. It applies to organisations with access to personal information held in NHS systems, organisations supporting NHS bodies, social care providers delivering through the NHS Standard Contract and other listed organisations.
For adult social care, Digital Care Hub explains that the Data Security and Protection Toolkit covers policies, procedures and real operating processes. It includes paper records, verbal disclosures, digital systems, cyber security and the duty to share information safely for a person’s care. That wider scope matters. A provider cannot complete strong toolkit evidence by asking an IT supplier to answer every question.
Standards Met is the level adult social care providers should aim to reach. It means your published assessment contains the mandatory evidence required for that level. It does not certify that a service will never experience a data breach, and it does not replace ongoing risk management.
Reaching Standards Met can support access to shared systems and helps provide assurance to NHS partners, commissioners, people using services and staff. Digital Care Hub also explains that providers need at least Approaching Standards for NHSmail access. Check the current access rules before relying on the toolkit for a particular system.
Use the following distinction carefully.
| Your position | Current position | Practical response |
|---|---|---|
| Your organisation has access to personal information held in NHS systems | NHS England says you must use the toolkit | Confirm your organisation code, scope and annual publication status |
| Your care service is funded through an NHS Standard Contract | Completion is a contractual requirement | Check the contract, commissioner requirements and target publication level |
| Your adult social care service does not fall into either group above | Digital Care Hub says all adult social care services in England are strongly recommended to complete it | Use the toolkit as a recognised assurance framework and aim for Standards Met |
| A council or Integrated Care Board contract specifies the toolkit | Your contract may create a specific obligation | Check the exact wording, deadline, level and reporting route |
Do not describe DSPT as legally mandatory for every CQC-registered provider. That wording is too broad. Equally, do not dismiss it as optional administration. CQC’s Chief Inspector of Adult Social Care publicly recommended in July 2026 that all care providers use DSPT to improve how they manage personal data.
The distinction is operationally important. A provider funded by the NHS may have a clear contractual requirement. Another provider may be responding to commissioner expectations, NHSmail access conditions, CQC evidence needs or its own governance priorities. Record which basis applies to your service.
The annual deadline for the 2025 to 2026 toolkit was 30 June 2026. Missing the date does not make unfinished work disappear. Digital Care Hub’s current message is to keep going. Complete the remaining evidence, correct weak answers and publish when the assessment is accurate.
Start your Data Security and Protection Toolkit recovery with a short meeting. Confirm the registered organisation, service scope, current assessment status, outstanding questions, evidence owners and target publication date. If a commissioner or NHS partner requires DSPT, tell the relevant contract lead what you are doing and follow the contract’s reporting route.
Do not rush unsupported answers simply to obtain a publication status. The published assessment should match your real controls. If an answer depends on a policy, training record, supplier assurance, backup test or incident procedure that does not exist, treat that as an action rather than writing as if it is already in place.
Confirm the correct legal organisation, Organisation Data Service code, locations and services. Decide which people, systems, devices, suppliers and records are inside the assessment. A weak scope can produce confident answers about only part of the organisation.
Name one DSPT lead and give each evidence area an owner. The registered manager may co-ordinate the work, but information governance, HR, operations and IT support may each hold essential evidence. Record who approves the final assessment.
Create an evidence register with five fields: question or control, source record, owner, last review date and verification status. This turns the toolkit into a controlled assurance exercise. It also stops the team relying on memory or copying last year’s answer.
Do not stop at document existence. Check whether staff understand their responsibilities, access is removed when people leave, backups can be restored, mobile devices are controlled, suppliers are reviewed and incident procedures work under pressure. Record the test and the result.
Use the live toolkit and current official question guidance. Answer for your service as it operates now. Where a control is incomplete, use the permitted action-plan route only if it genuinely applies and describe the gap, action, owner and target date accurately.
Ask a leader who did not write the answers to test them against source records. Challenge vague phrases such as ‘staff are trained’ or ‘backups are completed’. A reviewer should be able to find the training evidence, completion status, backup frequency and latest restore test.
Publish only after the organisation and evidence have been checked. Save the publication record, evidence register, review notes and action plan. Then add quarterly checks and an annual republish date to the governance calendar.
Digital Care Hub groups the social care questions across staffing and roles, policies and procedures, data security, and IT systems and devices. The Data Security and Protection Toolkit matrix below adds a practical verification layer.
| Evidence area | Records to gather | Control test | Warning sign |
|---|---|---|---|
| Roles and training | Role descriptions, induction, refresher training, competency checks and leaver records | Sample whether staff can explain secure handling and escalation | Training is recorded but overdue or not linked to role |
| Policies and privacy information | Data protection policy, privacy notices, retention schedule and information-sharing procedure | Compare documents with actual records, systems and sharing routes | Generic policy wording does not match the service |
| Access and devices | User lists, permissions, device register, mobile controls and software update records | Sample joiners, movers and leavers; check unsupported software | Dormant accounts or shared credentials remain active |
| Suppliers | Contracts, data-processing terms, assurance evidence and review records | Trace which suppliers handle personal data and how risks are monitored | No owner knows what data a supplier can access |
| Backups and continuity | Backup logs, restore tests, business continuity plan and downtime records | Run a controlled restore or downtime exercise | Backups exist but have never been restored |
| Incidents and breaches | Incident log, response procedure, investigation records and learning actions | Tabletop test who acts, who decides and how evidence is retained | Staff know to report but do not know the route |
| Records lifecycle | Information asset register, retention rules, disposal evidence and archive controls | Sample records from creation to secure disposal | Paper, email and exported files fall outside the register |
This matrix is a Care Sync Experts working method, not a replacement for the live toolkit. Use it to organise evidence, then answer the current DSPT questions and follow the official help text.
A strong Data Security and Protection Toolkit annual return is built through routine governance. Use a simple cycle.
| Frequency | Minimum review | Evidence retained |
|---|---|---|
| Monthly | Joiners and leavers, access exceptions, incidents, training gaps and device changes | Exception log and completed actions |
| Quarterly | Supplier changes, information assets, policy actions, backup results and cyber alerts | Governance review record |
| After a material change | New care system, location, contract, supplier, data-sharing route or serious incident | Risk review, updated register and approved control changes |
| Six to eight weeks before publication | Full evidence refresh and answer challenge | Completed evidence register and correction log |
| After publication | Archive, action-plan ownership and lessons for the next cycle | Publication record and dated improvement plan |
This cadence makes the toolkit useful. It also helps leaders show how data protection commitments connect with workforce management, business continuity, supplier oversight and quality governance.
Another risk is relying on a fixed question count from an old guide. The toolkit can change between assessment years. Use the live assessment and current Digital Care Hub guidance rather than designing your evidence plan around an historic number.
Care Sync Experts can help care providers connect DSPT work with wider Compliance Management. We can help organise evidence ownership, review policies and governance records, identify gaps, build an improvement tracker and prepare leaders to maintain the controls after publication.
If your service is still establishing its wider regulatory systems, our CQC Registration Support can help align documents, responsibilities and evidence. For a focused conversation about your current DSPT position, book a consultation with Care Sync Experts.
Evidence note: this DSPT guide was checked against current NHS England, Adult Social Care Standards Directory, Digital Care Hub and Local Government Association sources on 21 July 2026. The 2025 to 2026 deadline has passed, and question wording may change for a new assessment year. Check the live toolkit and current official guidance before making a submission or contractual decision. This guide does not replace official instructions or advice on your specific legal or contractual position.
No. NHS England says organisations with access to personal information held in NHS systems must use it. Digital Care Hub says providers funded through an NHS Standard Contract have a contractual requirement to complete it each year. All other adult social care services in England are strongly recommended to complete it. Your council or Integrated Care Board contract may also set a specific requirement.
Keep going. Confirm the assessment scope, list outstanding evidence, assign owners, correct unsupported answers and publish when the assessment is accurate. If a contract requires DSPT, follow its reporting and escalation terms. Do not invent evidence or abandon the work because the deadline has passed.
The Data Security and Protection Toolkit is an annual assessment and publication process. Digital Care Hub says providers must complete it at least once a year to keep it current. Review controls throughout the year and complete an additional review after material changes such as a new system, supplier, contract or serious data incident.
The exact evidence depends on the live questions. Common areas include staff roles and training, policies and privacy information, access controls, devices, suppliers, backups, business continuity, incidents, retention and secure disposal. Each answer should connect to a current record and a test showing that the control works.
No. DSPT provides recognised evidence about data protection and cyber security arrangements. It can support your wider governance evidence, but it does not determine a CQC judgement or replace the provider’s other legal, regulatory and operational responsibilities.