DSPT, the Data Security and Protection Toolkit, is the official self-assessment tool for data protection and cyber security in adult social care in England. Care providers with access to personal information held in NHS systems must use it. Providers working under an NHS Standard Contract also have a contractual requirement to complete it each year. Other adult social care services are strongly recommended to complete it and aim for Standards Met.
The 2025 to 2026 deadline was 30 June 2026. If your service missed it, keep going. Digital Care Hub’s post-deadline guidance says the priority is to complete the work, publish the assessment and then make sure the commitments are reflected in daily practice. This guide gives you a practical recovery plan, an evidence matrix and a twelve-month maintenance cycle.
Data Security and Protection Toolkit work is not limited to software. The Data Security and Protection Toolkit covers the information you hold about people who use services, staff, visitors, commissioners and partners. That includes paper records, conversations, mobile devices, emails, care systems and information sharing.
Key Takeaways
- Check whether toolkit completion is mandatory for your service or strongly recommended. Do not assume the same position applies to every CQC provider.
- If the 30 June 2026 deadline has passed, finish the assessment and publish as soon as your evidence is accurate.
- Gather evidence before answering. Policies alone do not prove that controls work in practice.
- Aim for Standards Met. If you are using an action-plan route, record ownership, dates and evidence for every gap.
- Treat publication as the start of an annual control cycle, not a once-a-year form-filling exercise.
On This Page
What Is the Data Security and Protection Toolkit?
The NHS Data Security and Protection Toolkit, usually shortened to DSPT, is a free online self-assessment. It helps health and care organisations measure how they manage data security and information governance against the National Data Guardian’s 10 data security standards.
The current NHS Adult Social Care Standards Directory records DSPT version 8 as active. It applies to organisations with access to personal information held in NHS systems, organisations supporting NHS bodies, social care providers delivering through the NHS Standard Contract and other listed organisations.
For adult social care, Digital Care Hub explains that the Data Security and Protection Toolkit covers policies, procedures and real operating processes. It includes paper records, verbal disclosures, digital systems, cyber security and the duty to share information safely for a person’s care. That wider scope matters. A provider cannot complete strong toolkit evidence by asking an IT supplier to answer every question.
What does Standards Met mean?
Standards Met is the level adult social care providers should aim to reach. It means your published assessment contains the mandatory evidence required for that level. It does not certify that a service will never experience a data breach, and it does not replace ongoing risk management.
Reaching Standards Met can support access to shared systems and helps provide assurance to NHS partners, commissioners, people using services and staff. Digital Care Hub also explains that providers need at least Approaching Standards for NHSmail access. Check the current access rules before relying on the toolkit for a particular system.
Who Needs to Complete the Data Security and Protection Toolkit?
Use the following distinction carefully.
| Your position | Current position | Practical response |
|---|---|---|
| Your organisation has access to personal information held in NHS systems | NHS England says you must use the toolkit | Confirm your organisation code, scope and annual publication status |
| Your care service is funded through an NHS Standard Contract | Completion is a contractual requirement | Check the contract, commissioner requirements and target publication level |
| Your adult social care service does not fall into either group above | Digital Care Hub says all adult social care services in England are strongly recommended to complete it | Use the toolkit as a recognised assurance framework and aim for Standards Met |
| A council or Integrated Care Board contract specifies the toolkit | Your contract may create a specific obligation | Check the exact wording, deadline, level and reporting route |
Do not describe DSPT as legally mandatory for every CQC-registered provider. That wording is too broad. Equally, do not dismiss it as optional administration. CQC’s Chief Inspector of Adult Social Care publicly recommended in July 2026 that all care providers use DSPT to improve how they manage personal data.
The distinction is operationally important. A provider funded by the NHS may have a clear contractual requirement. Another provider may be responding to commissioner expectations, NHSmail access conditions, CQC evidence needs or its own governance priorities. Record which basis applies to your service.
Missed the 30 June 2026 Data Security and Protection Toolkit Deadline?
The annual deadline for the 2025 to 2026 toolkit was 30 June 2026. Missing the date does not make unfinished work disappear. Digital Care Hub’s current message is to keep going. Complete the remaining evidence, correct weak answers and publish when the assessment is accurate.
Start your Data Security and Protection Toolkit recovery with a short meeting. Confirm the registered organisation, service scope, current assessment status, outstanding questions, evidence owners and target publication date. If a commissioner or NHS partner requires DSPT, tell the relevant contract lead what you are doing and follow the contract’s reporting route.
Do not rush unsupported answers simply to obtain a publication status. The published assessment should match your real controls. If an answer depends on a policy, training record, supplier assurance, backup test or incident procedure that does not exist, treat that as an action rather than writing as if it is already in place.
Data Security and Protection Toolkit: 7 Practical Steps
1. Lock the organisation and assessment scope
Confirm the correct legal organisation, Organisation Data Service code, locations and services. Decide which people, systems, devices, suppliers and records are inside the assessment. A weak scope can produce confident answers about only part of the organisation.
2. Assign accountable owners
Name one DSPT lead and give each evidence area an owner. The registered manager may co-ordinate the work, but information governance, HR, operations and IT support may each hold essential evidence. Record who approves the final assessment.
3. Build evidence before answering
Create an evidence register with five fields: question or control, source record, owner, last review date and verification status. This turns the toolkit into a controlled assurance exercise. It also stops the team relying on memory or copying last year’s answer.
4. Test whether each control works
Do not stop at document existence. Check whether staff understand their responsibilities, access is removed when people leave, backups can be restored, mobile devices are controlled, suppliers are reviewed and incident procedures work under pressure. Record the test and the result.
5. Answer with precise, current evidence
Use the live toolkit and current official question guidance. Answer for your service as it operates now. Where a control is incomplete, use the permitted action-plan route only if it genuinely applies and describe the gap, action, owner and target date accurately.
6. Run an independent challenge
Ask a leader who did not write the answers to test them against source records. Challenge vague phrases such as ‘staff are trained’ or ‘backups are completed’. A reviewer should be able to find the training evidence, completion status, backup frequency and latest restore test.
7. Publish, archive and schedule the next review
Publish only after the organisation and evidence have been checked. Save the publication record, evidence register, review notes and action plan. Then add quarterly checks and an annual republish date to the governance calendar.
Data Security and Protection Toolkit Evidence Matrix for Adult Social Care
Digital Care Hub groups the social care questions across staffing and roles, policies and procedures, data security, and IT systems and devices. The Data Security and Protection Toolkit matrix below adds a practical verification layer.
| Evidence area | Records to gather | Control test | Warning sign |
|---|---|---|---|
| Roles and training | Role descriptions, induction, refresher training, competency checks and leaver records | Sample whether staff can explain secure handling and escalation | Training is recorded but overdue or not linked to role |
| Policies and privacy information | Data protection policy, privacy notices, retention schedule and information-sharing procedure | Compare documents with actual records, systems and sharing routes | Generic policy wording does not match the service |
| Access and devices | User lists, permissions, device register, mobile controls and software update records | Sample joiners, movers and leavers; check unsupported software | Dormant accounts or shared credentials remain active |
| Suppliers | Contracts, data-processing terms, assurance evidence and review records | Trace which suppliers handle personal data and how risks are monitored | No owner knows what data a supplier can access |
| Backups and continuity | Backup logs, restore tests, business continuity plan and downtime records | Run a controlled restore or downtime exercise | Backups exist but have never been restored |
| Incidents and breaches | Incident log, response procedure, investigation records and learning actions | Tabletop test who acts, who decides and how evidence is retained | Staff know to report but do not know the route |
| Records lifecycle | Information asset register, retention rules, disposal evidence and archive controls | Sample records from creation to secure disposal | Paper, email and exported files fall outside the register |
This matrix is a Care Sync Experts working method, not a replacement for the live toolkit. Use it to organise evidence, then answer the current DSPT questions and follow the official help text.
How to Maintain the Data Security and Protection Toolkit Throughout the Year
A strong Data Security and Protection Toolkit annual return is built through routine governance. Use a simple cycle.
| Frequency | Minimum review | Evidence retained |
|---|---|---|
| Monthly | Joiners and leavers, access exceptions, incidents, training gaps and device changes | Exception log and completed actions |
| Quarterly | Supplier changes, information assets, policy actions, backup results and cyber alerts | Governance review record |
| After a material change | New care system, location, contract, supplier, data-sharing route or serious incident | Risk review, updated register and approved control changes |
| Six to eight weeks before publication | Full evidence refresh and answer challenge | Completed evidence register and correction log |
| After publication | Archive, action-plan ownership and lessons for the next cycle | Publication record and dated improvement plan |
This cadence makes the toolkit useful. It also helps leaders show how data protection commitments connect with workforce management, business continuity, supplier oversight and quality governance.
Common DSPT Mistakes to Avoid
- claiming DSPT is mandatory for every CQC provider without checking the service’s position;
- treating the toolkit as an IT-only task;
- copying last year’s answers without checking changes;
- using a policy as proof that staff follow the control;
- forgetting paper records, verbal disclosures, mobile devices or exported files;
- listing backups without testing whether data can be restored;
- overlooking suppliers that can access or host personal data;
- publishing before gaps, owners and dates are accurate;
- failing to retain the evidence and publication record;
- waiting until June to review twelve months of change.
Another risk is relying on a fixed question count from an old guide. The toolkit can change between assessment years. Use the live assessment and current Digital Care Hub guidance rather than designing your evidence plan around an historic number.
How Care Sync Experts Can Support Your Data Security and Protection Toolkit Readiness
Care Sync Experts can help care providers connect DSPT work with wider Compliance Management. We can help organise evidence ownership, review policies and governance records, identify gaps, build an improvement tracker and prepare leaders to maintain the controls after publication.
If your service is still establishing its wider regulatory systems, our CQC Registration Support can help align documents, responsibilities and evidence. For a focused conversation about your current DSPT position, book a consultation with Care Sync Experts.
Evidence note: this DSPT guide was checked against current NHS England, Adult Social Care Standards Directory, Digital Care Hub and Local Government Association sources on 21 July 2026. The 2025 to 2026 deadline has passed, and question wording may change for a new assessment year. Check the live toolkit and current official guidance before making a submission or contractual decision. This guide does not replace official instructions or advice on your specific legal or contractual position.
Frequently Asked Questions
Is the Data Security and Protection Toolkit mandatory for all care providers?
No. NHS England says organisations with access to personal information held in NHS systems must use it. Digital Care Hub says providers funded through an NHS Standard Contract have a contractual requirement to complete it each year. All other adult social care services in England are strongly recommended to complete it. Your council or Integrated Care Board contract may also set a specific requirement.
What should a care provider do after missing the 30 June 2026 Data Security and Protection Toolkit deadline?
Keep going. Confirm the assessment scope, list outstanding evidence, assign owners, correct unsupported answers and publish when the assessment is accurate. If a contract requires DSPT, follow its reporting and escalation terms. Do not invent evidence or abandon the work because the deadline has passed.
How often should care providers complete DSPT?
The Data Security and Protection Toolkit is an annual assessment and publication process. Digital Care Hub says providers must complete it at least once a year to keep it current. Review controls throughout the year and complete an additional review after material changes such as a new system, supplier, contract or serious data incident.
What evidence is needed for DSPT Standards Met?
The exact evidence depends on the live questions. Common areas include staff roles and training, policies and privacy information, access controls, devices, suppliers, backups, business continuity, incidents, retention and secure disposal. Each answer should connect to a current record and a test showing that the control works.
Does completing DSPT ensure CQC compliance?
No. DSPT provides recognised evidence about data protection and cyber security arrangements. It can support your wider governance evidence, but it does not determine a CQC judgement or replace the provider’s other legal, regulatory and operational responsibilities.
