This briefing is general guidance, current at the time of writing. It is not legal or compliance advice. Whether the DSPT applies to your practice depends on your specific NHS relationships, so verify with your DPO, your commissioner, or NHS England before you rely on it.
The question comes up in almost every private-clinic onboarding: do we actually need the Data Security and Protection Toolkit, or is that only for NHS trusts? The honest answer is “it depends, and the thing it depends on is precise.” Get it wrong in one direction and you fail a contract condition. Get it wrong in the other and you spend weeks on a submission you never needed.
This is the decision guide. It sets out what the DSPT is, the single test for whether it is mandatory for your clinic, what changed in the 2025 to 2026 version, and what completing it actually involves.
What the DSPT is
The Data Security and Protection Toolkit is an annual online self-assessment, run by NHS England and overseen by the National Data Guardian. An organisation completes it to give assurance that it is handling health and care data securely and in line with the National Data Guardian’s data-security standards. The headline result for a standard submission is expressed as Standards Met, Approaching Standards, or Standards Not Met. The annual submission deadline is 30 June.
It is not, in itself, an Act of Parliament. Its force comes from contracts and NHS policy: it is written into the NHS Standard Contract and into the data-sharing agreements that govern NHS patient data. That is the key to the whole question, because it means the obligation attaches to a relationship, not to the label “clinic”.
The one test: is there an NHS nexus?
NHS England’s own wording is that “all organisations that have access to NHS patient data and systems must use this toolkit.” Read as a decision, that produces a single test. Your clinic is required to complete the DSPT if any of the following is true:
- You access NHS patient data (for example, you receive GP referrals, or you are sent records from an NHS system to deliver a service).
- You hold an NHS contract or a data-sharing agreement that names the DSPT as a condition. Most NHS contracts do.
- You use a national NHS system, in particular NHSmail or the e-Referral Service, both of which require a current DSPT to onboard and to keep access.
If none of those is true, the mandate has nothing to attach to. A purely private clinic that takes no NHS referrals, holds no NHS contract, processes no NHS patient data, and does not use NHSmail is not legally required to complete the DSPT.
A caveat on that, worth stating plainly: no single NHS page says in one sentence “private clinics with no NHS work are exempt.” The conclusion is drawn from the consistent framing that the requirement attaches to the NHS nexus. So the safe way to hold it is not “we are private, therefore exempt”, but “we have checked, and none of the three nexus triggers applies to us.” Those are different statements, and a commissioner will respect the second one.
Why so many private clinics are in scope without realising it
The trap is that the nexus is easy to acquire quietly:
- Referrals. A physiotherapy or audiology clinic that accepts NHS referrals is handling NHS patient data, even if most of its work is private.
- Occupational health. Supplying an occupational-health service to an NHS body typically brings a data-sharing agreement with it.
- NHSmail. A clinic that adopted NHSmail for secure email, often on a clinician’s advice, took on the DSPT requirement at the same time. NHSmail onboarding requires a DSPT at Standards Met for the main health-provider categories (social-care providers are held to a lower “Approaching Standards or higher” bar).
- A single NHS contract. One contract with the DSPT written into its conditions puts the whole organisation in scope for that submission.
So the practical version of the test is not “are we an NHS organisation” but “does any thread of NHS data, any NHS system, or any NHS contract touch this practice.” Often one does.
The CQC angle: even if it is not contractually mandatory
There is a second reason the DSPT matters to a clinic that is CQC-registered, even where no contract strictly compels it. CQC uses data-security assurance as evidence within its well-led assessment. CQC’s own guidance for general practice frames this under a well-led line of enquiry about whether information is being processed and protected properly, and treats DSPT completion and currency as evidence of that.
The precise wording matters here, because it is easy to overstate. CQC’s guidance also says, in terms, that “CQC does not directly assess GDPR compliance or make detailed, technical assessments of data security.” So the accurate position is: CQC uses your DSPT status as assurance evidence in the well-led domain; it does not audit the DSPT itself. A current, honest DSPT submission is a well-led asset. It is not a box CQC ticks on your behalf. (That guidance is written for general practice specifically; the principle generalises, but attribute it precisely.)
What changed in Version 8 (2025 to 2026)
Version 8 of the toolkit was published on 18 September 2025. Two changes matter for a clinic deciding what it faces.
1. The Cyber Assessment Framework alignment, but only for the largest organisations. Version 8 aligns to the NCSC Cyber Assessment Framework (CAF) version 3.4. This is the change people have heard about, and it is easy to assume it applies to everyone. It does not. The CAF-aligned path is for Category 1 organisations, broadly: NHS trusts, Integrated Care Boards, Commissioning Support Units, DHSC arm’s-length bodies, genomics organisations, and independent providers designated as Operators of Essential Services. Large IT suppliers sit on a separate independent-assessment track.
Most smaller clinics are not on the CAF path. GP practices, dental practices, opticians, pharmacies, and the majority of independent providers continue on the standard, question-and-evidence-based DSPT. If your clinic is a five-clinician private practice, the CAF-alignment headlines about independent audits and mandatory penetration testing most likely do not describe your submission. Confirm your category before assuming the heavier regime applies.
2. The scoring vocabulary. On the CAF-aligned path, individual contributing outcomes are scored Not Achieved, Partially Achieved, or Achieved. That is a per-outcome level, not the top-line grade. For a standard-path clinic the headline result is still Standards Met / Approaching Standards / Standards Not Met. Do not confuse the two; a supplier that quotes “Achieved” at you may be describing the wrong track for your practice.
The DSPT Nexus Test
When a clinic asks us whether it needs the DSPT, this is the sequence we run. It resolves most cases in five questions.
The DSPT Nexus Test. (1) Do you receive NHS referrals or otherwise access NHS patient data? (2) Do you hold any NHS contract or data-sharing agreement? Check whether it names the DSPT. (3) Do you use NHSmail, the e-Referral Service, or another national NHS system? (4) Are you CQC-registered, so a DSPT strengthens your well-led evidence even where not contractually required? (5) Do you want NHS work in future, where a completed DSPT is a precondition of bidding? A “yes” to 1, 2, or 3 means the DSPT is effectively mandatory. A “yes” only to 4 or 5 means it is strongly advisable but not compelled.
The value of running it explicitly is that it turns a vague worry into a documented decision, which is exactly what a commissioner, an insurer, or a CQC inspector wants to see.
What completing it involves, and the website’s part
The DSPT is an organisational assessment, not a website audit. But a large share of the evidence has a website-side footprint: the published privacy notice, the named information-governance lead, the incident-reporting route, the supported and patched stack, and the documented list of sub-processors. Those are the assertions the assessor can verify in a browser before speaking to anyone, and they are the ones clinics most often fail on. The assertion-by-assertion detail is set out in the DSPT website-side checklist.
How a regulated-grade estate handles this
Custodiance runs a clinic’s web and email estate as a managed, in-jurisdiction service, so the website-side DSPT evidence is a property of the estate rather than a scramble before the 30 June deadline. Where a clinic is in scope, the estate carries:
- The named information-governance or Caldicott contact, present on the contact page and in the footer.
- The incident-reporting route and the breach-response timeline, stated publicly.
- The supported, statically rendered stack, with the hardened header set and a security contact, so the “unsupported systems” and “IT protection” assertions hold up under a headless scan.
- The privacy notice structured to Article 30, and the documented sub-processor list, kept current with explicit last-updated dates.
At the close of onboarding a clinic in scope receives an evidence pack mapping each relevant assertion to the URL on its estate that satisfies it, ready to attach to the submission. This is the floor of a Growth engagement (£1,495/mo); a fractional-CTO Embedded engagement (from £6,000/mo, bespoke) owns the wider compliance posture and roadmap.
Frequently asked questions
We are entirely private with no NHS work at all. Can we ignore the DSPT?
You are not legally compelled to complete it, because the mandate attaches to an NHS nexus you do not have. Two cautions, though. First, check honestly: NHSmail, a single occupational-health contract, or accepting occasional NHS referrals all create the nexus. Second, if you are CQC-registered or expect to bid for NHS work, a voluntary DSPT is a genuine asset even when not required. “We checked and no trigger applies” is a stronger position than “we assumed we were exempt.”
We use NHSmail. Does that alone put us in scope?
Yes. NHSmail onboarding and continued access require a current DSPT, at Standards Met for the main health-provider categories. If your clinic adopted NHSmail, you took on the DSPT requirement with it, whether or not anyone framed it that way at the time.
Does the new Cyber Assessment Framework version apply to our small clinic?
Most likely not. The CAF-aligned path is for large Category 1 organisations and designated Operators of Essential Services. A typical small independent clinic stays on the standard question-and-evidence DSPT and reports a Standards Met result. Confirm your category with NHS England or your commissioner rather than assuming the heavier audit regime.
What is the deadline?
The annual DSPT submission deadline is 30 June. Because much of the evidence is website-side and takes time to put right, the practical work should start well before then, not in June.
Where this fits
Once you know the DSPT applies, the practical work is the DSPT website-side checklist. The controller-duty view of the same data is why your UK clinic’s website probably breaks GDPR, and the special-category detail is health data on your clinic website. The transparency-versus-privacy balance for published pages is the CQC-ready clinic website briefing, and the booking-specific rules are in online booking for clinics without breaking data rules. The published posture behind all of it, including the documented sub-processor list and the in-jurisdiction sovereignty position, is the Custodiance framework, and the overview for practices is Custodiance for clinics. When a clinic’s next DSPT submission is approaching, the next step is to request a scoping call.
Sources & methodology
The scope and version facts are drawn from NHS England’s DSPT guidance and the CQC data-security guidance for general practice. The private-clinic exemption point is an inference from the consistent NHS-nexus framing, not a quoted exemption, and is flagged as such above.
- Data Security and Protection Toolkit - NHS England Digital - https://digital.nhs.uk/cyber-and-data-security/cyber-security-services/data-security-and-protection-toolkit
- DSPT overview and who must complete it - NHS England - https://www.dsptoolkit.nhs.uk/Help/overview
- DSPT organisation types and categories - NHS England - https://www.dsptoolkit.nhs.uk/Help/5
- DSPT Version 8 and CAF v3.4 alignment - NHS England - https://www.dsptoolkit.nhs.uk/News/161
- CAF-aligned DSPT guidance - NHS England Digital - https://digital.nhs.uk/cyber-and-data-security/guidance-and-resources/caf-aligned-dspt-guidance
- NHSmail onboarding and the DSPT requirement - NHSmail Support - https://support.nhs.net/article-tags/dspt/
- Nigel’s surgery 85: data security and protection expectations for general practice - Care Quality Commission - https://www.cqc.org.uk/guidance-providers/gps/gp-mythbusters/nigels-surgery-85-data-security-protection-expectations-general-practice
- Methodology: NHS England DSPT guidance and CQC well-led guidance, read for the scope question specifically. General guidance, not legal advice. Last updated 3 July 2026.