Data Security and Protection Toolkit


As part of the digital offer, The Data Security and Protection Toolkit (DSPT) should be completed by all CQC registered Care providers every year. It is an online self-assessment tool for demonstrating compliance with the ten data security standards for health and social care organisations.

In less than four minutes, the film looks at how the Data Security and Protection Toolkit helps you to check your data and cyber security policies, procedures and practices – and demonstrate that you have good systems in place.

Achieving standards met within the DSPT is a contractual requirement with CCGs and Local Authorities

You will benefit by potentially having access to:

  • NHS Mail - allows you to exchange information securely and quickly.
  • Remote monitoring - A platform on which to record resident observations to support rapid assessment of vulnerable care home residents.
  • Proxy Access - with proxy access you can order medication on behalf of your service users. Co-ordinate my Care - a service that coordinates urgent care for patients.
  • GP Connect

You can use the DSPT as evidence for:

  • Your compliance with Data Protection Legislation
  • CQC Key Lines of Enquiry (KLOEs)
  • GDPR/ DPA 2018
  • 10 Data Standards - NHS and council contracts

The following Adult Social Care DSPT training is available now. Presentation attached

There are three stages to the toolkit.

  1. You will need to Register and set up a
  2. Once you have registered you will be able to complete the questions to Publish at Approaching
  3. You will then be presented with additional questions in order to complete to Standards

The overall aim is to get to Standards met - This is full compliance for social care organisations. We have developed a comprehensive guide to help you to complete the toolkit in the Downloads section on this page.

Approaching Standards

Approaching Standards consists of 27 mandatory questions. You can complete the non - mandatory questions at this stage. If you are unable to complete all of the mandatory questions, you will be required to download an action plan which will be pre-populated with your outstanding questions.

Standards Met

There are a further 17 questions to answer in this section. Once you have completed these questions you will be able to publish at standards met and therefore, be fully compliant.

Before registering for the toolkit you will need to consider whether you are registering as a single- site or multi-site organisation. If you have more than one home with the same policies and procedures in place you are able to complete your toolkit once and claim for all the sites.

All sites will have an Organisation Data Service Code (ODS code). All Care Home and Domicillary providers will have at least two codes, a 'HQ' code which usually begins with an A or a C and is followed by 4 digits and child code for the actual site which starts with a V.

Single site providers or domicillary care providers operating out of one office can use either their HQ code or their child code.

Multi-site organisations which are one legal entity should register with the parent 'HQ' code as this will allow you to claim for all of your sites. Once you have registered for the DSPT toolkit you will need to email exeter.helpdesk@nhs.net for your HQ functionality to be turned on.

To find your ODS code please go to https://odsportal.digital.nhs.uk/Organisation/Search

To Register

  • Click on this link: https://www.dsptoolkit.nhs.uk/Account/Register
  • Insert the ODS code for your organisation and press “continue”
  • Insert your user Make sure the email address you provide is a work email address
  • You will then be sent an email containing a link which you click on, this takes you back to the registration page for you to set up your

To complete your organisation profile

  • Go to https://www.dsptoolkit.nhs.uk/Account/Logi Enter your login details
  • Click on the "Continue to questions" button to complete your profile
  • Choose your Organisation You should select "Social care"
  • You will be asked who has the following roles in your organisation: Caldicott Guardian, Senior Information Risk Owner, Information Governance Lead, Data Protection Some of these positions may not be relevant to your organisation and you can leave these blank.

If you click “continue” you will move on to the next page.

You will be asked if your organisation uses NHSmail or has a Cyber Essentials Plus certification. Make sure you select the right option or “Not Sure” if you are uncertain.

  • Check your answers and make changes if Once you’re happy, click “Accept and Submit”. You can go back and make changes at any point.

There is plenty of additional support and resources available to help you to complete your Data Security and Protection Toolkit. Please see below for additional websites and contact details.

The Data Security and Protection Toolkit - Digital Social Care

You can contact Digital Social Care directly at

For help with registration on the Data Security and Protection Toolkit (DSPT)

For help with Information Governance Queries 

We have a comprehensive DSPT guide in the downloads section (right) which will assist you with completing your toolkit.

If you need 1:1 support outside of these times, please email the team at ELHCP.digitalfirstcare@nhs.net for further assistance. This mail box will be monitored Monday to Friday from 8am to 5pm


Updated: 20/01/2022