NHS DSPT

Our position on each of the ten NDG data security standards.

The NHS Data Security and Protection Toolkit is the annual self-assessment that any organisation processing NHS data must complete. Our submission is refreshed annually and available under NDA. Here’s where we stand on each of the ten National Data Guardian standards.

NHS Data Security & Protection Toolkit compliance badge

Our position, in detail

Standard 1 — Personal confidential data

All staff sign a confidentiality agreement on onboarding, refreshed annually. Access to production data is limited to named engineers with logged break-glass procedure. Every access is audited.

Standard 2 — Staff responsibilities

Role-specific data security training on onboarding and annually thereafter. Records kept per staff member. Failure to complete blocks access to production systems.

Standard 3 — Training

Annual mandatory data security and awareness training covering phishing, incident reporting, subject access rights, and healthcare-specific handling. 100% completion enforced.

Standard 4 — Managing data access

Role-based access control at every layer — application, database, infrastructure. Access reviews conducted quarterly by the CISO. Joiner-mover-leaver process automated via IdP integration.

Standard 5 — Process reviews

Every significant process (customer onboarding, incident response, DPIA, joiner-mover-leaver, backups) is documented and reviewed at least annually.

Standard 6 — Responding to incidents

Incident response runbook covering detection, containment, eradication, recovery and lessons learned. Rehearsed quarterly. Confirmed breach notification: 24h to customer DPO, 72h to ICO where applicable.

Standard 7 — Continuity planning

Business continuity plan tested annually. Recovery time objective 4 hours, recovery point objective 15 minutes for structured data. Cross-region encrypted backup replication.

Standard 8 — Unsupported systems

No unsupported operating systems, no unsupported browsers, no unsupported dependencies in production. Dependency scanning runs on every build; anything flagged EOL is scheduled for replacement.

Standard 9 — IT protection

Endpoint protection on all staff devices. TLS 1.3 everywhere. HSTS preload. WAF and DDoS protection at edge. Vulnerability scanning weekly, penetration testing annually by independent third party.

Standard 10 — Accountable suppliers

Every supplier processing personal data has a signed DPA, is listed in our sub-processor register, and is reviewed annually. Sub-processor changes trigger customer notification with 30-day objection window.

Documents & evidence available under NDA

  • Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
  • Sub-processor register
  • Data Processing Agreement template
  • Incident response runbook (redacted)
  • Independent penetration test summary
  • Latest internal audit findings (redacted)

Need this evidence for procurement?

Send us an NDA and we’ll return the full evidence pack for NHS Data Security & Protection Toolkit within 3 working days.