NHS DSPT
Our position on each of the ten NDG data security standards.
The NHS Data Security and Protection Toolkit is the annual self-assessment that any organisation processing NHS data must complete. Our submission is refreshed annually and available under NDA. Here’s where we stand on each of the ten National Data Guardian standards.
Our position, in detail
Standard 1 — Personal confidential data
All staff sign a confidentiality agreement on onboarding, refreshed annually. Access to production data is limited to named engineers with logged break-glass procedure. Every access is audited.
Standard 2 — Staff responsibilities
Role-specific data security training on onboarding and annually thereafter. Records kept per staff member. Failure to complete blocks access to production systems.
Standard 3 — Training
Annual mandatory data security and awareness training covering phishing, incident reporting, subject access rights, and healthcare-specific handling. 100% completion enforced.
Standard 4 — Managing data access
Role-based access control at every layer — application, database, infrastructure. Access reviews conducted quarterly by the CISO. Joiner-mover-leaver process automated via IdP integration.
Standard 5 — Process reviews
Every significant process (customer onboarding, incident response, DPIA, joiner-mover-leaver, backups) is documented and reviewed at least annually.
Standard 6 — Responding to incidents
Incident response runbook covering detection, containment, eradication, recovery and lessons learned. Rehearsed quarterly. Confirmed breach notification: 24h to customer DPO, 72h to ICO where applicable.
Standard 7 — Continuity planning
Business continuity plan tested annually. Recovery time objective 4 hours, recovery point objective 15 minutes for structured data. Cross-region encrypted backup replication.
Standard 8 — Unsupported systems
No unsupported operating systems, no unsupported browsers, no unsupported dependencies in production. Dependency scanning runs on every build; anything flagged EOL is scheduled for replacement.
Standard 9 — IT protection
Endpoint protection on all staff devices. TLS 1.3 everywhere. HSTS preload. WAF and DDoS protection at edge. Vulnerability scanning weekly, penetration testing annually by independent third party.
Standard 10 — Accountable suppliers
Every supplier processing personal data has a signed DPA, is listed in our sub-processor register, and is reviewed annually. Sub-processor changes trigger customer notification with 30-day objection window.
Documents & evidence available under NDA
- Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
- Sub-processor register
- Data Processing Agreement template
- Incident response runbook (redacted)
- Independent penetration test summary
- Latest internal audit findings (redacted)
