Does an NHS supplier need the Data Security and Protection Toolkit?
If your organisation has access to NHS patient data or systems, check the current Data Security and Protection Toolkit, known as the DSPT, and the contract under which access is granted. Identify what data and systems your service actually touches, whether you are a direct-care provider, IT supplier or another organisation type, and which evidence category the current toolkit assigns. Do not assume that a supplier delivering services on NHS premises must use the same toolkit route as a software processor, or that a generic document store completes the assessment.
The official DSPT site says organisations with access to NHS patient data or systems use the toolkit to provide assurance about data security and handling. It is an online self-assessment against the National Data Guardian’s ten data security standards. Its 2026 to 27 version was released in September 2026, with updated outcomes, assertions and evidence items. The current year, organisation category and contract matter. This page explains how to make a scope and evidence decision. It does not list every assertion or certify that any supplier has reached a required status.
Complys may help a business organise some workforce, contractor and policy evidence, depending on its actual configuration. The public Complys site does not show that its platform submits a DSPT return, performs a cyber assessment, verifies patient-data controls or makes a supplier compliant. Keep those responsibilities with the supplier’s information governance and security leads.
Start with the service and data flow, not the supplier label
“NHS supplier” covers very different work. A contractor may repair building fabric without receiving patient information or an NHS system account. Another contractor may administer a scheduling platform containing identifiable patient data. A clinical service provider may handle records as part of direct care. A cloud host may process data on instructions from an NHS organisation. Their toolkit and contractual positions cannot be inferred from the fact that each sells something to the NHS.
Draw the actual data flow. What information enters the supplier’s systems? Is it identifiable patient data, pseudonymised information, staff data, building access data or an account that can reach an NHS system? Who provides the data, who decides its use, where is it stored, who can access it and which subcontractors are involved? If an estates worker is given a temporary system account, ask what the account can see. If a supplier says it receives only service tickets, check whether free-text tickets can include patient names or clinical details. Scope should reflect reality rather than an idealised contract summary.
The DSPT official site frames use around access to NHS patient data and systems. The official organisation-type guidance shows that organisation type and category affect the evidence presented. Some details in that help page describe earlier toolkit years, so confirm the current 2026 to 27 category and contract before relying on a threshold or category rule. If uncertain, ask the NHS customer and DSPT support rather than selecting an organisation type to minimise questions.
A supplier may also have data protection obligations independent of DSPT. The UK GDPR relationship between controller and processor depends on who decides the purposes and means of processing. The ICO guidance on controller and processor contracts explains the need for appropriate contractual terms when a processor acts for a controller. The toolkit cannot replace that agreement, and a signed contract cannot replace the controls and evidence the supplier actually needs.
Check the current year and organisation route
Use the current toolkit period. The DSPT site lists the 2026 to 27 version 9 evidence items and release notes. A prior-year submission can inform preparation, but it does not prove that the current assertions are met. New evidence items, changed wording, system requirements or audit arrangements can affect the work. Record which version and organisation category you used in the supplier’s evidence plan.
Identify the organisation that must submit. A group may have several legal entities, trading names and service lines. Do not assume a parent company’s record covers every subsidiary or site. The toolkit organisation guidance discusses parent and child arrangements when a parent assessment covers the child’s services and activities. The scope should be documented, and the NHS customer should know which legal entity and service its assurance concerns.
The DSPT organisation search lets a buyer see an organisation’s most recent published self-assessment status. This is useful evidence but not a full security review. Confirm that the name or code matches the supplier, the assessment year is current for the procurement decision and the service in the contract falls within the declared scope. A published status does not show that every subcontractor or product has been independently tested for your precise use.
The toolkit FAQ says organisations with access to NHS patient data and systems should complete a self-assessment each year, and explains that a certificate is available at specified published status levels. Do not treat the certificate as a perpetual accreditation. It represents a year and a published status. Procurement and information governance teams may require additional evidence or conditions for a particular service.
Build an evidence register for the actual assertions
Start from the current toolkit’s assertions, outcomes and evidence items rather than a generic compliance checklist. For each applicable item, assign an owner, identify the policy or operating control, locate evidence that the control works, record the period covered and set a review date. Evidence can include policy, technical configuration, training, access review, incident process, supplier contract or audit result, depending on the item. The security and information governance team should judge sufficiency. A document uploaded to a folder is only evidence if it matches the assertion and reflects current practice.
Avoid a common pattern in which one person collects documents while no one owns the control. A data-sharing or processor contract may be signed, but does it describe the live subprocessors? An access policy may say permissions are reviewed, but where is the review record? A training module may exist, but can the organisation show the relevant staff completed it? The question is not whether a file exists. It is whether the supplier can show the actual practice that the toolkit asks about.
Separate evidence by data and service. If a supplier provides a worker compliance product and a patient-facing clinical platform, the latter may bring different information governance risks. Do not copy the patient-platform evidence statement to the worker product without checking its data flows, or vice versa. The official DSPT organisation types guidance says the assessment scope for IT suppliers concerns the health and care data they process. Because some help text is year-specific, confirm the current rule for the actual entity before final submission.
An evidence register should also distinguish source from conclusion. A penetration-test report, audit result or certification may support one assertion, but it does not by itself mean all toolkit requirements are met. Record limitations and action plans. Where an item is not met, assign a remedy, owner and due date under the current toolkit process. The 2026 to 27 requirements and improvement-plan pathways should be checked on the official site at submission time. Do not publish a fixed pass threshold in a generic page when the version and category may change.
Define contracts, people and system access
If a supplier processes personal data for an NHS organisation, the parties need to define who is controller and processor for the specific processing. The ICO contract guidance covers instructions, confidentiality, security, subprocessors, data-subject support, end-of-contract handling and audit terms. These are operational commitments. A supplier should know which people can access the data, how access is approved, how it is removed and how incidents are escalated under the agreement.
Worker information is not automatically patient information, but it can still be sensitive. A healthcare staffing supplier may handle criminal-record evidence, registration details or occupational-health information while not holding patient records. The legal and contractual duties for that information still matter. Do not place confidential worker health records into a general compliance folder merely because the organisation also uses the DSPT. The ICO guidance on worker health information requires additional care with purpose, lawful basis, access and processor arrangements.
Information governance induction should be tied to actual access. NHS England information governance guidance includes contracted staff, temporary staff, students and volunteers who can access personal data among those needing appropriate data-security induction and training. A supplier’s general annual course does not settle whether an individual should have an NHS account or what privileges it should hold. The NHS host and supplier need a specific access and training arrangement.
For a non-digital estates contractor, the work may involve patient-area access without data processing. Physical access, confidentiality and site induction remain relevant, but the DSPT applicability question should be answered from the actual NHS patient-data or system access and the contract. Do not create a blanket statement that every NHS contractor needs DSPT. Equally, do not overlook a service-ticket portal or shared drive that exposes patient information merely because the contract is labelled facilities management.
Keep product claims inside the verified boundary
Complys publicly describes worker files, certificates, training matrices, contractor onboarding and document tracking across its healthcare and general product pages. These may help a supplier organise portions of workforce and contract evidence. They do not demonstrate that Complys has a DSPT module, fulfils current assertions, submits the assessment, audits the supplier’s cyber controls or handles NHS clinical records. A product demonstration and written data-flow review are needed before any stronger claim is made.
If a supplier chooses to store DSPT-related evidence in Complys, it should first decide what data is appropriate for that system, who can access it and whether the contract permits it. Keep metadata and documents proportionate. A general evidence system can hold an owner and due date for a control while the sensitive technical or patient information remains in a restricted security repository. The tool should support the governance plan, not become an unreviewed second copy of confidential data.
The Complys training matrix describes learning records and alerts, and its contractor workflow describes supplier compliance documents. Those are reasonable aids for someone who needs to organise workforce evidence. They should not be presented as a route to DSPT certification. The user’s question is whether a particular supplier service is in scope and what independent evidence the current toolkit requires.
Worked examples
Maintenance company with no NHS data access
A maintenance company repairs external doors at a hospital. Its workers use a paper job order with room numbers, receive site induction and work under local access controls. The company does not receive NHS patient data or an NHS system account under this contract. Its estates and safety obligations remain substantial, but the team does not automatically claim that the DSPT applies merely because the customer is an NHS trust. It asks the trust to confirm any patient-data or system access in the actual workflow and checks the contract. If a new digital ticketing portal later exposes patient information, the scope decision is revisited.
Digital rota supplier with patient data
A software supplier hosts a service scheduling system that includes patient identifiers and appointments. The data flow shows who sends the information, where it is processed, which support staff can view it and which cloud subcontractors are involved. The supplier and NHS customer define contractual roles and current DSPT expectations. The supplier selects the correct toolkit organisation route, assigns owners for the 2026 to 27 assertions, and records current security evidence. A certificate from the previous toolkit year is not presented as final assurance for the new service.
Staffing supplier with worker records only
A healthcare agency stores worker training, professional registration and right-to-work evidence. It does not access NHS patient records under one contract, but it handles sensitive worker information and may log into an NHS portal under another. The agency maps the contracts separately, seeks the NHS customer’s requirements and applies UK data protection controls to worker information in any case. It does not use a generic “NHS supplier” label as the only test for DSPT scope. A future portal account triggers a fresh check.
A practical scoping and evidence checklist
This is a management checklist, not a legal eligibility calculator or a substitute for the live toolkit instructions. The most important output is a documented, accurate scope decision. Without it, a supplier can spend time assembling irrelevant documents while missing the actual patient-data risk.
- Write down the legal entity and the NHS customer or service contract.
- Map patient-data and NHS-system access, including staff and subcontractors.
- Identify controller, processor and other roles for each processing activity with legal and information governance advice.
- Confirm current DSPT applicability, organisation type and toolkit year through official guidance and the customer.
- List applicable assertions and assign control and evidence owners.
- Check whether evidence is current, service-specific and supported by actual practice.
- Resolve missing controls or document a current approved improvement route.
- Review contracts, subprocessor access, staff training and account removal.
- Publish and verify the correct organisation’s status as required, then plan the next annual review.
- Reassess when the service, data, system access, subcontractors or toolkit version changes.
FAQs
Is the DSPT mandatory for every company that sells to the NHS?
The official DSPT site frames use around access to NHS patient data and systems. Contracts and organisation categories also matter. A seller with no such access should not assume it has the same route as a data processor. Ask the customer and check the current official guidance for the actual service. Other procurement or confidentiality requirements may still apply.
Does a published DSPT status mean the supplier is secure for any service?
No. It is a published self-assessment status for an organisation and year. A buyer should confirm the entity, time period and service scope, then assess the particular data flow, contract and risks. Additional assurance may be needed. The toolkit organisation search is one source of evidence, not a substitute for supplier due diligence.
Can a supplier reuse last year's answers?
Past evidence may help, but review it against the current year's assertions and real controls. The official site released new 2026 to 27 evidence items in September 2026. A copied policy or answer can be inaccurate if systems, suppliers or access arrangements changed.
Does Complys make a supplier DSPT compliant?
No. Complys may help organise some workforce or contractor evidence if the supplier's product configuration and data governance permit it. It does not submit the toolkit, map current assertions, audit cyber controls or process NHS patient records. The supplier's authorised information governance team must complete the actual toolkit assessment and maintain the security controls.
Where Complys fits
Complys can help organise some workforce and contractor evidence, such as worker documents, training records, contractor onboarding files and review dates. Storing worker documents in Complys does not make a supplier DSPT compliant, does not submit or map the toolkit, and Complys is not a patient-record system, a cyber assessor or a security control set. The scope decision and the actual toolkit assessment stay with the supplier’s authorised information governance and security leads, and the DSPT itself is completed on the official NHS England site.
Sources
- NHS England: Data Security and Protection Toolkit
- DSPT: organisation types guidance
- DSPT: frequently asked questions
- DSPT: organisation search
- ICO: controller and processor contracts
- ICO: workers’ health information
- NHS England: information governance and data protection
Related: training matrix software, and sector pages for hospitals and clinics.