Data Security and Protection Toolkit 2025-26 update
FAO: Practice Managers and DSPT Leads,
Please note: practice DSPT submission needs to be completed by Tuesday 30 June 2026. All GP practices are required to complete the toolkit annually and must achieve ‘Standards Met’ accreditation.
What is new, what has been updated
This year two mandatory new evidence requirements have been introduced, three have been amended, and six non-mandatory evidence items have been included. More information about the two new mandatory evidence items can be found here:
- DSPT Evidence Item 4.3.1 (Mandatory) – IT Administrator Accountability
- DSPT Evidence Item 7.1.1 (Mandatory) – Digital Asset Register
NHS NEL GP DPO Service help guide
As we have done in previous years, we have issued a help guide for GP practices, which can be found on the NHS NEL GP DPO Service SharePoint site: A3A8R_GPDSPT – Home.
The guide includes general compliance advice for all 45 evidence requirements (mandatory and non-mandatory), links to national policies and guidance, templates, and the GP IT evidence and statements you need for your DSPT submission.
NEL ICB GP IT evidence
The NHS NEL GP DPO Service help guide includes the GP IT statements and evidence for your DSPT submissions. GP IT have provided information for the following evidence item requirements: 4.3.1; 4.5.3; 6.2.1; 7.1.1; 7.3.4; 8.3.1; 9.1.1; 9.2.1; 9.5.2; 10.1.2 and 10.2.1.
NHS England training / knowledge refresher
If you are new to DSPT work or you need a knowledge refresher, please join one of the NHS England DSPT webinars, the next one is on the 15 April – visit the support page for more information: Data Security and Protection Toolkit Support.
Focused campaign – improving GP practice privacy notices
Many of our GP practices across NEL have privacy notices that have not been maintained since the introduction of the General Data Protection Regulation (GDPR), are you one of them? Please check! A GDPR compliant patient and service user privacy notice template has been issued for GP practices to use:
DSPT Evidence Item 1.1.3 (Mandatory) – Privacy Notices.
NHS NEL GP DPO Service update
NHS NEL GP DPO Service contact details
Information governance advice and guidance contact details
For information governance advice and guidance please log your data protection query with the NHS NEL Service Desk at Itservicedesk.nelicb@nhs.net or 0300 303 6778 (never include patient identifiable information).
For advice and guidance on data breaches, directly email the DPO at nel.gpdpoig@nhs.net.
GP practices: Please log your data protection query with the NHS NEL Service Desk at Itservicedesk.nelicb@nhs.net or 0300 303 6778 (please do not include PID).