Data Security and Protection Toolkit (DSPT): The 30 June Deadline Explained

DSPT is an annual self-assessment against 45 mandatory data security standards, due every 30 June. Here's what Standards Met vs Approaching Standards actually means, and why DSPT sits alongside CQC compliance rather than as a separate IT exercise.

Learnsignal Education Team
4 min read
Updated

Every UK care provider handling NHS or adult social care data has one fixed date to work towards each year: 30 June. That's the annual deadline for the Data Security and Protection Toolkit (DSPT) — and unlike a lot of compliance paperwork, DSPT isn't a one-off form. It's a self-assessment against 45 mandatory data security standards, and the difference between passing and failing it has real consequences for a provider's ability to access NHS systems and demonstrate CQC compliance.

What the DSPT actually covers

The toolkit assesses an organisation across four areas: staffing and roles (staff responsibilities and training requirements), policies and procedures (data protection policies, privacy notices, supplier management, retention and disposal), data security itself (physical security, breach response, business continuity), and IT systems and devices (mobile device management, password protocols, backups, system security). It's a genuinely operational assessment, not a box-ticking policy review — assessors expect evidence that these practices are actually in place, not just documented.

The standards, and what "passing" means

DSPT has tiered achievement levels. To reach Standards Met — the target level for every provider — an organisation has to answer all 45 mandatory questions satisfactorily. Approaching Standards, a lower bar of 26 questions, is acceptable for a first-time submission provided the organisation has a credible action plan for closing the gap. Anything below that is recorded as Not Met. The distinction matters beyond the paperwork: NHS Digital and commissioners use DSPT status as a genuine signal of data security maturity, and a "Not Met" or missing submission can affect a provider's ability to access NHS Mail, shared care records, and other NHS digital services.

Why this sits alongside CQC compliance, not separate from it

DSPT isn't a parallel, unrelated compliance track. Data security failures — a lost device with unencrypted resident records, a breach that goes unreported, a supplier contract with no data processing terms — are exactly the kind of failure that surfaces in a CQC inspection under the "Well-led" and "Safe" domains. A provider treating DSPT as an IT-department-only exercise, separate from the compliance function that owns CQC readiness, is missing that the two are assessing overlapping risk from different angles.

Building DSPT into the annual compliance calendar

  • Don't treat 30 June as a surprise. Because DSPT has to be renewed every year, not just completed once, it belongs on the same recurring compliance calendar as CQC readiness reviews and policy reviews — not as an annual scramble.
  • Assign clear ownership across IT and compliance. The 45 standards span staffing, policy, and technical controls — no single department owns the full toolkit, so DSPT needs a named coordinator pulling evidence from IT, HR, and compliance rather than defaulting to whichever team happens to notice the deadline first.
  • Treat "Approaching Standards" as a genuine warning, not a pass. It's an acceptable starting point for a new submission, but an organisation that stays at Approaching Standards year after year without visible progress toward the full 45 questions is building a pattern an inspector or commissioner will notice.
  • Keep evidence current, not retrospective. Policies, breach logs, and staff training records need to reflect current practice at submission time — a policy document that hasn't been touched since the previous year's submission is a red flag even if the underlying practice has genuinely improved.

Where the risk actually sits

The areas that most commonly trip up first-time or renewing submitters are the operational ones: incomplete supplier due diligence (does every third-party data processor have an actual data processing agreement on file), device management for staff using personal phones for work communication, and breach response plans that exist on paper but have never been tested. None of these are exotic requirements — they're the same discipline that underpins good incident investigation and documentation practice, applied specifically to data rather than clinical incidents.

Frequently asked questions

Is DSPT only relevant to NHS organisations?
No. Any care provider handling NHS or adult social care patient data — including independent care homes and domiciliary care agencies — is expected to complete DSPT, not just NHS trusts.

What happens if a provider misses the 30 June deadline?
A missed or lapsed submission can affect access to NHS digital services (such as NHS Mail and shared care records) and is visible to commissioners and regulators as a compliance gap, even without a single specific penalty attached to the date itself.

Does reaching "Standards Met" once mean it's done?
No. DSPT is an annual requirement — the toolkit has to be reassessed and resubmitted every year, and standards can be tightened between versions, as happened with the toolkit's most recent update.

Data security compliance is now inseparable from care-quality compliance. Learnsignal's CPD training library covers data protection, information governance, and the wider compliance training healthcare organisations need to keep pace with DSPT and CQC requirements together.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience in teaching and helping students achieve their accounting qualifications.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Healthcare Compliance & CPD Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans