The DSPT is one of those acronyms that quietly decides whether you can plug into NHS infrastructure. Some telehealth operators must complete it; many assume they must and don't; a few need it and have no idea. Getting the question right matters, because the answer gates access to NHS systems and shapes how you evidence data security. Here is who needs a DSPT and how to approach it.

What the DSPT actually is

The Data Security and Protection Toolkit is an online self-assessment, run by NHS England, that organisations use to measure and evidence their data security against a defined set of national standards. It is completed annually and results in a published status — broadly, whether an organisation has met the required standard or is still working toward it.

Crucially it is a self-assessment backed by evidence, not a certification someone awards you. You attest to your controls and, where required, provide supporting evidence. The value — and the scrutiny — comes from whether that attestation reflects reality.

Who needs a DSPT and who doesn't

The practical trigger is your relationship with NHS data and systems. If you access NHS patient data or connect to national services — NHSmail, GP Connect, the Electronic Prescription Service and similar — a current DSPT is typically a precondition. The NHS will not generally let you integrate without one.

A purely private telehealth service that never touches NHS data or systems often does not need a DSPT at all. But two cautions apply: first, confirm the position for your specific integrations rather than assuming; second, not needing a DSPT does not lower the bar — you still owe the same duties under UK GDPR. See our guide to UK GDPR for telehealth.

The ten data security standards

The toolkit is organised around ten data security standards spanning people, process and technology — covering areas such as personal responsibility and training, managing access, protecting data, responding to incidents, keeping systems up to date, and holding suppliers to the same standard. They are deliberately broad, because data security is not a single control.

For a telehealth operator the supplier dimension is easy to underestimate: your dispensing partner, identity-verification provider and hosting all sit inside your data-security perimeter, and the standards expect you to account for them, not just your own systems.

How the assessment works

Completion is an annual cycle: you work through the toolkit's questions, attest to each control, attach evidence where required, and submit by the national deadline. The outcome is a status against the required standard, and the assessment is expected to be kept current — it is a yearly commitment, not a one-off.

The work is real. A first submission for a growing operator is weeks of effort to gather evidence, close gaps and document controls honestly. Padding it to reach a status you have not genuinely met is the failure mode — the evidence has to hold up.

Key takeaway

The DSPT question turns on one thing: do you touch NHS data or connect to NHS systems? If yes — NHSmail, GP Connect, EPS and similar — a current DSPT is typically a precondition. If no, you often don't need one, but you still owe the same duties under UK GDPR.

DSPT versus UK GDPR and Cyber Essentials

These regimes overlap but are not the same. UK GDPR is the legal baseline for handling personal data and applies regardless. Cyber Essentials is a technical-controls certification. The DSPT is the NHS-facing data-security assessment that gates NHS integration. A mature operator runs all three as one coherent programme rather than three disconnected projects.

The efficiency is in the shared evidence: much of what satisfies the DSPT also supports your UK GDPR accountability and your security certifications. Our guide to telehealth cybersecurity essentials covers the technical side that underpins all three.

Not needing a DSPT does not lower the bar. A purely private service still owes the same data-protection duties under UK GDPR — the toolkit is the NHS-facing evidence of them, not the reason to have them.

Common DSPT pitfalls

The recurring failures are familiar: attesting to controls that are aspirational rather than operational, ignoring the supplier dimension, treating the submission as a one-off and letting it lapse, and thin evidence that would not survive a closer look. Each is visible to anyone who checks, and each undermines the assurance the DSPT is supposed to provide.

The fix is discipline: complete it honestly, keep the evidence current, and align it with your records and retention practice. Our guide to records and retention covers the documentation habits that make an annual submission far less painful.

How PExpo supports DSPT

PExpo operates the regulated layer with the data-security controls the toolkit expects, and a defined split of responsibilities documented in the DPA — so a brand connecting through PExpo is not evidencing the shared infrastructure from scratch. The brand-side and customer-specific controls remain yours to attest.

That accelerates a DSPT submission for operators who need one, and keeps the shared-layer evidence consistent. See our brand model for the scope, our DPA for the responsibility split, or our UK GDPR guide for the legal baseline.

The DSPT rewards operators who answer the 'do we touch NHS data' question honestly, then treat the toolkit as an annual, evidence-backed discipline aligned with their UK GDPR and security programme rather than a box-tick. See our guides to UK GDPR for telehealth and cybersecurity essentials, or our brand model.

Frequently asked questions

Does a private UK telehealth service need a DSPT?

Generally only if it accesses NHS patient data or connects to NHS systems such as NHSmail, GP Connect or the Electronic Prescription Service. A purely private service that never touches NHS data or systems often does not need one, but should confirm the position for its specific integrations and still meet UK GDPR requirements.

What is the DSPT based on?

The Data Security and Protection Toolkit is an annual NHS England self-assessment organised around ten national data security standards, spanning people, process and technology — including training, access management, data protection, incident response, system maintenance and supplier assurance.

How is the DSPT different from UK GDPR and Cyber Essentials?

UK GDPR is the legal baseline for personal data and applies regardless. Cyber Essentials is a technical-controls certification. The DSPT is the NHS-facing data-security assessment that gates NHS integration. They overlap and are best run as one programme with shared evidence.