Data Security & Protection Toolkit (DSPT) 2025-26 (version 8) Certificate - Standards Exceeded
This certificate is evidence that the practice has completed a Data Security and Protection Toolkit self-assessment to demonstrate it is practising good data security and that personal information is handled correctly and has exceeded the required standards.
This certificate is valid to 30th June 2027.
You can download the certificate by clicking the link below
1.1.1 What is your organisation's Information Commissioner's Office (ICO) registration number?
What is your organisation's Information Commissioner's Office (ICO) registration number?
ICO Registration reference: Z9076518
1.1.2 - TVMP - GDPR Data Flow Mapping and Asset Register GP
Does your organisation have an up to date list of the ways in which it holds and shares different types of personal and sensitive information?
Yes - see policy at link below.
1.1.3 - TVMP - GDPR - DSP Toolkit - Privacy notice
Does your organisation have a privacy notice?
Yes - Download our policy by clicking the link below
1.1.5 - TVMP - GDPR - DSP Toolkit - Data Protection Officer Job Spec and Responsibilities
Your organisation's approach to security is owned and directed by senior responsible individuals, with regular discussions driven by individuals who have overall accountability for security.
Yes - see Job Spec and Responsibilities below
1.2.4 - TVMP - GDPR - DSP Toolkit - National Data Opt Out Policy
1.3.1 Data Protection Data Security and Cyber Security Policies
Does your organisation have up to date policies in place for data protection and for data and cyber security, aligned with good practice guidance and (where applicable) national policies?
Yes.
Download our policies by clicking the links below
1.3.2 - Does your organisation monitor your own compliance with data protection policies and regularly review the effectiveness of data handling and security controls?
Yes. Staff are constantly reviewed and spot checked for confidentiality and data protection and these are managed through staff performance reviews. Any data protection issues and breaches by staff are also noted and these are dealt with either in the form of individual or team learning events or Significant Event Audit meetings.
All data breaches are recorded on a "Breach Reporting Form". These forms are then sent to the DPO for advice on what action should be taken. A breach log is maintained and all breaches are recorded on it. We have had 16 data breaches this year.Breach reporting policy and procedure
Please click below to download our Data Security Audit Checklist
1.3.8 - TVMP- GDPR - Data Protection Impact Assessment (DPIA) Policy
Does your organisation's data protection policy describe how you identify and minimise risks to personal data when introducing, or changing, a process or starting a new project involving personal data?The Data Protection and DPIA policy documents describe how we identify and minimise risks to personal data, when introducing, or changing, a process or starting a new project involving personal data. We do this by performing a Data Protection Impact Assessment (DPIA) risk assessment at the preliminary stages of any new project which involves processing personal data.
These have been uploaded to the Practice Index - Library - DSP Toolkit page which can be found at:
https://hub.practiceindex.co.uk/library/24196/gdpr-dspt-toolkit.
These documents can be downloaded, directly, using the internet links below.
https://hub.practiceindex.co.uk/file/87e69de7-4890-489e-9aa0-fa639b080434
https://hub.practiceindex.co.uk/file/ecb0bfe8-1da3-4da1-b210-2b6be3989ffd
1.3.13 - Briefly describe the physical controls your buildings have that prevent unauthorised access to personal data.
Staff areas are secured by the use of a door access control system using FOBs which are issued to staff members. Furthermore, paper records are stored in lockable rooms. Patient records are stored in lockable cupboards / drawers which are specifically designed for the purpose. Other sensitive paper records are stored in the secure staff area in lockable cupboards/filing cabinets.
1.4.1 - TVMP - GDPR - Record retention schedule Policy
Does your organisation have a timetable which sets out how long you retain records for?
Yes - see Policy below
1.4.3 TVMP - GDPR - Records maintained appropriately
If your organisation destroys any records or equipment that hold personal data, how does it make sure that this is done securely?
Generally, paper medical records are not destroyed. They are usually returned to the PCSE either: to be forwarded to
the new practice for patients who have relocated to a new surgery or for retention in the case of deceased patients.
However, the practice is participating in the pilot of the new NHS England National Document Repository (NDR). This is a secure online portal for storing Lloyd George records digitally. A Lloyd George record can contain the following documents: scanned paper notes, electronic health record (EHR) notes, electronic health record (EHR) attachments and other letters and documents for a patient. If the practice uploads this information to the NDR, then the physical paper medical record, (Lloyd George or FP111), is destroyed using our secure shredding service.
All paper documents that contain patient identifiable details or fall under the remit of GDPR regulations are securely stored onsite in locked shredding cabinets until they are shredded, once a month, onsite by a licenced mobile data shredding company.
Old computers and laptops, as they remain the property of NHS England, and hence the responsibility of our IT services company, ITS Digital, are disposed of securely. Mobile phones and memory sticks are prevented from accessing the network through security policies. The use of CD/DVDs is restricted to a small number of users, and these are shredded if no longer needed. Any paper that contains patient identifiable information is placed in shredding bins and the services of a certified shredding and disposal company are employed to periodically empty the shredding bins and shred the contents whilst onsite.
2026 DSPT Version 8 – GP Category 4 Statement by our ICB commissioned IT services provider, ITS Digital
1.4.3: Data on hard drives and solid-state drives on from the GPIT Infrastructure are destroyed by Pure Planet Recycling Ltd who hold ISO14001 certification and shred data storage media while at ITS Digital's premises. Shredding evidence is checked by ITS Digital and signed off before they leave site with the waste for recycling.
2.1.1 - Does your organisation have an induction process that covers data security and protection, and cyber security?
Yes, all new staff are required to undertake a comprehensive induction process. This always includes UK GDPR training unless they can demonstrate that they have undertaken relevant training in the last year.
All staff complete mandatory Data Security Awareness training on commencement of employment and annually thereafter. Compliance is monitored via training records, with non-compliance followed up by management. Training includes GDPR, confidentiality, and safe use of IT systems
2.2.1 - Do all employment contracts, and volunteer agreements, contain data security requirements?
Do all employment contracts, and volunteer agreements, contain data security requirements?
Yes - see policy below
3.2.1 - TVMP - GDPR - UKGDPR Training record June 2026
Have at least 95% of staff, directors, trustees and volunteers in your organisation completed training on data security and protection, and cyber security, in the last twelve months?
Yes - please see the UKGDPR Training record below
4.1.1 - Does your organisation have an up to date record of people and their roles?
Yes - all staff records are stored securly on Practice Index
4.2.4 - Does your organisation have a reliable way of removing or amending people's access to IT systems when they leave or change roles?
Yes, in Practice Index, we have implemented "HR Check" one of which is Leaver's Checklist that lists all the systems to which a user has access, (see 4.1.1 for data source). We use this to ensure that, when employees leave, they are removed from, and unable to access our systems or, in the case of changing their roles, their system access rights are amended accordingly.
ITS Digital as the IT support provider will action, upon request from the organisation, amendment or removal of access as appropriate.
4.3.1 - Have all the administrators of your organisation's IT system(s) signed an agreement to hold them accountable to higher standards?
Yes -
IT support for the practice servers has been outsourced, by BLMK Clinical Commissioning Group (BCCG), to Herts Beds and Luton ICT (HBLICT) who have sub-contracted these responsibilities to ITS Digital. All HBLICT staff have signed the Standards accountability agreement that can be found at:
ITS Digital statement:
2026 DSPT Version 8 – GP Category 4 Statement: Yes, all system administrators have signed an agreement which holds them accountable to the highest standards of use.
4.4.1 - The person with responsibility for IT confirms that IT administrator activities are logged and those logs are only accessible to appropriate personnel.
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement: ITS Digital ensures that logs, including privileged account use, are kept securely and only accessible to appropriate personnel. Privileged accounts are reviewed regularly, and processes exists where the Server Teams are alerted to any changes to these accounts. Server Logs are held on an in-house management tool. Network logs are held in-cloud behind MFA and PIM. Logs cannot be tampered with by end users.
Download the statement by clicking the link below
4.5.3 - Multi-factor authentication is used on all remotely accessible user accounts on all systems, with exceptions only as approved by a relevant board or senior management.
Yes -
All remote systems (VPN, VDI) require the user to have active MFA before allowing access.
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement: All remote systems (VPN, VDI) require the user to have active MFA before allowing access.
All systems have a password complexity requirements and staff are informed of password best practices.
Download the statement by clicking the link below
5.1.1 - If your organisation has had a data breach or a near miss in the last year, has the organisation reviewed the process that may have allowed the breach to occur?
Yes - see statement below:
We have had 16 data breaches in the past year. All of these were reported to our external DPO. The advice we received from the DPO was that they were all categorised as minor breaches. These did not require escalation beyond practice level as they were all controlled and contained. On each occasion, we sent an email to all staff reminding them of the importance of checking the patient details and letters/forms before sending, to ensure they are being sent to the correct patient. Affected patients were also informed of the breaches. We also reviewed the processes that were being used when the breaches occurred with a view to making them more robust and reducing the chances of errors and breaches happening. Breaches have also been discussed and documented at the Practice Clinical Meetings.
5.2.1 - Are the actions to address problem processes, being monitored and assurance given to the senior team?
yes - Breaches are reported and documented at the Practice Clinical Meetings. Senior Team tomonitor these closely.
6.1.1 - Does your organisation have a system in place to report data breaches?
Yes - Breaches are reported on the GDPR Data Breach Form and also in Practice Index on the Breach Reporting Log.
6.1.3 - If your organisation has had a data breach, were all individuals who were affected informed?
Yes - As per breach policy and DPO was contacted to assess the magnitude of the breach, (all of which were deemed to be minor), to allow us to ascertain what actions, if any, were required. The DPO deemed that no external disclosure was necessary and that we should use the incident as an internal learning opportunity at practice level only.
6.2.1 - Do all the computers and other devices used across your organisation have antivirus/antimalware software which is kept up to date?
Yes - we have this assuranc through ITS Digital who have provided the organisaion with the Cyber Essential PLUS certification.
7.1.1 - Do you have a digital asset register detailing your organisation's hardware and software , which is kept up to date?
Yes.
ITS Digital, (Practice's IT Provider), confirmation statement:
:
2026 DSPT Version 8 – GP Category 4 Statement: Confirmed for all GPIT assets.
The statement can be downloaded, directly, using the internet link below:
7.1.2 Does your organisation have a business continuity plan that covers data and cyber security?
Yes. Our systems and services, including IT systems and the main surgery telephone systems are hosted offsite, cloud based services. They have all been configured in such a way that we would be able to relocate operations to our other surgery site with the minimum of disruption. Furthermore, our IT systems provider have advised us that our two Windows File servers have been configured to use replication services so that both servers are kept synchronised with the latest data.
All supplier contact information, to be used in the event of an emergency or failure is stored on the replicated servers or on cloud based secure systems that can be accessed remotely or from the unaffected surgery.
We also have a Business Continuity Plan (BCP), that is regularly updated, that serves as a quick reference document.
Our Business continuity plan can be dowloaded by clicking the link below.
7.3.2 Are all emergency contacts are kept securely, in hardcopy and are up-to-date.
In order to comply with GDPR, we no longer maintain a hard copy of staff contact information. Version control will make this information out of date very quickly and therefore, we now ensure that staff contact information is maintained electronically within the Practice Index Hub, our secure staff management and training platform. This system is hosted externally and can be accessed remotely by authorised personnel in the event of an incident that prevents access to the practice's on-site systems or data storage locations.
The Practice Index Hub provides a single, centrally managed source of staff contact information, enabling records to be updated promptly and ensuring version control is maintained. This approach reduces the risk of outdated information being held, and supports effective communication with staff during business continuity and incident management situations.
Access to the system is restricted to authorised users and managed in accordance with the practice's information governance and data protection requirements.
7.3.4 How does your organisation make sure that there are working backups of all important data and information?
Our external IT system supplier, ITS Digital, have assured us that this evidence item is complied with. We have three backup data disks that we rotate, over the course of the week, to ensure that we always have the latest backup offsite in case we have an incident, at the practice, that prevents access to the premises and the server.
The surgery's server holds our shared drives + user documents
- The server has volume shadow copies of all of the data for the shared drives on the current drives (taken twice a day)
- Each server has a mirrored RAID array as redundancy for the data should a drive fail internally
- Each server then backs up each night to an external USB hard drive via Acronis Backup
- Any failures are reported to ITS Digital via email – the surgery is then contacted to resolve the issue if needed
- This USB drive is rotated by the surgeries on a Monday, Wednesday, Friday
Drives that are not in use are taken off site and stored securely or stored in a fireproof safe on site
All of the data on the drives are encrypted for security
8.1.4 Are all the IT systems and the software used in your organisation still supported by the manufacturer or the risks are understood and managed?
Yes.
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement: Confirmed for all GPIT related software and systems.
8.3.1 How do you make sure that the latest software updates are downloaded and installed promptly?
IT support for the practice has been outsourced, to Herts Beds and Luton ICT (HBLICT) who have sub-contracted these responsibilities to ITS Digital. As part of this arrangement, the practice is not able to install software on our IT systems. Responsibility for the strategy for security updates therefore lies with these organisation as the practice has no control over this. They have advised us of the following:
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement: We deploy updates at the earliest opportunity after Microsoft publishes them and they have been tested. We deploy daily deployment for AV updates and for other systems upgrades as and when advised by suppliers if not applied automatically. The GPIT infrastructure is monitored via MDE, which provides real-time security monitoring, advanced threat detection, vulnerability management and automated investigation & response, amongst others.
8.3.8 - Your organisation is registered for and actively using the NCSC early warning service.
Yes.
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement:
Not required. The GPIT infrastructure is monitored via MDE, which provides very thorough protection from both an endpoint and network scanning perspective, with comprehensive malware detection that is overseen by a national NHS team, as well as end point software integrated into the operating system and managed by GPO. NHS England’s Cyber Security Operations Centre (CSOC) monitors for new threats and attacker activity 24 hours a day, 7 days a week, providing real-time protection – we also utilise the CSOC Secure Boundary service, which uses next generation firewall (NGFW) and web application firewall (WAF) protection to protect internet traffic from digital and cloud-based threats.
MDE and CSOC services provide real-time monitoring and protection, whereas the NCSC early warning system simply provides details of potential cyber issues gathered from a variety of cyber threat intelligence feeds, all of which already part of the MDE and CSOC services already in use.
8.4.3 - You identify and understand security vulnerabilities in your systems, such as through regular vulnerability testing
Yes.
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement: Confirmed for the managed GPIT infrastructure.
Download the statement by clicking the link below
9.1.1 Does your organisation make sure that the passwords of all networking components, such as a Wi-Fi router, have been changed from their original passwords?
We can confirm this because we are are Cyber Essentials PLUS certifified.
9.2.1 - The annual IT penetration testing is scoped in negotiation between the Board/person with delegated responsibility for data security, business and testing team including a vulnerability scan and checking that all networking components have had their default passwords changed to a high strength password.
We can confirm this because we are are Cyber Essentials PLUS certifified.
9.5.2 Are all laptops and tablets or removable devices that hold or allow access to personal data, encrypted?
Yes.
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement: Confirmed that all laptops and tablets supported on the GP IT infrastructure are encrypted. We employ port control to prevent data being copied to removable media.
Download the statement by clicking the link below
10.1.2 Does your organisation have a list of its suppliers that handle personal information, the products and services they deliver, and their contact details?
Yes - Spreadsheet and document management systems. Currently in the process of migrating all this information to Practice Index portal
10.2.1 Do your organisation's IT system suppliers have cyber security certification?
Yes.
Our IT Systems suppliers have confirmed this for all their subcontractors as per the link below. Please note that the practice does not use any other systems (e.g. telephony systems) that have access to the clinical system or the HSCN network
ITS Digital, (Practice's IT Provider), confirmation statement:
2026 DSPT Version 8 – GP Category 4 Statement: ITS Digital currently hold CE+ certification (certificate number 5d9380af-d3e6-499b-a8b3-1da03d2c80af) and Data Security and Protection Toolkit (Version 7 - standards exceeded).
Click the link below to download our Cyber Essentials Certificate