What is the DSPT and why must pharmacies complete it?
The Data Security and Protection Toolkit (DSPT) is how a pharmacy makes its annual information governance declaration: an online self-assessment completed at the official portal, https://www.dsptoolkit.nhs.uk, against your pharmacy's ODS code, confirming that the pharmacy meets the ten National Data Guardian data security standards. Completion is mandatory under the NHS Terms of Service, the deadline is 30 June each year, and the declaration covers the whole of your data handling, paper prescriptions and hard-copy records as much as the PMR, because the duty to protect patient information applies equally to both.
Two structural facts frame everything else. First, every pharmacy submits against its own ODS code, and every owner also holds an NHS Parent Organisation Code (POC), even owners of a single pharmacy, which matters for the batch route later. Second, the DSPT is not paperwork floating free of consequences: it is part of the trust infrastructure that stands behind your access to NHS systems and data flows, it is the declaration a Community Pharmacy Assurance Framework visit can test against reality, and its themes overlap heavily with what a GPhC inspector samples.
"A Toolkit answered honestly from real systems is twenty minutes of confirmation; one answered aspirationally is a standing misstatement renewed annually."
Alongside the Toolkit sits one adjacent legal duty worth stating bluntly because it still catches people: every pharmacy processes personal data and must be registered with the Information Commissioner's Office and pay the annual data protection fee, which you can check and do at https://ico.org.uk/for-organisations/data-protection-fee/, and failure to register is not an administrative lapse but a breach of data protection law and a criminal offence.
If you missed the 30 June deadline
Submit now, because the portal does not slam shut at midnight. Community Pharmacy England's own FAQs confirm the Toolkit is not locked on the deadline date and it may still be technically possible to publish shortly afterwards, so the correct response to a missed deadline is immediate completion, not paralysis. The obligation is a Terms of Service requirement, which means an unsubmitted declaration is a live compliance gap that compounds the longer it stands, and where genuinely exceptional circumstances caused the delay, contact the DSPTK query point and say so.
Then fix the cause, which is almost always the same one: the Toolkit was treated as a June event rather than a scheduled working session earlier in the year. Our compliance calendar puts it where it belongs, as a diarised two-hour block in May with a named owner, and the method below is what fills that block.
The two-hour method: five steps in the right order
The Toolkit is fast when the sequence is right, because the first two steps unlock most of the answers before you touch the harder questions.
| Step | What you do | What you need open | Time |
|---|---|---|---|
| 1. Refresh the GDPR Workbook | Update Community Pharmacy England's GDPR Workbook templates to reflect your current pharmacy | The workbook and ten minutes of honesty about what changed this year | 30 to 45 minutes |
| 2. Confirm pre-populated answers | Log in at https://www.dsptoolkit.nhs.uk; the Toolkit displays last year's answers for many questions, so confirm what still holds and amend what does not | Last year's submission, effectively shown to you | 15 minutes |
| 3. Route the technical questions to your PMR supplier | Use your supplier's guidance document or the Toolkit's supplier feature for the technical section | Your PMR supplier's IG support details | 10 minutes plus supplier turnaround |
| 4. Complete the remaining mandatory questions | Work down the mandatory list with CPE's question-by-question guidance beside you, entering "see GDPR WB" where the refreshed workbook covers it | CPE question-by-question guidance from the CPE data security hub | 30 to 45 minutes |
| 5. Publish and file | Publish the assessment, save the confirmation, diarise next year's session | Your compliance calendar | 10 minutes |
Steps one and two are the whole trick. Pharmacy teams that have refreshed and updated the GDPR Workbook meet the criteria for around half of the Toolkit questions and can simply enter "see GDPR WB" against them, and since the 2026 cycle the Toolkit also shows previous answers for confirmation rather than demanding re-entry, so a pharmacy in its second year of doing this properly is mostly confirming rather than composing.
The GDPR Workbook shortcut, properly explained
The GDPR Workbook is Community Pharmacy England's template pack covering the data protection documentation a pharmacy needs, records of processing, privacy information, security arrangements and the rest, and the DSPT is designed around it: a current, completed workbook is accepted as the evidence behind roughly half of the Toolkit's questions. The shortcut is the cross-reference, "see GDPR WB", typed into those questions instead of restating the content.
The catch is the word current. The shortcut is a pointer to evidence, not an exemption from having it, so a workbook last touched three years ago converts your Toolkit from a declaration into a fiction. The honest refresh takes under an hour: walk the workbook's sections against what actually changed this year, new services, new staff roles, new suppliers, the website, and update the templates accordingly. This is also where the workbook earns its keep beyond June, because the same documents answer the data protection questions a patient, an ICO enquiry or an inspector might ask, and 2026's cycle added a new CPE template for handling data protection complaints, which belongs in the same folder.
The technical questions and your PMR supplier
The Toolkit includes technical questions about your clinical IT that most owners cannot answer from their own knowledge, and the system is designed to let your supplier answer them. Some PMR suppliers publish a guidance document or answer through their helpdesk; others use the Toolkit's supplier feature, where the supplier's IG support email address is added as a Member under the Admin and User List section, allowing the supplier's information to be bulk-inserted into the mandatory technical questions at a pre-set time the supplier advises. Either route is fine. A supplier offering neither is telling you something, and the questions from our DCB0129 buyers' guide belong in that conversation.
The 2026 cycle added the question that generated the most discussion: multi-factor authentication (MFA) on clinical IT systems. The shape of a good answer is factual and specific, what authentication your clinical systems support and enforce, rather than aspirational, and if the honest answer exposes a gap, the gap is the finding to fix, not the question to fudge. Ask your supplier for its MFA position in writing; it is a thirty-second email and the answer serves both the Toolkit and your own security posture.
Owners of three or more pharmacies: the POC batch route
Owners of three or more pharmacies can complete a single submission covering every branch through the HQ batch submission feature, logging in against the Parent Organisation Code rather than branch by branch. The mechanics are straightforward: the HQ account completes one assessment, reviews the branch list and publishes for all of them, with head-office staff also able to view individual submissions centrally through an HQ login arranged with the DSPTK query point.
The one preparation task that prevents last-minute misery is checking the branch list early. The HQ list is populated from ODS data, and where it is wrong, a sold branch still showing, a new acquisition missing, the fix runs through a support call to the DSPTK query point, which takes days you do not have in the final week. Community Pharmacy England explicitly advises multi-pharmacy owners to verify the pharmacies linked to their POC well ahead of the deadline, and ownership changes have their own wrinkle: where a pharmacy changes hands but keeps its ODS code, the new owner contacts the query point to lock the previous owner's account and register afresh against the code.
The questions behind the questions
Every Toolkit question is a proxy for something a well-run pharmacy already has, which is why this series keeps arriving at the same infrastructure from different directions. The mapping below is the useful way to read the whole exercise.
| Toolkit theme | What it is really checking | Where it already lives |
|---|---|---|
| Staff training | Every team member completed data security training this year, with records | The training file from your onboarding process, week one for every starter |
| Access to data | Access limited to who needs it, accounts individual, leavers removed | The roles and permissions model, no shared logins, quarterly access review |
| Incidents and breaches | A working process to detect, record and report, including the 72-hour ICO clock for notifiable breaches | The incident SOP required by the Responsible Pharmacist Regulations |
| Continuity | A plan for when systems or premises fail | The business continuity arrangements your distance-services risk assessment already covers |
| Suppliers | Third parties handling your data meet security standards | The supplier assurance file, DCB0129 answers included |
| Unsupported systems and IT protection | No end-of-life software; technical controls in place | Your PMR supplier's written answers and your own kit inventory |
Read that way, the Toolkit stops being an annual imposition and becomes an annual audit of infrastructure you need anyway, and the pharmacies for whom it takes two hours are simply the ones for whom the right-hand column is true.
Scams, pitfalls and the after
Community Pharmacy England has warned of emails circulating to pharmacies claiming the recipient is under investigation for a GDPR or data protection breach, designed to panic staff into contact or payment. The real ICO does not open investigations by threatening email, and any such message goes to your incident process, not your reply button.
Beyond the scams, two hazards deserve naming. The perennial failure modes: starting in the final week, training records that exist in memory but not on file, and ICO registrations that quietly lapsed with a changed payment card, each cheap to fix in May and expensive in June. And the after: the declaration you publish is testable, by a CPAF visit, by an inspector sampling your access controls or training records, and by reality the day an incident happens, so the standard to hold is that every answer points at something that genuinely operates.
That standard is also the exit from the annual scramble permanently. A pharmacy whose training records, access model, incident log and supplier files are maintained as living systems does not prepare for the DSPT at all; it confirms it, which is the same property this series has claimed for inspections, and it is true for the same reason.
Where to complete the Toolkit and find the official guidance
Everything you need sits in four official places, and bookmarking them once removes the annual hunt. The Toolkit itself is completed at the NHS portal, https://www.dsptoolkit.nhs.uk, where you register or log in against your pharmacy's ODS code, and where multi-pharmacy owners access the HQ batch feature against their Parent Organisation Code. Community Pharmacy England's data security hub at cpe.org.uk/digital-and-technology/data-security/data-security-and-protection-toolkit holds the pharmacy-specific guidance suite: the five-step overview, the question-by-question guidance for the mandatory questions, the GDPR Workbook, the batch submission guide and the on-demand webinar recorded with the NHS DSPTK team. CPE's data security FAQs at cpe.org.uk/digital-and-technology/data-security/data-security-faqs answer the edge cases, including late submission, ownership changes and registration queries. And ICO registration and the annual data protection fee are handled at ico.org.uk/for-organisations/data-protection-fee. Treat any DSPT or GDPR communication arriving from addresses outside nhs.uk, cpe.org.uk or ico.org.uk domains with suspicion, per the scam warning above; when in doubt, navigate to these bookmarks directly rather than clicking links in emails.
Key takeaways
- The DSPT is the mandatory annual IG declaration under the NHS Terms of Service, due by 30 June each year against your pharmacy's ODS code, and it covers paper records as much as electronic ones.
- If the deadline has passed, submit immediately: the portal is not locked at midnight, and an unsubmitted declaration is a live Terms of Service breach.
- A refreshed CPE GDPR Workbook satisfies around half the questions with the "see GDPR WB" cross-reference, and since 2026 the Toolkit pre-populates last year's answers for confirmation.
- Route the technical questions to your PMR supplier, via their guidance or the Toolkit's supplier bulk-insert feature, and get their multi-factor authentication position in writing for the new 2026 question.
- Owners of three or more pharmacies should use the POC batch submission and verify the branch list against ODS data early, since corrections run through a support call.
- Every pharmacy must also hold current ICO registration, arranged at ico.org.uk, and failure to register is a criminal offence, not an oversight.
- Ignore scam emails claiming GDPR investigations, a live pattern CPE has warned about, and route them to your incident process.
FAQs
Confirmed, not composed.
Half the Toolkit is a records problem, and the right-hand column of this article's mapping table is what Dataforge PMR maintains by default: individual accounts with role-based access, training and competence records per team member, incident logs and a named audit trail on every action. To see your DSPT answers generated by your systems rather than written for them, book a 30-minute demo.
Book a demo