Compliance · Data protection

Completing the Data Security and Protection Toolkit as a small pharmacy

The Data Security and Protection Toolkit is the annual declaration, mandatory under the NHS Terms of Service and due by 30 June each year, that your pharmacy meets the national data security standards. Done in May with the right sequence it takes about two hours; done on 29 June from a standing start it consumes a week. This guide gives the method, the three shortcuts that make it fast, the 2026-cycle changes including the new multi-factor authentication question, the batch route for multi-pharmacy owners, and what to do if the deadline has already gone past.

Last reviewed 14 July 2026 by Arham Jamaal, Superintendent Pharmacist. Referenced against the sources cited in this article.

What is the DSPT and why must pharmacies complete it?

The Data Security and Protection Toolkit (DSPT) is how a pharmacy makes its annual information governance declaration: an online self-assessment completed at the official portal, https://www.dsptoolkit.nhs.uk, against your pharmacy's ODS code, confirming that the pharmacy meets the ten National Data Guardian data security standards. Completion is mandatory under the NHS Terms of Service, the deadline is 30 June each year, and the declaration covers the whole of your data handling, paper prescriptions and hard-copy records as much as the PMR, because the duty to protect patient information applies equally to both.

Two structural facts frame everything else. First, every pharmacy submits against its own ODS code, and every owner also holds an NHS Parent Organisation Code (POC), even owners of a single pharmacy, which matters for the batch route later. Second, the DSPT is not paperwork floating free of consequences: it is part of the trust infrastructure that stands behind your access to NHS systems and data flows, it is the declaration a Community Pharmacy Assurance Framework visit can test against reality, and its themes overlap heavily with what a GPhC inspector samples.

"A Toolkit answered honestly from real systems is twenty minutes of confirmation; one answered aspirationally is a standing misstatement renewed annually."

Alongside the Toolkit sits one adjacent legal duty worth stating bluntly because it still catches people: every pharmacy processes personal data and must be registered with the Information Commissioner's Office and pay the annual data protection fee, which you can check and do at https://ico.org.uk/for-organisations/data-protection-fee/, and failure to register is not an administrative lapse but a breach of data protection law and a criminal offence.

If you missed the 30 June deadline

Submit now, because the portal does not slam shut at midnight. Community Pharmacy England's own FAQs confirm the Toolkit is not locked on the deadline date and it may still be technically possible to publish shortly afterwards, so the correct response to a missed deadline is immediate completion, not paralysis. The obligation is a Terms of Service requirement, which means an unsubmitted declaration is a live compliance gap that compounds the longer it stands, and where genuinely exceptional circumstances caused the delay, contact the DSPTK query point and say so.

Then fix the cause, which is almost always the same one: the Toolkit was treated as a June event rather than a scheduled working session earlier in the year. Our compliance calendar puts it where it belongs, as a diarised two-hour block in May with a named owner, and the method below is what fills that block.

The two-hour method: five steps in the right order

The Toolkit is fast when the sequence is right, because the first two steps unlock most of the answers before you touch the harder questions.

StepWhat you doWhat you need openTime
1. Refresh the GDPR WorkbookUpdate Community Pharmacy England's GDPR Workbook templates to reflect your current pharmacyThe workbook and ten minutes of honesty about what changed this year30 to 45 minutes
2. Confirm pre-populated answersLog in at https://www.dsptoolkit.nhs.uk; the Toolkit displays last year's answers for many questions, so confirm what still holds and amend what does notLast year's submission, effectively shown to you15 minutes
3. Route the technical questions to your PMR supplierUse your supplier's guidance document or the Toolkit's supplier feature for the technical sectionYour PMR supplier's IG support details10 minutes plus supplier turnaround
4. Complete the remaining mandatory questionsWork down the mandatory list with CPE's question-by-question guidance beside you, entering "see GDPR WB" where the refreshed workbook covers itCPE question-by-question guidance from the CPE data security hub30 to 45 minutes
5. Publish and filePublish the assessment, save the confirmation, diarise next year's sessionYour compliance calendar10 minutes

Steps one and two are the whole trick. Pharmacy teams that have refreshed and updated the GDPR Workbook meet the criteria for around half of the Toolkit questions and can simply enter "see GDPR WB" against them, and since the 2026 cycle the Toolkit also shows previous answers for confirmation rather than demanding re-entry, so a pharmacy in its second year of doing this properly is mostly confirming rather than composing.

The GDPR Workbook shortcut, properly explained

The GDPR Workbook is Community Pharmacy England's template pack covering the data protection documentation a pharmacy needs, records of processing, privacy information, security arrangements and the rest, and the DSPT is designed around it: a current, completed workbook is accepted as the evidence behind roughly half of the Toolkit's questions. The shortcut is the cross-reference, "see GDPR WB", typed into those questions instead of restating the content.

The catch is the word current. The shortcut is a pointer to evidence, not an exemption from having it, so a workbook last touched three years ago converts your Toolkit from a declaration into a fiction. The honest refresh takes under an hour: walk the workbook's sections against what actually changed this year, new services, new staff roles, new suppliers, the website, and update the templates accordingly. This is also where the workbook earns its keep beyond June, because the same documents answer the data protection questions a patient, an ICO enquiry or an inspector might ask, and 2026's cycle added a new CPE template for handling data protection complaints, which belongs in the same folder.

The technical questions and your PMR supplier

The Toolkit includes technical questions about your clinical IT that most owners cannot answer from their own knowledge, and the system is designed to let your supplier answer them. Some PMR suppliers publish a guidance document or answer through their helpdesk; others use the Toolkit's supplier feature, where the supplier's IG support email address is added as a Member under the Admin and User List section, allowing the supplier's information to be bulk-inserted into the mandatory technical questions at a pre-set time the supplier advises. Either route is fine. A supplier offering neither is telling you something, and the questions from our DCB0129 buyers' guide belong in that conversation.

The 2026 cycle added the question that generated the most discussion: multi-factor authentication (MFA) on clinical IT systems. The shape of a good answer is factual and specific, what authentication your clinical systems support and enforce, rather than aspirational, and if the honest answer exposes a gap, the gap is the finding to fix, not the question to fudge. Ask your supplier for its MFA position in writing; it is a thirty-second email and the answer serves both the Toolkit and your own security posture.

Owners of three or more pharmacies: the POC batch route

Owners of three or more pharmacies can complete a single submission covering every branch through the HQ batch submission feature, logging in against the Parent Organisation Code rather than branch by branch. The mechanics are straightforward: the HQ account completes one assessment, reviews the branch list and publishes for all of them, with head-office staff also able to view individual submissions centrally through an HQ login arranged with the DSPTK query point.

The one preparation task that prevents last-minute misery is checking the branch list early. The HQ list is populated from ODS data, and where it is wrong, a sold branch still showing, a new acquisition missing, the fix runs through a support call to the DSPTK query point, which takes days you do not have in the final week. Community Pharmacy England explicitly advises multi-pharmacy owners to verify the pharmacies linked to their POC well ahead of the deadline, and ownership changes have their own wrinkle: where a pharmacy changes hands but keeps its ODS code, the new owner contacts the query point to lock the previous owner's account and register afresh against the code.

The questions behind the questions

Every Toolkit question is a proxy for something a well-run pharmacy already has, which is why this series keeps arriving at the same infrastructure from different directions. The mapping below is the useful way to read the whole exercise.

Toolkit themeWhat it is really checkingWhere it already lives
Staff trainingEvery team member completed data security training this year, with recordsThe training file from your onboarding process, week one for every starter
Access to dataAccess limited to who needs it, accounts individual, leavers removedThe roles and permissions model, no shared logins, quarterly access review
Incidents and breachesA working process to detect, record and report, including the 72-hour ICO clock for notifiable breachesThe incident SOP required by the Responsible Pharmacist Regulations
ContinuityA plan for when systems or premises failThe business continuity arrangements your distance-services risk assessment already covers
SuppliersThird parties handling your data meet security standardsThe supplier assurance file, DCB0129 answers included
Unsupported systems and IT protectionNo end-of-life software; technical controls in placeYour PMR supplier's written answers and your own kit inventory

Read that way, the Toolkit stops being an annual imposition and becomes an annual audit of infrastructure you need anyway, and the pharmacies for whom it takes two hours are simply the ones for whom the right-hand column is true.

Scams, pitfalls and the after

SCAM WARNING

Community Pharmacy England has warned of emails circulating to pharmacies claiming the recipient is under investigation for a GDPR or data protection breach, designed to panic staff into contact or payment. The real ICO does not open investigations by threatening email, and any such message goes to your incident process, not your reply button.

Beyond the scams, two hazards deserve naming. The perennial failure modes: starting in the final week, training records that exist in memory but not on file, and ICO registrations that quietly lapsed with a changed payment card, each cheap to fix in May and expensive in June. And the after: the declaration you publish is testable, by a CPAF visit, by an inspector sampling your access controls or training records, and by reality the day an incident happens, so the standard to hold is that every answer points at something that genuinely operates.

That standard is also the exit from the annual scramble permanently. A pharmacy whose training records, access model, incident log and supplier files are maintained as living systems does not prepare for the DSPT at all; it confirms it, which is the same property this series has claimed for inspections, and it is true for the same reason.

Where to complete the Toolkit and find the official guidance

Everything you need sits in four official places, and bookmarking them once removes the annual hunt. The Toolkit itself is completed at the NHS portal, https://www.dsptoolkit.nhs.uk, where you register or log in against your pharmacy's ODS code, and where multi-pharmacy owners access the HQ batch feature against their Parent Organisation Code. Community Pharmacy England's data security hub at cpe.org.uk/digital-and-technology/data-security/data-security-and-protection-toolkit holds the pharmacy-specific guidance suite: the five-step overview, the question-by-question guidance for the mandatory questions, the GDPR Workbook, the batch submission guide and the on-demand webinar recorded with the NHS DSPTK team. CPE's data security FAQs at cpe.org.uk/digital-and-technology/data-security/data-security-faqs answer the edge cases, including late submission, ownership changes and registration queries. And ICO registration and the annual data protection fee are handled at ico.org.uk/for-organisations/data-protection-fee. Treat any DSPT or GDPR communication arriving from addresses outside nhs.uk, cpe.org.uk or ico.org.uk domains with suspicion, per the scam warning above; when in doubt, navigate to these bookmarks directly rather than clicking links in emails.

Key takeaways

  • The DSPT is the mandatory annual IG declaration under the NHS Terms of Service, due by 30 June each year against your pharmacy's ODS code, and it covers paper records as much as electronic ones.
  • If the deadline has passed, submit immediately: the portal is not locked at midnight, and an unsubmitted declaration is a live Terms of Service breach.
  • A refreshed CPE GDPR Workbook satisfies around half the questions with the "see GDPR WB" cross-reference, and since 2026 the Toolkit pre-populates last year's answers for confirmation.
  • Route the technical questions to your PMR supplier, via their guidance or the Toolkit's supplier bulk-insert feature, and get their multi-factor authentication position in writing for the new 2026 question.
  • Owners of three or more pharmacies should use the POC batch submission and verify the branch list against ODS data early, since corrections run through a support call.
  • Every pharmacy must also hold current ICO registration, arranged at ico.org.uk, and failure to register is a criminal offence, not an oversight.
  • Ignore scam emails claiming GDPR investigations, a live pattern CPE has warned about, and route them to your incident process.

FAQs

30 June each year, as part of the pharmacy's annual information governance declaration under the NHS Terms of Service. The current cycle closed on 30 June 2026, and the next runs to 30 June 2027. The portal is not locked at midnight on the deadline, so a missed submission should be completed immediately rather than abandoned, but the sensible pattern is a diarised working session in May. The Toolkit is completed at https://www.dsptoolkit.nhs.uk.
AJ
WRITTEN BY
Arham Jamaal
Superintendent Pharmacist · Published researcher, pharmacokinetics
This article is general guidance for pharmacy professionals, not legal advice. Toolkit content, deadlines and guidance change each cycle; always check the current CPE and NHS DSPTK publications before completing your declaration. Last reviewed 14 July 2026.

Confirmed, not composed.

Half the Toolkit is a records problem, and the right-hand column of this article's mapping table is what Dataforge PMR maintains by default: individual accounts with role-based access, training and competence records per team member, incident logs and a named audit trail on every action. To see your DSPT answers generated by your systems rather than written for them, book a 30-minute demo.

Book a demo

Keep reading