How to Write a DSPT Data Security Policy: What NHS England Expects
Standard 2 of the DSPT — Staff Responsibilities — requires you to demonstrate that all staff understand their data security duties. The primary evidence for this standard is your data security policy and proof that staff have read it.
Getting this right isn't about writing a lengthy document. It's about having a policy that's specific to your organisation, reviewed within the last 12 months, and acknowledged by staff. Most providers fail Standard 2 not because their policy is badly written, but because it hasn't been reviewed recently or because no one collected the acknowledgements.
What the policy needs to cover
A DSPT-compliant data security policy needs to address these areas to satisfy Standard 2 evidence requirements. You don't need separate headings for each — they can overlap and combine — but the content needs to be there.
Data handling expectations. How staff should handle patient or client data: on which systems, on which devices, what to do if they need to share data with a third party. The key principle is that personal data is used only for the purpose it was collected, shared only with authorised recipients, and kept no longer than needed.
Access management. Who has access to which systems, how new access is authorised, and what happens when someone leaves. Your policy should state that access is role-appropriate, that leavers have access removed promptly, and that admin accounts are minimised and documented.
Device use. Whether staff can use personal devices for work purposes and, if so, under what conditions. If you allow BYOD, the policy needs to address encryption requirements and what happens if a personal device is lost or stolen. If you don't allow BYOD, the policy should state that clearly.
Incident reporting. How staff identify a data security incident (from a lost USB drive to an email sent to the wrong person) and who they report it to. The policy should name the reporting contact and include a brief description of what counts as a reportable incident.
Named data protection lead. The name or role of the person responsible for data security in your organisation. This can be the registered manager, practice manager, or a named lead — but it needs to be in the document.
Training expectations. A statement that staff are expected to complete annual data security awareness training as a condition of their role.
What makes evidence strong vs weak
The DSPT doesn't require a perfect policy. It requires a policy that demonstrates your organisation is actively managing data security rather than ignoring it.
Strong evidence:
- Current review date (within the last 12 months) in the document header
- Staff acknowledgement records — signature sheets, email confirmations, or a training completion record that includes the policy acknowledgement
- Organisation-specific content — your actual systems, your named lead, your processes
- Consistent with other evidence items (your access register should reflect what the policy says about access management)
Weak evidence:
- A policy from three years ago with no review date
- A downloaded template with the placeholder organisation name still in it
- A policy that references systems or roles your organisation doesn't have
- No record that staff have read it
The assessor isn't reading for legal precision. They're checking whether you've genuinely engaged with the requirement or just ticked a box.
Reviewing and updating an existing policy
If your policy is more than 12 months old, it needs a review before your next submission. Reviewing doesn't mean rewriting from scratch — it means:
- Read it and check it's still accurate. Have your systems changed? Has your staffing structure changed? Is the named data lead still in that role? Update what's out of date.
- Check it covers Standard 3's training requirement. The v8 DSPT requires a Training Needs Analysis approach (see the DSPT training change guidance) — your policy should reflect that staff training is TNA-driven and role-appropriate, not just "complete the e-learning module".
- Update the review date. Change the date in the document header to today's date and record the review in your review schedule.
- Re-circulate for acknowledgements. Even if the content barely changed, the annual review is a good opportunity to confirm that all current staff have seen the current version.
Collecting staff acknowledgements
This is where most organisations fall short. Writing a good policy is half the work; proving staff have read it is the other half.
Options that work as DSPT evidence:
- Physical signature sheet — staff name, signature, date, policy version. Keep a copy in your HR file or data security folder.
- Email confirmation — ask staff to reply confirming they've read and understood the current policy. Keep the email chain.
- Training platform record — if you use an LMS or e-learning platform for data security training, include the policy acknowledgement as a step in the training module.
- A tick in your staff records spreadsheet — if you track training and acknowledgements in a spreadsheet, a column for "Policy acknowledged (date)" works, as long as you can show when it was completed.
What doesn't work: telling the assessor that "staff are all aware of the policy" without any documentary evidence. Awareness without a record isn't evidence.
Keeping the policy current year to year
A data security policy only needs significant rewriting when your systems or processes change materially. For most small providers, the annual review involves:
- Updating the review date
- Checking named contacts are still current
- Checking any referenced system names are still accurate
- Adding a brief note if anything significant changed (new cloud storage platform, change in staff mix, new device policy)
Use the DSPT evidence checklist generator to see how your policy fits into the full picture of Standard 2 and Standard 3 evidence requirements. For a full breakdown of what the DSPT requires across all 10 standards, see our evidence requirements guide.
This guide is based on DSPT v8 (2025/26) requirements as published by NHS England. Always verify current requirements on the official DSPT portal. This is not legal or compliance advice.