DSPT Staff Training Records: Meeting Standard 3 in the New TNA Era
Standard 3 of the DSPT — Staff Training — has changed significantly since 2022/23. The old requirement was a simple metric: 95% of staff complete the national Data Security Awareness Level 1 e-learning module. The new requirement is more flexible — and more work to evidence correctly.
Understanding what's changed, and what your training records now need to demonstrate, is essential for satisfying Standard 3 in v8.
What changed in 2023/24 — the training source, not the threshold
⚠️ Correction (2026-09-02). This guide previously said the 95% requirement had been replaced by a Training Needs Analysis. That is true for Category one organisations only. NHS England's v8 (2025-26) evidence-item workbook marks item 3.2.1 — the 95% completion question — “Required to meet standard (mandatory)” for Category 3 and Category 4. The TNA (3.1.1) and the 95% figure (3.2.1) are both mandatory for those categories; the TNA did not replace the threshold.
Until the 2022/23 cycle, Standard 3 evidence was relatively straightforward: run a completion report from the NHS e-Learning for Healthcare (e-LfH) platform, show that 95% or more of staff had completed Data Security Awareness Level 1, and you were done.
The DSPT training guidance page describes the change:
"Until July 2023, the DSPT required that you train at least 95% of your staff using the national Data Security Awareness Level 1 e-learning or a local equivalent. This has changed for 2023/24."
The new requirement: "Staff have appropriate understanding of information governance and cyber security, with an effective range of approaches taken to training and awareness."
This breaks into three components:
- A Training Needs Analysis (TNA) — endorsed by senior leadership — identifying what training is needed for each staff group
- Delivery of training activities against the TNA
- Evaluation — evidence that training was effective
The e-learning module from NHS e-LfH is still valid, still free, and still widely used. But it's no longer the only acceptable route, and the 95% threshold has been replaced with a more holistic assessment of whether your training approach is appropriate for your organisation.
The Training Needs Analysis
A TNA for data security doesn't need to be elaborate. For a small provider, a one-page document grouping your staff into 2-4 roles, describing the data security training appropriate for each, is sufficient.
Example structure for a 20-person care home:
| Role group | Examples | Data access | Training required |
|---|---|---|---|
| Care workers | Senior carers, carers | Care planning software, resident records | Data Security Awareness Level 1 (annual), plus mobile device policy briefing |
| Administrative staff | Office manager, receptionist | Care planning software, NHSmail, financial records | Data Security Awareness Level 1 (annual), plus information sharing protocol |
| Managers | Registered manager, deputy manager | Full system access, admin rights | Data Security Awareness Level 1 (annual), plus incident reporting procedure, plus DPA overview |
| Agency and bank workers | Temporary carers | Care planning software (limited access) | Data Security Awareness Level 1 (annual) before first shift with patient access |
The TNA should be signed by the registered manager or equivalent ("endorsed by senior leadership"), and dated. It forms the documented basis for your training programme.
Delivery: what counts and what records you need
NHS e-Learning for Healthcare (e-LfH) module. Still the most common approach. The Data Security Awareness Level 1 module at portal.e-lfh.org.uk is free, takes approximately 60 minutes, and covers the core IG and cyber security topics. To use this as evidence, you need a completion report from the e-LfH platform showing names, dates, and pass/fail status. Individual completion certificates printed per-person also work.
Commercial e-learning platforms. Platforms like iHASCO, Skills for Care, or Birdie (for care providers) offer data security awareness modules. If you use one of these, your completion report serves as evidence. The module should cover information governance, data security, cyber security basics, and incident reporting.
In-house training. A face-to-face or online training session delivered internally counts — but the records need to show content, attendance, and evaluation. "We covered data security in our staff meeting" without a note of what was covered, who attended, and whether understanding was assessed is weak evidence.
Blended approach. Many providers use the e-LfH module for the core content and supplement with team briefings, induction sessions, or incident-specific awareness updates. This is valid — record each element separately.
Evaluation: the component most providers miss
The new three-component requirement includes evaluation — evidence that training was effective, not just delivered. For small providers, this doesn't mean formal assessments. It means:
- A brief survey or verbal check. Did staff understand the key messages? Were there any questions that suggested misunderstanding?
- Pass rates from e-learning. The e-LfH module includes a quiz. A completion report with pass rates is evaluation evidence.
- An attendance check. If you run a training session, confirming all required staff attended and asking a few checking questions at the end counts.
- Incident log correlation. If staff are reporting data security incidents (Standard 6), that's evidence that training on incident recognition and reporting is working.
Your evaluation doesn't need to be formal. A dated note recording "Training delivered to all 18 staff, all passed the e-LfH module, no questions raised about the policy acknowledgement section" is sufficient.
Annual completion tracking
The DSPT requires training records that demonstrate all current staff have completed training within the last 12 months. Common tracking approaches:
- Spreadsheet. Name, role, training date, module/session name, pass/fail (if applicable). Update when new staff join and when annual refreshers are due.
- e-LfH admin dashboard. If your whole team uses the e-LfH portal, your organisation admin can run completion reports directly from the platform.
- Commercial platform dashboard. Most commercial e-learning providers offer admin dashboards with completion tracking.
The key is that you can produce a report showing every current staff member's training status. Leavers don't need to appear; joiners who haven't yet completed training should be flagged.
Common gaps before submission
TNA not documented. The new requirement explicitly needs a TNA. If you've been running training against the 95% model without a TNA, write one now — even retrospectively confirming your current training approach meets role-based needs.
Completion report from more than 12 months ago. Training records need to show completion within the current 12-month assessment period. If some staff completed training in November 2024, those records were valid for v7 but aren't for v8 (2025/26 deadline June 2026). Chase renewals.
Agency and bank staff not tracked. Workers who cover infrequently are the most common gap. Establish a check at onboarding: training must be complete before first access to patient systems.
Records show training was assigned but not completed. A training platform record showing a module was assigned and opened but not completed isn't a completion record. Chase outstanding completions.
No evaluation evidence. Review your records for any indication that training effectiveness was assessed. Even a brief note showing you checked understanding satisfies this component.
Use the DSPT evidence checklist generator to track Standard 3 items alongside your full submission. For the complete list of evidence requirements across all 10 standards, see our DSPT evidence requirements guide.
This guide is based on DSPT v8 (2025/26) requirements and the training change guidance published by NHS England. Always verify current requirements on the official DSPT portal. This is not legal or compliance advice.