DSPT Supplier Assurance: Data Processing Agreements and Standard 10
Standard 10 of the DSPT — Accountable Suppliers — requires you to demonstrate that you've identified all third parties who process personal data on your behalf and that you have documented assurance about how they handle it. For most small Category 3 providers, this means building and maintaining a supplier register, having a data processing agreement (DPA) with each supplier on it, and collecting security assurance.
This standard is often where providers make their first contact with concepts from UK GDPR — controller vs processor, lawful basis, and the Article 28 requirements for written processing contracts. The DSPT doesn't require you to have a legal background, but it does require you to have the documentation.
Data controllers and data processors
Before looking at what evidence you need, it helps to understand the UK GDPR roles:
You are a data controller. You decide what patient or client data you collect, why you collect it, and how long you keep it. You're responsible for that data's security.
Your suppliers are (mostly) data processors. When a supplier — your practice management software vendor, your IT provider, your cloud storage service — processes patient data in order to provide their service to you, they are processing it on your behalf. Under UK GDPR, that relationship must be governed by a written contract.
This written contract is the data processing agreement. It must include specific clauses per Article 28 UK GDPR: the processor must only process data on the controller's instructions, must implement appropriate security measures, must assist the controller with data subject rights requests, and must delete or return data when the contract ends.
Most established NHS software providers have standard DPA terms available. If your supplier's DPA terms are embedded in their standard service agreement, that counts.
Building your supplier register
Start with a list of all third parties who handle patient, client, or staff personal data. For a typical small Category 3 provider:
Near-certain processors:
- Practice management or care management software (Dentally, EMIS, TPP, Nourish, Birdie, etc.)
- Managed IT provider (if you use one)
- Email service (NHSmail, Microsoft 365, Google Workspace)
- Cloud backup or storage service (OneDrive, Google Drive, Dropbox, etc.)
- Payroll service (if they handle staff personal data on your behalf)
Possibly processors (depending on how you use them):
- Telephone answering or call management services (if call recordings include patient-identifiable data)
- Online appointment booking platforms
- Patient communication services (SMS appointment reminders, etc.)
- Referral management platforms
For each supplier, record:
- Supplier name
- What personal data they process
- Data processing agreement in place (yes/no; date; where stored)
- Security assurance type (DSPT / ISO 27001 / SOC 2 / supplier questionnaire / other)
- Date assurance last confirmed
- Named account manager or compliance contact
Getting DPAs in place
For major NHS-integrated software, DPA terms are usually part of the standard service agreement or available on request. If you don't have a DPA with a key supplier:
- Check your original contract for data processing or GDPR-related clauses.
- Contact the supplier and ask for their standard DPA or data processing addendum. Most will have a pre-prepared document.
- If the supplier is unwilling to provide DPA terms, that's a significant concern — it may indicate they aren't compliant with UK GDPR obligations. Escalate to the supplier's compliance team.
For large cloud platforms:
- Microsoft 365 / OneDrive: Microsoft's Data Processing Agreement is part of the Microsoft Products and Services DPA, available via the Microsoft Licensing and Supplemental Terms portal.
- Google Workspace: Google's Data Processing Amendment is available via the Google Admin console under Account > Legal.
- NHSmail: Managed by NHS England under the NHS Digital Terms and Conditions — effectively, the assurance comes from NHS England's own DSPT status and governance.
Collecting security assurance
Beyond the DPA, Standard 10 requires evidence that your suppliers handle data securely. The accepted forms of assurance:
DSPT submission. NHS-specific suppliers often have their own DSPT submissions. You can check a supplier's DSPT status at dsptoolkit.nhs.uk/OrganisationSearch. Note the supplier name, their DSPT status, and the assessment year.
ISO 27001 certification. A current ISO 27001 certificate demonstrates that the supplier has independently audited their information security management system. Valid if the certificate is in date — ISO 27001 certificates are valid for three years with annual surveillance audits. Request a copy or check the certification body's public directory.
SOC 2 report. Common for US-headquartered cloud services. A SOC 2 Type II report covers a 6-12 month period and is a robust form of assurance. Available from the supplier's compliance documentation page or on request.
Supplier-issued assurance letter. For smaller suppliers without ISO/SOC certifications, a written statement from their technical or compliance lead confirming their security controls is acceptable. It should be dated and signed, and cover the relevant controls: encryption, access management, incident response, and data retention.
Your supplier register should record the form of assurance you hold for each supplier and when it was last confirmed.
Annual review
Standard 10 evidence needs to be current. Before each DSPT cycle:
- Check that DPAs are still in place — not expired or superseded by a new service agreement that doesn't include processing terms.
- Request renewed assurance letters from suppliers that don't have ISO/SOC certifications.
- Verify that ISO/SOC certifications are still in date (check the certificate expiry or the certification body's registry).
- Check for new suppliers added since your last review.
- Check for suppliers you no longer use — confirm data has been deleted or returned per the DPA terms.
A dated review note in your supplier register, even just "Reviewed [date], all DPAs current, assurance confirmed for [supplier list]", provides clear evidence that you actively manage this standard rather than treating it as a one-time setup task.
Common evidence gaps
No DPA with a major software supplier. This is the most common Standard 10 failure. Check your contracts and request DPA terms from any supplier not covered.
No DPA with your IT provider. If your IT provider has access to systems holding personal data — even just for maintenance and support — they are a data processor. You need a DPA with them.
Assurance that's more than 12 months old. Annual DPA confirmations and renewed assurance letters are expected.
Large cloud platforms assumed to be fine. Microsoft, Google, and Amazon are secure, but the DSPT requires documented assurance. Reference their published DPA terms and compliance certifications explicitly in your supplier register — don't rely on the assumption that everyone knows they're secure.
For a full checklist of Standard 10 evidence items alongside the other 9 standards, use the DSPT evidence checklist generator.
This guide is based on DSPT v8 (2025/26) requirements and UK GDPR as applicable in England and Wales. This is not legal advice. For questions about your UK GDPR obligations, consult a qualified data protection practitioner.