DSPT Procrastination Is Putting Patient Data at Risk

As a Data Protection Officer, I see a recurring pattern every year: healthcare organisations rushing to complete the Data Security and Protection Toolkit (DSPT) at the last minute. Let’s face it—data protection is far too important to be treated this way.

The DSPT is not just an administrative task – it’s designed to ensure compliance with data protection laws like the UK GDPR and protect sensitive patient information. Yet many approach it as a box-ticking exercise, risking consequences to security and reputation. We need to prioritise proactive compliance and embed data protection in everyday operations.

The Problem: Last-minute DSPT completion

Many organisations fall into the same traps every year. The following practices may hinder compliance and expose organisations to data breaches and regulatory scrutiny.

Last-Minute Panic

Leaving the DSPT until the submission deadline creates an environment of rushed decisions and missed details. Completing it in a hurry means critical areas are either overlooked or inadequately addressed.

When data protection is handled this way, the toolkit fails to achieve its purpose—improving your organisation’s data security framework. Instead of reflecting meaningful security practices, the submission becomes a patchwork of hastily gathered evidence.

Failing to Involve the Right People

All too often, a single person is tasked with the DSPT. Data protection is a complex issue that spans multiple areas of an organisation. It requires input from several departments to ensure comprehensive coverage.

When only one person is responsible, key aspects of data security—like staff training or patient consent—may be neglected. This leaves an organisation vulnerable to gaps in compliance and risks further problems if that person leaves or lacks expertise in certain areas.

Sharing Credentials

In some cases, organisations allow multiple people to share DSPT login credentials, often as a time-saving measure. This is a serious cybersecurity risk. Shared accounts eliminate accountability and make it difficult to track changes or investigate issues.

Why This Matters

These poor practices don’t just jeopardise DSPT compliance. They have far-reaching consequences for patient care, organisational reputation, and operational security.

  1. Increased Cyber Risk
    Rushed or incomplete DSPT submissions often reflect weak data security practices. Organisations that fail to address vulnerabilities are at higher risk of data breaches, ransomware attacks, and unauthorised access. The financial and reputational damage from such incidents can be devastating.
  2. Regulatory Consequences
    Failure to meet DSPT requirements can trigger audits and enforcement actions from the NHS or Information Commissioner’s Office (ICO). Organisations risk fines, increased scrutiny, or even losing access to NHS systems. Losing that access can significantly disrupt operations.
  3. Loss of Patient Trust
    Patients trust healthcare providers to protect their sensitive information. A single breach can erode that trust, damaging relationships and reputations. Rebuilding that trust can take years and is never guaranteed.
A Better Approach to DSPT Compliance

Improving DSPT compliance isn’t about working harder; it’s about working smarter.

Start Early:

Treat the DSPT as a year-round process rather than a last-minute deadline. Break it into manageable sections and create internal timelines for completion. Starting early allows for a thoughtful review of your organisation’s data protection measures.

Form a Multidisciplinary Team

Data security involves more than just IT. Create a team that includes representatives from various departments with a clear role in contributing to the DSPT. This approach ensures that all aspects of data protection are addressed thoroughly.

Implement Strong Access Controls

Ensure that each person contributing to the DSPT has their own account with appropriate permissions. Avoid sharing passwords. This not only strengthens security but also provides a clear audit trail, ensuring accountability across the organisation.

Provide Continuous Training

Regular security awareness training helps staff understand their role in protecting data. Topics should include identifying phishing attacks, maintaining password hygiene, and reporting security incidents. Data protection should be a shared responsibility embedded in everyday practice.

Leadership’s Role

Senior leadership must prioritise data protection to drive real change. When leaders take ownership of DSPT compliance and allocate adequate resources, they set the tone for the entire organisation. Staff are more likely to take security seriously when leadership models that commitment.

A Call to Action

The DSPT is not just about compliance—it’s a tool to protect patient data and strengthen trust.  Data protection is a core responsibility for healthcare providers. It’s time to move beyond last-minute panic and shortcuts. Let’s take a proactive approach to the DSPT and treat it with the seriousness it deserves.

Sharon Forrester-Wild
Data Protection Officer, Howbeck Healthcare
dpo.healthcare@nhs.net