Data Security and Protection Toolkit
Data Security and Protection Toolkit
Providers of NHS services within England, including community pharmacy contractors, are required to give information governance assurances to the NHS each year via an online self-assessment – the Data Security and Protection Toolkit (previously called the ‘IG toolkit’).
Click on a heading below for more information
2021/22 Toolkit and guidance
PSNC and NHS Digital are currently updating the Data Security and Protection Toolkit (DSPTK) and related tips. Additional user testing is also planned. If you would like to get involved with this user testing, please contact firstname.lastname@example.org.
NHS Digital may update contractors about the availability of the initial Toolkit version. However, contractors may benefit from holding off accessing the Toolkit until the planned improvements have been finalised and PSNC has released its updated guidance. Contractors will then still have adequate time to complete the Toolkit before the submission deadline on 30th June 2022.
Guidance for past years
2020/21 Toolkit and guidance (last year’s)
PSNC has published a suite of 2020/21 guidance to assist community pharmacy contractors with completing the Data Security and Protection Toolkit for 2020/21. The Toolkit had to be completed by 30th June 2021.
The deadline for the 2020/21 Toolkit submission had been extended from the usual 31st March cut-off as part of measures designed to address contractor workload pressures during the COVID-19 pandemic.
Detailed guidance is available:
|Toolkit guidance (2020/21)||Description (2020/21)|
|Toolkit completion: Five steps to complete the Toolkit (overview) 2020/21||This gives a step-by-step guide to completing the Toolkit and references other materials.|
|Toolkit completion: Question-by-question guidance (mandatory questions) (PDF ver) 2020/21||This can be used to work your way down the Toolkit completing the mandatory questions.|
|Toolkit completion: Question-by-question guidance (all questions) (spreadsheet ver) 2020/21||This can be used to view or filter all the questions.|
|Toolkit completion: FAQs factsheet 2020/21||This provides FAQs.|
|Toolkit completion: Using the Data Security and Protection Toolkit’s HQ batch submission feature – step-by-step guide 2020/21 and associated Checking pharmacies linked to HQ code using ODS portal factsheet 2020/21.||These explain how to request the feature is set-up for you. Contractors with three or more pharmacies may benefit from using the feature. See also the ‘Batch guidance’ section of this webpage.|
|Data security templates||Templates and policies including new ones which enable completion of the newest version of the Toolkit. All the templates have been refreshed to align with the latest toolkit and with the ongoing COVID-19 pandemic.|
|Data security training||Training resources. Including the updated Pharmacy data security and IG training (for induction or refreshment).|
|PSNC’s Data security hub||This hub includes new resources such as: Antivirus, Backups, Data handling and Roles.|
See also briefings updated in for 2020/21 completions:
- The national data opt-out system for patients and how to complete the DSPTK opt-out question
- Preparing for Windows 10 end-of-life cycles
- Ten steps to help improve data and cyber security
The final deadline for completing the mandatory questions was re-scheduled from March 31st 2020 to September 30th 2020.
April 2021 update: Related guidance has been superceded and the older version of the Toolkit can no longer be published
COVID-19 update: It has been agreed that no action will be taken against contractors who have not completed the Data Security and Protection toolkit for 2019/20, provided they are working to complete the toolkit for 2020/21.
2019/20 Toolkit webinar
In 2020, PSNC and NHS Digital presented a webinar to support Toolkit completion. An on-demand version of the webinar is available via the link above.
Answering technical questions and the Toolkit PMR feature
The Toolkit includes some technical questions which you may need the assistance of your PMR supplier to answer. Some PMR suppliers will provide information to support your completion of the technical questions via a guidance document or via their helpdesk.
Alternatively, some PMR suppliers have chosen to utilise the Toolkit PMR feature. This feature involves your PMR supplier setting up an email address (e.g. email@example.com) that they share with customers and this is then entered by the contractor within the ‘Admin’>’User List’ section of the Toolkit (the email address can be added as a ‘Member’). This then allows information supplied by your PMR supplier to be bulk-inserted for the mandatory technical questions within the Toolkit.
The bulk upload of information is likely to be at a pre-set time which your PMR supplier will advise you of. Once the information has been uploaded, you will be able to add or amend the answers entered by your PMR supplier if necessary. Your supplier, as a ‘Member’ within the Toolkit, will technically be able to see your answers to all the questions.
The Toolkit contains functionality to allow pharmacy contractors with three or more pharmacies to complete a bulk submission of assessments on behalf of its branches. If this functionality is of interest to a contractor, they should first read:
These documents explain how to request the feature is set-up for you.
When you log in to the Toolkit as an HQ organisation (with HQ ODS code), you will be able to complete your assessment, review your list of branches and publish your Toolkit assessment for your branches. Your HQ’s branch list has been populated from data held by the ODS team. If your list is not accurate, please raise a support call with the Exeter Helpdesk.
Related topics from within PSNC’s Data Security and IG hub are:
- Access control methods (e.g. passwords)
- Cyber and technical security advice about how to prevent and deal with data and cyber issues
- Data handling, record keeping and disposal
- Data quality
- DSPTK FAQS factsheet (or webpage)
- DSPTK HQ batch submission feature (step-by-step guide)
- DSPTK HQ batch submission feature (factsheet)
- GDPR and workbook
- Fax usage
- Mobile messaging
- Mobile device usage and ‘bring your own device’ policy
- National data opt-out system for patients (for data processing for planning/research)
- NHS login – an authentication system for patients (used by NHS App and other apps) to reduce the number of logins/accounts needed by patients
- NHS Identity (authentication for health and care professionals)
- Roles (e.g. IG lead)
- System settings and IT updates
- Ten steps to help improve data and cyber security within your pharmacy (factsheet)
- Top tips and case studies
- Video conferencing and video consultations
- Windows 10 versions end-of-support transition guidance
If you have queries about this webpage, please contact firstname.lastname@example.org.