This support programme is part of the Better Security, Better Care programme, funded by NHSX to support data and cyber security across the adult social care provider sector. This support is aligned to Digital Social Care.
Digital Social Care has produced a really useful reference guide to help small and medium sized Care Providers to understand, register and publish the Data Security and Protection Toolkit (DSPT) – Click here
Registering your DSPT
- Find your NHS ODS Code: https://odsportal.digital.nhs.uk/Organisation/Search
- Check to see if your organisation has already published DSPT: https://www.dsptoolkit.nhs.uk/OrganisationSearch
- Registering your DSPT: https://www.hcpa.info/wp-content/uploads/DSPT-getting-started-guide.pdf
- Registration with ICO: https://ico.org.uk/for-organisations/data-protection-fee/
- Search ICO to check if you are already registered: https://ico.org.uk/esdwebpages/search
Setting up your organisation profile on DSPT
- Guidance on the right people to add to your profile: https://www.hcpa.info/wp-content/uploads/Organisation-profile-questions-guidance-for-social-care.pdf
Ensuring you can complete your DSPT
- REALLY USEFUL – How it all works: https://www.hcpa.info/wp-content/uploads/Toolkit-journey-diagram.pdf
- REALLY USEFUL – Workbook to help small and medium sized Care Providers publish the DSPT to Standards Met: Click here
- Policy templates: https://www.digitalsocialcare.co.uk/latest-guidance/template-policies/
- Other templates (Information Asset Register, Record of Data Processing Activities, Privacy notice, etc): https://www.digitalsocialcare.co.uk/latest-guidance/how-to-document-your-data-processing/
- Information Commissioners Office (ICO) guidance on individual’s rights and template for Privacy Notice: Click here
- Document Retention guidance: Click here
- Lots of other useful resources: https://www.digitalsocialcare.co.uk/
Templates:
- Template Information Asset Register (IAR): Click here
- Template Record of Processing Activities (RoPA): Click here
- Guidance on documenting data in Information Asset Register and Record of Processing Activities: Click here
- Template Privacy Notice: Click here
- Template Data Protection Policy: Click here
- Template Data Privacy Policy: Click here
- Template Data Protection Impact Assessment (DPIA): Click here
- Template Spot-checks audit checklist: Click here
- Template Unsupported Software register: Click here
Videos:
- Once you have registered for a DSPT account, this short video will tell you what you need to set up your organisational profile: Click here (Thanks to WMCA for the use of their video)
- More videos supporting DSPT: CLICK HERE
Events:
- Digital Social Care offer free online events focussing on the data protection lead role in social care, adopting digital scoial care records, using iPads in social care organisations, and many more subjects: click here to see DSC’s latest events
Important – Protecting against scam / phishing emails:
Worried about scam emails? Know how to spot a scam email? Know what to do if a staff member has already clicked on a scam email?
- Her Majesty’s National Cyber Security Centre has produced this helpful poster, which you may want to show your staff, or put on your office wall: Click here