NHSmail and Data Protection Security Toolkit

DSPT a requirement for contractors using NHSmail

Laptop and business data

NHSX, NHS Digital and NHSEI have updated guidance for contractors using NHSmail. All organisations with NHSmail accounts are required to complete the Data Security & Protection Toolkit (DSPT), an online self-assessment tool, on an annual basis. Completing the DSPT is a prerequisite for signing up to an NHSmail account.

A temporary DSPT waiver was in place until 30 June 2021, but from 1 July 2021 optometry contractors applying for an NHSmail account have been required to complete the DSPT. Contractors will have 12 months in which to complete the toolkit. The 2021/22 the cycle runs from 1 July 2021 to 30 June 2022. 

NHSX, NHS Digital and NHSEI are advising existing NHSmail account holders who have not yet completed the DSPT since signing up to do so because: 

  • Completion of the DSPT demonstrates patient information is being managed safely and securely
  • It provides evidence to the Information Commissioner’s Office (ICO) that the contractor is compliant with key elements of GDPR when dealing with medical records
  • It serves to strengthen staff members’ awareness and preparedness around cybersecurity and data protection. Data breaches can have significant implications for the contractor

DSPT submissions will be monitored and non-compliance may result in suspension or deletion of the NHSmail account, including the shared mailbox and individual user accounts. 

The DSPT is also a requirement for the Electronic Eyecare Referral System (EeRS), which is being rolled out across parts of England in 2021/22. Electronic communication will become an increasingly integral part of service provision as future opportunities for remote working and implement digital solutions, which form a key part of the NHS Long Term Plan, are considered.

Webinar and further support

NHSX, NHS Digital and NHSEI are holding webinars to help contractors in the completion of the DSPT. Presented by John Hodson, Senior Information Assurance at NHS Digital, the webinars will feature a short demo, tips for how to get going and an opportunity to ask questions. The webinars will take place on:

  • Thursday 21 October, 5:30-6:15pm
  • Wednesday 3 November, 5:30-6:15pm

To register, contractors need to email [email protected] stating their name, job role, company and the webinar they would like to attend. 

Contractors can register for the DSPT through Quality in Optometry or the DSPT website

Further support is also available from the NHS Digital helpdesk: 0300 303 4034 / [email protected]


For more information, please contact Serena Box, PR and Media Manager, at the Association of Optometrists, [email protected] or telephone 020 7549 2040.

Association of Optometrists

The Association of Optometrists (AOP) is the leading representative membership organisation for optometrists in the UK. We support over 82% of practising optometrists, to fulfil their professional roles to protect the nation’s eye health. For more information, visit