Data Security and Protection Toolkit: GDPR information
Why and how we process your data in the Data Security and Protection Toolkit (DSPT) and your rights.
|How we use the information (processing activities)||The DSPT requires account details that contain an individual’s name, email address and telephone number for administration purposes. This includes providing audit data for all DSPT transactions and supporting NHS Digital services having a dependency on the DSPT.|
|Does this contain sensitive (special category) data such as health information?||No|
|Who are recipients of this data?||
|Is data transferred outside the UK?||Within Europe|
|How long the data is kept||3 years minimum from no longer required|
|Our lawful basis for holding this data||Legal obligation|
|How can you withdraw your consent?||
Consent not the basis for processing
|Is the data subject to decisions made solely by computers? (automated decision making)||No|
|Where does this data come from?||Data subject|
|The legal basis for collecting this data||
Legal obligation (Direction)
Where NHS Digital uses this data
The Data Security and Protection Toolkit is an online self-assessment tool that all organisations must use if they have access to NHS patient data and systems.