Background
The Business Supplies Group is one of the UK’s leading providers of business supplies and services, working with both public and private sector organisations. Its key clients include the NHS, which the Group equips with printers and multi-functional devices (MFDs) used across healthcare settings.
They engaged The DPO Centre to support their NHS Data Security and Protection Toolkit (DSPT) submission. With a growing need to formalise and evidence their data protection practices, they sought external expertise to accelerate progress and ensure full alignment with NHS and GDPR requirements.
Key Challenges
- Completing NHS DSPT submission
- Demonstrating accountability
- Raising C-Suite awareness
Solution
The designated DPO began by conducting a gap analysis to assess the organisation’s current data protection framework. Working under tight time constraints, the DPO implemented mitigation measures in real time, including the creation of a Record of Processing Activities (RoPA) and clear, usable data protection policies.
The DPO helped formalise the NHS Data Security and Protection Toolkit (DSPT) submission process, ensuring responses were accurate, evidenced, and aligned with NHS and GDPR expectations. With a mandatory audit required in year one, a key focus was demonstrating accountability in a way that was both practical and auditable.
Senior leaders gained a clearer understanding of the DSPT’s importance, including clarification of the organisation’s in-scope status due to remote access to patient data. This sparked a positive cultural shift, with leadership now actively involved and better prepared to manage future submissions with confidence.
Outcome
The Business Supplies Group said:
‘The DPO Centre has been instrumental in guiding us through the Data Security and Protection Toolkit (DSPT) process. From the outset, they took the time to understand our business requirements thoroughly. Our DPO then conducted a comprehensive and insightful gap analysis, which laid a strong foundation for the work ahead. The project team was led with professionalism and clarity, ensuring everything stayed on track. Finally, a secondary DPO carried out the external audit with a level of thoroughness and fairness that gave us real confidence in the outcome. The entire team was professional, knowledgeable, and a pleasure to work with. We’re extremely grateful for their support.’