Dear Gloucestershire Health and Care NHS Foundation Trust,
Under the Freedom of Information Act 2000, please provide the following information:
1. A list of all external suppliers, contractors, or partner organisations who currently fall within the remit of the NHS Data Security & Protection Toolkit (DSPT) for your organisation.
This includes any supplier that handles patient data, accesses NHS systems, or provides digital, software, cloud, data-processing, or cyber-security services requiring DSPT compliance.
2. A list of any new, incoming, or planned suppliers (contracted or due to go live within the next 12 months) who will fall within the DSPT remit for the same reasons.
3. For each supplier identified in Q1 or Q2, please confirm (if recorded):
– Whether they are required to maintain a “Standards Met” DSPT submission
– The date you last checked or verified their DSPT status (or expected verification date for new suppliers)
4. Does your organisation maintain an internal register or log of DSPT-relevant suppliers (including planned or onboarding suppliers)?
– If yes, please provide the relevant extract.
– If no, please confirm that no such register exists.

