Go to content

Emails about data protection officer requirements

Dental practices are receiving emails from the Data Protection Officers Association (DPOA) containing claims about data protection officer (DPO) requirements and NHS Data Security and Protection Toolkit (DSPT) compliance.

While NHS dental practices are required to appoint a DPO, this is not an obligation for most private practices. Members can use our GDPR for dental practices advice to determine their obligations or speak to a member of our advice team. We also have a course on data protection that members can access as well as training for DPOs.

There is no separate obligation to register your DPO with the Information Commissioners Office (ICO) however you will notify the ICO as part of your fee registration and details of your DPO can be updated on the ICO website.

Members can use our template guide to completing the NHS Data Security and Protection Toolkit for accurate information on the latest DSPT requirements.

If you are a member and concerned about your obligations, please contact our advice team.

We have also contacted the ICO. The regulator is aware of this communication and has received a high volume of related enquiries.


Bespoke help when you need it

1-2-1 advice for Extra and Expert members

As an Extra or Expert member, you can rely on unlimited, one-to-one support from our industry experts whenever you need it. Whether you need quick guidance or in-depth support, our expert advisors are here to help.