Metaluxo
← Insights

HealthTech

NHS GDPR Compliance: A Practical Guide for HealthTech Vendors

For 'NHS GDPR' — and most vendors are not ready.

The NHS is one of the largest buyers of HealthTech in the world. It is also one of the most regulated. Every vendor that touches patient data — whether a symptom tracker, a telemedicine platform, or an AI diagnostic tool — must satisfy GDPR, the NHS Data Security and Protection Toolkit, and often the NHS Digital Assessment Questions.

At Metaluxo we work with HealthTech startups preparing for NHS contracts. The gap between a working product and a contract-ready product is almost always compliance, not functionality.


The three gates every HealthTech vendor must pass

Gate 1: GDPR and special-category data

Patient data is special-category data under GDPR Article 9. This means:

  • You need both an Article 6 lawful basis and an Article 9 condition
  • Consent is rarely the right choice because patients can withdraw it
  • You must conduct a Data Protection Impact Assessment before processing begins
  • You need a Data Processing Agreement with every NHS organisation you work with
  • You must register with the ICO and pay the data protection fee

Most HealthTech founders we meet have a privacy policy and a cookie banner. They do not have a DPIA, a records of processing activities, or a data retention schedule. These are not optional for NHS contracts.

Gate 2: The NHS Data Security and Protection Toolkit

The DSPT is a self-assessment framework with ten standards:

  1. Leadership and accountability
  2. Data security training
  3. Data security incident management
  4. Access control and identity management
  5. Data security standards and policies
  6. Data asset management
  7. Technical security controls
  8. Secure data transfer and sharing
  9. Data disposal and destruction
  10. Third-party assurance

Each standard has mandatory assertions and evidence requirements. You cannot simply answer “yes.” You must upload policies, screenshots, training records, and incident logs.

For a startup, the DSPT takes 2–4 weeks to complete the first time. It is not a one-off — you must renew it annually.

Gate 3: The NHS Digital Assessment Questions

If your product is a digital health technology — an app, a platform, or an AI tool — the NHS may require you to complete the DAQ. This covers:

  • Clinical safety (DCB0129 / DCB0160)
  • Usability and accessibility
  • Data privacy and GDPR
  • Cyber security (aligned with DSPT)
  • Interoperability
  • Change management

The DAQ is not mandatory for every contract, but it is mandatory for any technology listed on the NHS Apps Library or procured through NHS frameworks.


What to prepare before the first NHS conversation

  1. A Data Protection Impact Assessment — specific to your product, your data flows, and your NHS use case. Not a template. A document that names your risks and your mitigations.

  2. A signed Data Processing Agreement — with the NHS organisation, not just your terms of service. The NHS has standard DPA wording and will not accept yours without review.

  3. Evidence of encryption — data at rest and in transit. The DSPT asks for specific algorithms (AES-256, TLS 1.2+).

  4. An incident response plan — with NHS-specific notification paths. You must be able to notify the NHS within 24 hours of a data breach.

  5. A clinical safety case — if your product influences clinical decisions. This requires a clinical safety officer and adherence to DCB0129.

  6. DSPT completion — ideally before the procurement conversation, not after.


Common mistakes HealthTech vendors make

  • Using a generic privacy policy. The NHS will read it. If it does not mention health data, special-category processing, or your NHS data flows, you will be asked to rewrite it.
  • Assuming cloud hosting in the UK is enough. The NHS may require NHS-approved hosting (NHSD-approved data centres or HSCN-connected environments).
  • Underestimating the DAQ. It is 100+ questions. Many require evidence attachments. Start it early.
  • Forgetting about staff training. DSPT Standard 2 requires evidence that staff have completed data security training. A certificate from an online course is usually sufficient.

Timeline from first contact to contract

MilestoneTypical timeline
Initial NHS conversationMonth 0
DSPT completionMonth 1–2
DAQ completion (if required)Month 2–3
DPIA and DPA signedMonth 2–3
Technical security reviewMonth 3–4
Pilot agreement signedMonth 4–6

The NHS moves slowly. Procurement timelines of 6–12 months are normal. The vendors that win are the ones that arrive prepared.

At Metaluxo we run NHS readiness programmes for HealthTech startups, typically delivering a completed DSPT, a product-specific DPIA, and a draft DPA in six weeks. If you are preparing for an NHS contract or funding round that depends on one, book a free 30-minute consultation and we will tell you exactly where you stand.

Common questions

Do HealthTech apps need NHS approval before launch?

Not always, but if your app processes NHS patient data or integrates with NHS systems, you will need a Data Processing Agreement and usually a Data Protection Impact Assessment.

What is the NHS Data Security and Protection Toolkit?

It is a self-assessment framework all NHS organisations and their suppliers must complete annually. It covers ten standards including leadership, access control, and incident response.

Can a startup handle NHS GDPR compliance without a DPO?

If you process health data at scale, you need a DPO. For a small pilot, a named privacy contact may suffice, but the NHS will ask who owns data protection.

Related reading

Send us a message
Message us Book now