What NHS DSPT means in practice
The NHS Data Security and Protection Toolkit is the annual self-assessment that organisations handling NHS patient data must complete. It implements the National Data Guardian's data-security standards and ties to the Caldicott principles. The AI implications: any AI system processing patient-identifiable data must be evidenced as compliant with the DSPT's data-security and IG controls — system access controls, audit logging, breach response, role-based access, training. The Information Commissioner's Office has signalled in recent enforcement positions that prompts to a cloud LLM containing PHI constitute a cross-border processing event subject to UK GDPR Article 44. The practical consequence is that NHS-serving healthcare AI is increasingly sovereign-deployed by default.
Related terms
Sovereign AI →
An architecture where customer data never leaves the network perimeter, model weights run on customer-controlled hardware, inference logs stay in the customer's SIEM, and the entire stack can operate air-gapped.
HIPAA →
The US Health Insurance Portability and Accountability Act — sets the rules for handling Protected Health Information (PHI) and shapes how US healthcare can use AI on clinical data.
GDPR →
The EU's General Data Protection Regulation — sets the rules for processing personal data of EU residents, with significant implications for AI systems that touch that data.
More in this category
All 62 terms, in plain language
Sovereign AI, RAG, agentic AI, IDP, MLOps and the regulations that shape enterprise AI.