Why Cloud Adoption Is Now a DSPT and UK GDPR Question
GP practices, care providers and the suppliers who serve them are moving day-to-day operations — clinical systems, correspondence, rotas, incident logs — onto cloud platforms faster than most information governance policies can keep up. That shift is not optional for long: on-premise servers are expensive to maintain, harder to patch consistently, and increasingly out of step with what NHS commissioners expect a modern practice to run on.
But in health and care, "moving to the cloud" is not just an IT decision. Every cloud service that touches patient data sits inside your Data Security and Protection Toolkit (DSPT) submission and your UK GDPR accountability obligations. Choose the wrong provider, or sign the wrong contract, and you inherit a supplier assurance problem that surfaces the moment an assessor or an auditor asks who processes your data and where.
1. DSPT Assertions the Cloud Touches Directly
The DSPT is built around evidence, not intentions. Several assertions require you to demonstrate exactly how any cloud supplier fits into your data flows and your incident response:
- Supplier assurance: you must be able to show that every processor handling patient data — including your cloud host — has appropriate contractual and technical safeguards in place.
- Data flow mapping: if patient data leaves your building for a cloud environment, that flow needs to be documented, not assumed.
- Business continuity: a cloud provider's resilience and backup arrangements become part of your own continuity plan, and DSPT reviewers expect that link to be explicit.
- Access control: role-based permissions inside a cloud platform must map to who actually needs to see patient data in your practice, not to a default configuration.
None of this is a reason to avoid the cloud. It is a reason to treat supplier selection as a compliance exercise, not just a procurement one.
2. UK GDPR Article 32: Security of Processing for Special Category Data
Health data is special category data under Article 9 UK GDPR, which raises the bar set by Article 32's "appropriate technical and organisational measures" beyond what a generic small business needs. In practice, that means asking a cloud provider for more than a standard compliance page before you migrate:
- Where exactly is patient data stored and processed? UK or EU data centres remove a layer of international transfer analysis that you do not have time for during a busy clinical week.
- What does the Data Processing Agreement say about sub-processors? A cloud host that quietly relies on further sub-processors needs to disclose them, and you need to know before you sign, not after an incident.
- How is data encrypted, and who holds the keys? Encryption at rest and in transit should be the baseline, not a premium add-on.
- What is the breach notification commitment? Your 72-hour obligation to the ICO starts running from when you become aware — a provider with a vague or slow notification process puts your own compliance clock at risk.
- Is there a named point of contact for DSPT and audit evidence requests? You will need supporting documentation at renewal time, and chasing a generic support inbox is not a plan.
3. Where Practices Get This Wrong
The most common failure pattern is not malicious — it is drift. A practice manager adopts a convenient tool to solve an immediate problem (shared rotas, a messaging app, a scanning service), patient data ends up flowing through it, and nobody updates the ROPA, the data flow map, or the DSPT evidence to reflect it. Eighteen months later, an assessor asks a straightforward question — "what happens to a Subject Access Request if the data sits with this third party?" — and there is no answer ready.
The fix is procedural, not technical: any new cloud tool that will handle patient data should go through the same short checklist before it is adopted, not after.
4. A Practical Adoption Checklist for Health and Care Settings
- Confirm the provider will sign a Data Processing Agreement that meets Article 28 UK GDPR requirements.
- Record the new data flow in your ROPA and data flow map before go-live, not retrospectively.
- Map the tool's access controls to your existing role-based permissions.
- Add the supplier to your DSPT supplier assurance evidence and your incident response plan.
- Set a review date — supplier terms and sub-processor lists change, and your evidence needs to keep pace.
Handled this way, cloud adoption strengthens your DSPT submission rather than complicating it: modern platforms typically offer better encryption, access logging and resilience than an ageing on-premise server ever will. The advantage only holds if the paperwork and the practice keep pace with the migration.
If you are assessing a cloud migration against your current DSPT position, our DSPT support service and DataPro NHS Compliance Solution map supplier assurance evidence directly to the relevant assertions, so gaps like these show up before submission — not during an audit.