Skip to content

National data guardian’s security standards

The ten data security standards to be met are:

  1. Colleagues handle, store and transmit personal confidential data securely, whether in electronic or paper form.
  2. Colleagues understand their responsibilities under the national data guardian’s data security standards.
  3. Colleagues complete appropriate annual data security training and pass a mandatory test.
  4. Personal confidential data is only accessible to colleagues who need it for their role and access is removed as soon as it is no longer required.
  5. Security breaches and near misses are recorded and used to inform the management of problem processes.
  6. Cyber-attacks against services are identified and resisted and CareCERT security advice responded to.
  7. A continuity plan is in place to respond to threats to data security, including significant data breaches or near misses.
  8. No unsupported operating systems, software or internet browsers are used within the IT estate.
  9. A strategy is in place for protecting IT systems for cyber threats.
  10. IT suppliers understand their obligations as data processors under General Data Protection Regulation (GDPR).