DSPT Alignment
CareLedgerPro
Version 1.1 — Last updated: 19 July 2026
How CareLedgerPro maps to DSPT areas
This page describes how CareLedgerPro's controls map to areas commonly assessed in the Data Security and Protection Toolkit (DSPT). It is provided as reference information for Controllers preparing their DSPT submission. CareLedgerPro is not DSPT-certified, does not submit DSPT on behalf of Controllers, and does not guarantee a DSPT outcome.
- Role-based access control — staff are granted least-privilege permissions and can only access clients, groups and records they are explicitly assigned to.
- Append-only audit logging — every access and change to financial records is recorded with user, timestamp and before/after detail. Changes are recorded in an audit log rather than silently overwritten.
- Encryption in transit and at rest — TLS 1.2+ protects data in transit and managed database encryption protects data at rest.
- Backups and recovery — automated encrypted backups with point-in-time recovery and a documented disaster-recovery process.
- Incident response and breach notification — a structured workflow supports detection, triage, containment, notification and review, and is designed to support workflows relevant to UK GDPR Article 33.
- Retention, deletion and supplier governance — defined retention periods, authenticated irreversible deletion, and appropriate data processing agreements and supplier safeguards.
Provider responsibility
The care provider remains responsible for its own DSPT submission, internal governance, staff training and policy compliance. CareLedgerPro supplies the technical controls and evidence base, but the provider must complete and submit its own assessment and ensure its use of the platform aligns with its own policies and procedures.
Related pages: Security Overview, Incident Response Plan, Sub-processors, Data Retention Policy, Data Deletion Policy.
Access control
Role-based permissions with least-privilege access to clients, groups and records.
Audit logging
append-only audit logs of every access and change, exportable for investigations.
Encryption
TLS 1.2+ in transit and managed encryption at rest.
Backups
Automated encrypted backups with point-in-time recovery.
Incident response
Structured workflow for detection, triage, containment and review.
Retention & deletion
Defined schedules and authenticated irreversible deletion.
Supplier governance
Sub-processors are engaged under agreements designed to support UK GDPR obligations. Hosting is in EU/UK-aligned regions. See the Sub-processor List for details.
Control summary
- Access control — least-privilege access to clients, groups, and records.
- Audit logging — logs of every access and change, exportable for investigations.
- Encryption — TLS 1.2+ in transit and managed encryption at rest.
- Backups — automated encrypted backups with point-in-time recovery.
- Incident response — structured workflow for detection, triage, containment, and review.
- Retention and deletion — defined schedules and authenticated irreversible deletion.
- Supplier governance — sub-processors are subject to appropriate agreements and hosting is in EU/UK-aligned regions.
Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.