Back to Compliance

DSPT Alignment

CareLedgerPro

Version 1.1 — Last updated: 19 July 2026

How CareLedgerPro maps to DSPT areas

This page describes how CareLedgerPro's controls map to areas commonly assessed in the Data Security and Protection Toolkit (DSPT). It is provided as reference information for Controllers preparing their DSPT submission. CareLedgerPro is not DSPT-certified, does not submit DSPT on behalf of Controllers, and does not guarantee a DSPT outcome.

  • Role-based access control — staff are granted least-privilege permissions and can only access clients, groups and records they are explicitly assigned to.
  • Append-only audit logging — every access and change to financial records is recorded with user, timestamp and before/after detail. Changes are recorded in an audit log rather than silently overwritten.
  • Encryption in transit and at rest TLS 1.2+ protects data in transit and managed database encryption protects data at rest.
  • Backups and recovery — automated encrypted backups with point-in-time recovery and a documented disaster-recovery process.
  • Incident response and breach notification — a structured workflow supports detection, triage, containment, notification and review, and is designed to support workflows relevant to UK GDPR Article 33.
  • Retention, deletion and supplier governance — defined retention periods, authenticated irreversible deletion, and appropriate data processing agreements and supplier safeguards.

Provider responsibility

The care provider remains responsible for its own DSPT submission, internal governance, staff training and policy compliance. CareLedgerPro supplies the technical controls and evidence base, but the provider must complete and submit its own assessment and ensure its use of the platform aligns with its own policies and procedures.

Related pages: Security Overview, Incident Response Plan, Sub-processors, Data Retention Policy, Data Deletion Policy.

Read the full DSPT Support Summary

Access control

Role-based permissions with least-privilege access to clients, groups and records.

Audit logging

append-only audit logs of every access and change, exportable for investigations.

Encryption

TLS 1.2+ in transit and managed encryption at rest.

Backups

Automated encrypted backups with point-in-time recovery.

Incident response

Structured workflow for detection, triage, containment and review.

Retention & deletion

Defined schedules and authenticated irreversible deletion.

Supplier governance

Sub-processors are engaged under agreements designed to support UK GDPR obligations. Hosting is in EU/UK-aligned regions. See the Sub-processor List for details.

Control summary

  • Access control — least-privilege access to clients, groups, and records.
  • Audit logging — logs of every access and change, exportable for investigations.
  • Encryption — TLS 1.2+ in transit and managed encryption at rest.
  • Backups — automated encrypted backups with point-in-time recovery.
  • Incident response — structured workflow for detection, triage, containment, and review.
  • Retention and deletion — defined schedules and authenticated irreversible deletion.
  • Supplier governance — sub-processors are subject to appropriate agreements and hosting is in EU/UK-aligned regions.

Not independently certified. Not legal advice. CareLedgerPro provides controls designed to help Controllers meet their obligations under UK GDPR, safeguarding standards, and CQC evidence expectations. Final responsibility for compliance, DPIA completion, DSPT submission, DSAR handling, and record retention rests with the provider.