Online Sessions
Online Sessions and Webinars
LSCP delivers a series of online sessions to guide care providers through every stage of the Data Security and Protection Toolkit (DSPT). Whether you are brand new to the toolkit or looking to strengthen existing compliance, our sessions cover everything from registering and staffing requirements, to policies, data protection practices, and IT systems. Each session is practical, easy to follow, and designed to help you complete the DSPT with confidence. By taking part, providers gain the knowledge, tools, and assurance needed to protect sensitive information, meet regulatory standards, and build trust with service users, families, and partners.
- TR0 – Introductory Webinar
- TR1 – Getting Started and Staffing
- TR2 – Policies and Procedures
- TR3 – Data Security
- TR4 – IT Devices and Systems
- Business Continuity Plans and How To Test Them
- Data Protection impact Assessment (DPIA) Workshops
- Information Asset Register (IAR) & ROPA Awareness Workshops
- Understanding the Data Use and Access Act 2025
This is for organisations at the very start of their journey with the Toolkit, or staff who are new to this role. We will explore
-
What is the Toolkit?
-
Why should we register?
-
What does it offer?
-
How will it benefit my company?
-
Registering for the toolkit
-
Accessing your ODS code
-
Completing the questions around your staffing and their roles
-
Importance of cyber security training for your workforce
-
It may also help to define who has organisational responsibility for data security
-
Accessing supporting evidence, which enables you to complete the questions within this section.
-
Reviewing policy templates that you can adopt or help you check your own policies are current.
-
Ensuring that you have the evidence to show your organisation is compliant with current legislation
-
Reviewing the Information Commissioner’s guidance
-
Reviewing how your organisation does all it can to ensure good practice in Data Protection
-
Exploring the physical controls around data
-
Reviewing staff training and exploring their understanding of their responsibilities around data protection.
-
Examining Data breaches and how we report and handle them
-
Reviewing organisational firewalls and antivirus software (If your staff work from home, do they have firewall protection)
-
Reviewing staff using their personal phones, tablets or laptops for work use
-
Exploring how your organisation controls personal data
-
Examining how staff access organisational IT systems
- Understand the purpose of a Business Continuity Plan (BCP) in adult social care
- Identify the essential components every BCP must include
- Recognise the roles and responsibilities during a disruption
- Understand the importance of communication during an incident
- Know how BCP testing works and why it is required
- Recognise the focus on data and cyber security
A Data Protection Impact Assessment (DPIA) is a legal requirement under UK GDPR when an organisation undertakes processing that may pose a high risk to individuals.
By the end of the workshop, participants will be able to:
- Recognise when a DPIA is legally required
- Identify risks to personal data and judge likelihood and severity
- Apply each step of the DPIA process to real scenarios
- Use the ICO screening checklist and template effectively
- Embed data protection by design into new projects and changes
- Demonstrate how their organisation identifies and minimises data risks, directly supporting DSPT requirement 1.3.8
- Strengthen GDPR compliance and organisational transparency
Care providers are legally required under the Data Protection Act (2018) and UK GDPR to maintain clear records of what personal and sensitive data they hold, why they hold it, and who they share it with. Many providers remain unaware of the Record of Processing Activities (ROPA) requirement and its serious legal implications, especially around Article 6 (lawful basis) and Article 9 (special category data).
This workshop will guide you through the importance of both the Information Asset Register (IAR) and ROPA, helping you to meet compliance obligations and protect your staff, residents, and organisation.
Learning Outcomes
By the end of the session, you will:
- Understand the legal requirements for IAR & ROPA under GDPR/DPA.
- Be able to identify and record personal and special category data.
- Recognise the lawful bases for processing data (Articles 6 & 9).
- Learn how SMEs in the North West care sector can achieve compliance.
- Gain confidence in setting up and maintaining your own IAR & ROPA.
- Understand Digital Asset Registers (DAR) and How to Complete them.
The Data Use and Access Act 2025 (DUAA) represents the most significant update to UK data protection law since the introduction of UK GDPR. While it does not replace GDPR, it introduces important changes that directly affect how adult social care providers use, share, and manage personal data in practice.
Many organisations are currently unaware of how these changes impact their day-to-day operations, policies, and DSPT submissions. This practical workshop provides a clear and accessible introduction to the DUAA, focusing on what has changed, why it matters, and what providers need to do now to remain compliant. This session will:
- Explain what the Data Use and Access Act 2025 is and why it matters for adult social care
- Identify the key DUAA changes that impact day-to-day practice, including RLI, SAR updates, and complaints requirements
- Apply Recognised Legitimate Interests (RLI) in real safeguarding and information-sharing scenarios
- Understand the new statutory data protection complaints process and staff responsibilities
- Describe the impact of Section 121 on digital systems, suppliers, and interoperability
- Identify which organisational policies and procedures must be updated for DUAA compliance
- Recognise roles and responsibilities across the organisation for implementation
- Understand how DUAA changes affect DSPT evidence requirements