Blog · 29 July 2026
DSPT and Data Handling for Medico-Legal Agencies
Who holds which data duty as medical records move between agency, expert, and instructing firm, and where the DSPT fits for medico-legal work.
A claimant’s GP records leave the instructing solicitor, arrive at your agency, go out to a panel expert, and come back with a report. On a busy month that journey happens hundreds of times. Every handover is a point where special category health data can be exposed, and the agency in the middle often carries the exposure.
This guide sets out who holds which data duty as records move between agency, expert, and instructing firm, and where the DSPT fits for medico-legal work. For the wider agency picture, read information for medico-legal agencies and our guide to using AI on medical records.
What the DSPT is
The Data Security and Protection Toolkit is an annual self-assessment published by NHS England. Organisations that handle health and care information use it to measure their practice against the recognised data security standards and to evidence that they meet them. In UK health and care, it is the common marker of safe data handling.
For a medico-legal agency, the records in question are claimant medical records, which are special category data under UK GDPR. Completing the DSPT is the clearest way to show instructing firms and experts that the agency meets NHS data security standards, rather than asking them to take it purely on trust.
Who holds which duty
Medical records on a case pass along a chain and the data duty does not sit in one place. Depending on the arrangement, the instructing solicitor, the agency, and the expert can each be a data controller or a data processor at different points. You can read more on the specification of each on the ICO website.
The practical point for a director is this: do not assume another party carries the duty. Each organisation in the chain should know its own role under UK GDPR, hold the records in a controlled environment, and hand them on securely. A gap anywhere along the chain becomes everyone’s problem and the agency in the middle is the one the instructing firm calls.
What makes the processing lawful
Knowing your role is only half of it. Claimant medical records are special category data, and the condition that makes medico-legal processing lawful is Article 9(2)(f) of the UK GDPR: processing necessary for the establishment, exercise or defence of legal claims. The ICO worked example is an employer passing details of an employee injury to its solicitors to defend a personal injury claim, which is the business your panel is in.
Two features matter in practice. The condition covers prospective proceedings and obtaining legal advice, not only live litigation, so records instructed before issue are within it. Unlike most special category conditions, it needs no Schedule 1 condition under the Data Protection Act 2018 and no appropriate policy document. It is not a blank cheque, the records you hold still have to be necessary and proportionate to the claim, this bites hardest on a large multi-provider bundle where only part of the history is relevant. That is an argument for working from a structured record rather than circulating everything to everyone.
Where the exposure sits
Records moving between parties create risk at every step.
- Transfer. Records sent by insecure email or an open link, rather than a secure channel.
- Storage. Records held on an expert’s personal device or a consumer cloud account, outside any controlled environment.
- Retention. Records kept long after the case closes, with no schedule to delete them.
- Consumer AI. Records pasted into personal ChatGPT or Gemini accounts, which were never built for patient data and may retain inputs. One in five experts told the Bond Solon 2025 survey they already use AI tools in their work, and 89 percent said specific guidance on AI use is needed.
Any one of these can turn into a breach. The agency that placed the expert usually carries the contractual and reputational weight, whoever made the error.
What good data handling looks like
A director does not need to solve this case by case. A few standing rules cover most of the risk.
- Move records only through secure, encrypted channels, never open email or public links.
- Keep records inside controlled environments with the right data protection standing, on the agency side and the expert side.
- Set a retention schedule, and delete records when the case and any appeal window close.
- Ban patient data in consumer AI accounts, and give experts a compliant alternative.
- Hold, or require, a published DSPT status of Standards Met as the baseline marker of safe handling. Registration on its own only means an organisation has signed up. Hold, or require, DSPT registration as the baseline marker of safe handling.
One change is worth a diary note. The Data (Use and Access) Act 2025 amended UK data protection law, with most provisions commencing in February 2026 and a further tranche from 19 June 2026. The change most likely to reach an agency is a new statutory right for people to complain to a controller directly about how their data has been handled. In practice, that means a documented complaints route and an updated privacy notice, rather than a change to how the records themselves are handled.
Giving your panel a compliant route
A policy holds only if experts have a safe way to do the work. Health Narrator gives your panel one route that meets the standard on both counts.
Health Narrator holds NHS DSPT registration and conforms to DCB0129, the NHS clinical risk management standard for manufacturers of health IT, evidenced by a Clinical Safety Case Report. We have not seen that combination in another tool built for medico-legal work. The underpinning policies were audited by 8Fold Governance, a UK healthcare compliance consultancy specialising in information governance and clinical safety. The product takes the full bundle and produces a structured, source-referenced chronology, with every finding linked to the source line and a full audit trail. It uses no patient data for model training and importantly, records stay inside a controlled environment rather than a personal AI account, so the expert works from a compliant tool shaped to their specialty.
When an instructing firm asks how your agency handles data, DSPT registration and a compliant platform give you a straight answer.
See what Health Narrator does for your panel.
Book a demo: calendly.com/ed-healthnarrator/30min
Frequently asked questions
What is the DSPT?
The Data Security and Protection Toolkit is an annual online self-assessment published by NHS England. Organisations that handle health and care information use it to measure their practice against the data security standards and to show they meet them. It is the recognised marker of safe data handling in UK health and care.
Does a medico-legal agency need the DSPT?
A medico-legal agency handles claimant medical records, which are special category health data. Completing the DSPT is the clearest way to show instructing firms and experts that the agency meets NHS data security standards. It is increasingly expected in a market where records move between several parties on every case.
Who is the data controller for a claimant's records?
Responsibility depends on the arrangement, and more than one party may hold a duty. The instructing solicitor, the agency, and the expert can each be a controller or processor at different points as records pass along the chain. Each party should know its role under UK GDPR and handle the records accordingly, rather than assume someone else carries the duty.
What data risks arise when records move between parties?
Records passing between firm, agency, and expert create exposure at each handover: insecure transfer, storage outside a controlled environment, retention beyond need, and use of consumer tools not built for patient data. The agency often carries the reputational and contractual exposure when a record is mishandled anywhere along the chain.
Is it safe for an expert to use consumer AI on medical records?
No, not on a personal account. Consumer AI tools were not built for patient data, offer no clinical safety assurance, and may retain inputs. Records belong in a tool with the right data protection and clinical safety standing, such as a published NHS DSPT status and DCB0129 conformance, with a full audit trail and no use of data for model training.
Health Narrator turns full medical records into structured, source-referenced chronologies for medico-legal experts and agencies, in minutes.
Book a Demo