How to successfully navigate Clinical Risk, CSO, DTAC, DSPT, GDPR and Medical Device regulations.
In short you need to be aware of the compliance and data protection regulations landscape that affect your technology. This means getting an understanding of the key requirements and formulating a plan to achieve them.
A good start is to consider:
Starting your compliance journey early on, ideally working alongside your development will save you time and money in the long run. This is particularly true for DTAC where good practice is to keep your development aligned with the DTAC standard.
GDPR and the Information Commissioner’s Office
ICO Registration Requirement: If your innovation involves processing personal data, it is mandatory to register with the Information Commissioner’s Office (ICO). This step ensures compliance with data protection regulations.
Leveraging the Data Security and Protection Toolkit (DSPT)
The DSPT serves as an online self-assessment tool, evaluating an organisation’s adherence to the National Data Guardian’s 10 data security standards. It is crucial for organisations that access NHS patient data and systems. Completing the toolkit helps ensures robust data security practices. Additionally, the Digital Social Care website offers free resources, including templates, to assist with DSPT
The importance of DTAC in the NHS
Getting acquainted with the Digital Technology Assessment Criteria (DTAC): DTAC assists healthcare organisations in evaluating suppliers during procurement or due diligence processes. It sets out the minimum standards required for entry into the NHS and social care. Compliance with DTAC is of growing significance as NHS Integrated Care Boards increasingly undergo audits to ensure adherence.
Adherence to the Data Protection Act
If your innovation involves handling personal data, it is crucial to comply with the Data Protection Act. This requirement is also covered in the Digital Technology Assessment Criteria (DTAC) guidelines.
Is your product a medical device?
Assessing whether your software qualifies as a Medical Device: Certain software applications may fall into the medical device category. If this applies to your innovation, ensure compliance with the requirements outlined in the UK Medical Device Regulations 2002 (UK MDR 2002) and proceed to register your innovation with the Medicines and Healthcare products Regulatory Agency (MHRA). It is advisable to consult with the MHRA to confirm whether registration is necessary for your specific medical device.
Efficacy and the need for Clinical Evidence
Maintaining your evidence files for compliance is a must. Compliance is not a ‘one off tick box exercise’, to remain compliant you must maintain your evidence file. As you develop your product whether it be another release or even something new, consider how it affects your compliance. Does it have a risk to harm patients for example, or does it have data protection implications. Think about the risk to your credibility and business relationships if it goes wrong.
Plan your route!
Assign an owner, you should assign responsibility for maintaining your compliance to a named owner. They and you should be promoting compliance into your ways of working.
By address regulatory, ethical, and financial considerations to ensure your app is safe, effective, trustworthy, and sustainable.
Top Tips for getting NHS Compliance
Our top tips to achieving a quicker market entry are to:
Start your compliance preparation early: It’s never too late, but starting early saves you money in the long run.
Know your compliance: Understand what regulations affect you.
Develop a plan: Fail to plan then you plan to fail!
Draw on specialist resource when you need it.

