What a hospice needs to do to be compliant
Publish the DSPT by 30 June each year, hold CQC registration for the care you deliver, and name a Data Protection Officer — for a hospice that is effectively required, not optional. Fundraising adds its own data rules, and trustees answer to the Charity Commission for cyber incidents.
Reviewed 5 July 2026 · Neil Chandarana, founder, Highguard
Every requirement for a hospice, in plain English.
DSPT, every year, visible to your commissioners
- Publish annually by 30 June
- Expected under NHS Standard Contract terms
- Status publicly visible
Hospices complete the DSPT in the category for charities and NHS business partners, publishing by 30 June each year. The NHS Standard Contract carries a data-security condition, so ICB-commissioned hospices are expected to hold a current publication, and your status sits on a public register that commissioners can check. The scope is your health and care data: clinical records, medication, referrals. The charity shop and the lottery are out of scope.
Sources: DSPT Toolkit · NHS Standard Contract
CQC registration and Regulation 17
- Registration for regulated activities
- Regulation 17 and well-led cover data and cyber
A hospice delivers regulated activities, so CQC registration is a given, and with it Regulation 17: accurate, complete and secure records, and effective governance and information systems. Data and cyber are assessed under the well-led question. A workforce that mixes clinicians, employed staff and volunteers makes the records, training and access-control side genuinely harder, and inspectors know it.
A Data Protection Officer, in practice required
- DPO effectively required
- Can be shared or outsourced
- ICO fee renews annually
The UK GDPR requires a DPO where the core activity is large-scale processing of special category data. Palliative care records are exactly that, which puts most hospices over the line: a named DPO, not a nice-to-have. The role can be shared or outsourced, but it must exist, and the ICO fee renews annually alongside it.
Fundraising data, under two sets of rules
- New Code of Fundraising Practice from Nov 2025
- Charity soft opt-in live since Feb 2026
- Every message needs an opt-out
The Code of Fundraising Practice, rewritten with effect from November 2025, embeds data protection into fundraising standards. Separately, the Data (Use and Access) Act extended the soft opt-in to charities from February 2026: you can email or text previous supporters without fresh consent, provided every message offers an opt-out. For a hospice this is a real opportunity, but only with clean supporter data and records of who came from where.
Sources: Fundraising Regulator
Trustees and the Charity Commission
- Serious incident reporting for breaches
- Cyber risk is a trustee duty
Significant data breaches and cyber attacks are reportable to the Charity Commission as serious incidents, and failing to report can itself be a breach of trustee duties. Managing cyber risk is part of the duty to protect the charity, which means trustees need honest reporting on where the hospice stands, not reassurance.
Sources: Charity Commission
Cyber Essentials, when contracts ask
- Driven by procurement, not regulation
- NCSC has funded it for small charities
Cyber Essentials is not universal for hospices, but NHS and public-sector procurement increasingly requests it, and the NCSC has run a funded Cyber Essentials programme for small charities in higher-risk sectors. If you bid for commissioned services, expect it in the paperwork and budget time for the technical controls it checks.
Sources: NCSC
Hospice compliance as you grow.
Inpatient hospice
CQC registration, a DSPT publication, a named DPO, and fundraising running under the code. The full list from day one, because the data is clinical from day one.
Hospice at home and community services
Care delivered in people's homes multiplies devices, access routes and records on the move. Shared care record access depends on keeping the DSPT current.
Wider NHS-commissioned services
More ICB contracts mean more data-security clauses, commissioner checks on your published DSPT, and Cyber Essentials appearing in bids.
Hospice compliance, asked and answered.
Does a hospice have to complete the DSPT?
Yes, in practice. Hospices handling NHS patient data or holding NHS and ICB contracts complete it in the category for charities and NHS business partners, publishing by 30 June each year, and commissioners can see the published status.
Does a hospice need a Data Protection Officer?
In almost all cases, yes. Large-scale processing of special category health data as a core activity triggers the UK GDPR DPO requirement. The role can be outsourced, but it must be filled and named.
Can we email past donors without consent?
Since February 2026, yes, under the charitable soft opt-in introduced by the Data (Use and Access) Act. It covers people who previously supported you, and every email or text must offer a clear opt-out.
Is a cyber attack reportable to the Charity Commission?
Significant incidents are. Breaches and attacks that cause serious harm to the charity, its funds or the people it serves should be reported as serious incidents, and trustees are responsible for making that call.
Does CQC look at a hospice's data security?
Yes. Regulation 17 requires secure, accurate records and effective information systems, and data and cyber sit under the well-led question at inspection.
Why this list keeps getting longer.
Somewhere along the way, compliance stopped being about security and became about admin. Portals, spreadsheets, evidence uploaded again and again, policy templates nobody reads.
The result is organisations that are certified but not secure. Teams that are busy but not protected.
It should not work like this. Compliance should be a side effect of good practice. Evidence of the work you already do, not a second job on top of it.
That is why Highguard exists. We are your compliance department. Specialists and AI agents do the work on this page, and you approve every word before anything is submitted.
Every engagement starts with an audit. In your first week you get a report of where you are compliant and where you are exposed, specific to your organisation.
Talk to us →Talk to us.
Book a 15-minute call. We'll show you where you stand and how fast we can get you certified.