Our GDPR Compliance Vetting Service

Protect your organisation from ICO fines, legal action, and data breach risks by ensuring your suppliers are fully UK GDPR compliant.

No Fees!
There are no fees, costs or charges for this report.There are no fees, costs or charges to amend and rescind this report.
All fees are paid by the third party for compiling this UK GDPR report. This report is sent to you for information purposes allowing you the opportunity to address any of the UK GDPR issues before any further action is taken.

Loading practice details…

NHS, ICO and CQC GDPR Compliance Report for Heswall Allen

The Report

dentaal have registered with the ICO as a Data Controller. This has been confirmed on the ICO website. This is correct.

dentaal have registered with the the Care Quality Commission. This is correct.

dentaal have completed NHS DSP Tool Kit before the 30th June deadline. This is correct.

  1. dentaal have not appointed a DPO. This is a breach of their NHS contract and mandatory CQC requirement.
  2. dentaal have not informed the ICO about the appointed DPO on their Data Controller registration. This is a breach of their NHS contract and a mandatory ICO requirement.
  3. dentaal have not named the DPO or given any details about the appointed DPO on the NHS DSP Tool kit that was submitted in 2025 and 2026. This is a breach of their NHS contract and mandatory CQC requirement.
  4. dentaal have continued to store and hold sensitive medical data without the oversight of a qualified and trained DPO as contractually required by the NHS and legal requirement of the ICO. This is a breach of their NHS contract and mandatory CQC requirement.
Detailed Explanation of this Report

dentaal are not GDPR complaint and their NHS DSP Tool Kit is in error.

As a public authority dentaal was required to appoint a trained and qualified DPO. The name and details of the appointed DPO should have been entered in section 1.1.5 of the NHS DSP Tool kit. No appointed trained and qualified DPO was entered there. This is a contractual and mandatory requirement for all public authorities. The NHS DSP Tool Kit is in error.

The June 2025 and June 2026 NHS DSPT Tool Kit were filled in by dentaal and submitted.

This was submitted to the NHS and CQC but due to NOT appointing a trained and qualified DPO dentaal are in breach of their NHS Contract and NOT GDPR compliant. This NHS DSP Tookit Error must be corrected.

No trained and qualified DPO has been named and appointed on the ICO Data Controller register.

This is required by the ICO, NHS and CQC
https://ico.org.uk/for-organisations/data-protection-fee/change/update-your-registration-details/

Contact us

Below are the Public NHS, ICO and CQC public registers that this GDPR DPO report has been based on.

You can verify the details in this report referencing these public registers to ensure this report on dentaal is accurate, up to date, and compliant with the NHS, ICO, and CQC data protection mandatory requirements.

Official Public Access NHS, ICO and CQC Registers Used in this GDPR Report:

NHS DSP Tool Kit Organization Search Links

https://www.dsptoolkit.nhs.uk/OrganisationSearch

NHS Data Security and Protection Tool Kit. Key Roles and the DPOKey Roles section 11 Data Protection Officer: See points 1,2,7,8

https://dsptoolkit.nhs.uk/Help/Attachment/61

Care Qulaity Commission Public Authority DSP Tool Kit Status Search

https://www.cqc.org.uk/search/all?filters%5B%5D=services%3Adentist&radius=all

Information Commissioners Office (ICO) Data Controller Register

https://ico.org.uk/esdwebpages/search

Information Commissioners Office (ICO) . Do I need a Data Protection Officer (DPO)?

https://ico.org.uk/for-organisations/data-protection-fee/does-my-organisation-need-a-data-protection-officer-dpo/

Conclusion of the GDPR Report:

No Qualified, trained DPO has been appointed by dentaal as required by the NHS.

dentaal are not GDPR compliant and are in breach of their NHS contract for not appointing a trained and qualified DPO for their practice.

dentaal in breach of their NHS Contract.

dentaal failed to appoint and designate a trained and qualified appointed DPO in the NHS DSP Tool Kit as a mandatory NHS requirement because no trained and qualified DPO has been appointed. Their NHS DSP Tool Kit is invalid and should be designated as “Regulations not met”

ICO Not informed of their appointed DPO

dentaal has NOT informed the ICO of the appointment of a trained and qualified DPO by amending their ICO Data Controller registration because they have not appointed a trained and qualified DPO.

dentaal must be reported to the Care Quality Commission and receive a CQC inspection.

Do not ignore this GDPR report:

Under Article 37(1)(a) of the GDPR it is illegal for a public authority to legally claim that its data protection standards are met if it has failed to appoint a Data Protection Officer (DPO). Currently The dentaal currently have a NHS and CQC quality rating as “Regulations Met” This is an incorrect and misleading claim and MUST be reported to the Care Quality Commission (CQC) if not rectified.

Once reported the CQC can either give two weeks notice prior to their inspection or in the case of any illegal activity or reports inspect your premises without any prior notice.

Four steps you MUST take to correct this serious NHS DSP tool kit error and avoid a Care Quality Commission (CQC) GDPR inspection.

The Four Steps you must take to resolve the DPO issue.

1. As required by the NHS, ICO and CQC you must appoint a trained and qualified DPO for your dental practice.

This can be an external DPO company or individual who is an expert on GDPR and has been trained as a medical DPO or an internal DPO who has been trained and expert in GDPR. However if you appoint an internal DPO we will require proof of the DPO and GDPR training for your nominated internal DPO.

Please note:

The courses and certificates below do not satisfy our training requirements for an internal DPO and do not meet our criteria for GDPR and DPO training verification:

Level 2 Data Protection Certificates. Data Security Level 1 on e-lfh Certificates and BDA DPO Certificates.

We will also not accept Free GDPR Compliance DPO Courses Like:

Allison DPO Certificates.“Train Me UK” DPO Certificates Similar free DPO training certificates. For more information please contact us using the form above.

2. We will require a confirmation that you have updated the ICO Data Controller registration informing the ICO who your appointed DPO is.

3. We will require a confirmation that you have updated your NHS DSP Tool Kit.

4. At the bottom of your privacy policy you should state the name and contact details of your new DPO. We need to have a website link to your privacy policy to confirm this.

Once we have this information we will amend this report and not report Corfe Mullen Dental Practice to the CQC and will inform the third party that you are now GDPR compliant.

IMPORTANT: On the email notification you received we have stated the date to send this report to the third party and to report this NHS breach of contract to the CQC for their investigation. Please act promptly!

You can send this information to us using the form above or send an email to us at info@rockwelldatacorp.com. *No personal data is stored or used.

The CQC Inspection: According to our records Corfe Mullen Dental Practice’s last CQC inspection was several years ago and is currently due for another Care Quality Commission Inspection. This GDPR DPO Non Compliance report will bring that CQC inspection forward.

To check the date of the last CQC inspection on your dental practice please go to:
https://www.cqc.org.uk/search/all?filters%5B%5D=services%3Adentist&radius=all

This third party GDPR vetting report is in line with Article 28(1) of the UK GDPR requirement law 2018 and is supported by the accountability principle in Article 5(2) and risk rules in Recital 76.