Information governance assurance

Data Protection & Cyber Security

At Daylong Direct, protecting patient, customer and healthcare professional data is central to how we operate. We continually invest in secure systems, staff awareness, supplier controls and recognised assurance standards to help keep information safe.

Cyber Essentials Plus Independently verified cyber security certification covering key technical controls.
NHS Data Security and Protection Toolkit Submission supporting safe handling of health and care information.
Secure service delivery Operational controls designed around patients, healthcare professionals, customers and suppliers.

Our commitment to protecting information

Clear governance around the information we handle

Daylong Direct handles information relating to NHS prescriptions, healthcare professionals, patients, customers and suppliers. We recognise the importance of protecting this information and maintaining strong governance around confidentiality, integrity and availability.

Our approach combines technical controls, staff training, secure processes and independent assurance. This supports our wider responsibility as an NHS prescription service provider and a trusted supplier of compression hosiery, wound care and associated healthcare products.

Independent assurance and recognised standards

Cyber Essentials Plus and NHS DSPT assurance

We continue to maintain recognised assurance through Cyber Essentials Plus certification and submission to the NHS Data Security and Protection Toolkit.

Cyber Essentials Plus certificate for Daylong Direct

Cyber Essentials Plus

Cyber Essentials Plus is an independently verified cyber security certification. It helps demonstrate that key technical controls are in place to protect against common cyber threats.

View Cyber Essentials Plus certificate

How we protect data

Practical controls for safe and reliable information handling

Our data protection and cyber security practices are designed to support safe, reliable and compliant handling of information across our business.

  • Secure access controls for systems and information.
  • Regular review of cyber security risks and controls.
  • Staff awareness and training around data protection responsibilities.
  • Secure handling of patient, customer and prescription information.
  • Ongoing supplier and system governance.
  • Continual improvement aligned with recognised assurance standards.

Supporting patients, healthcare professionals and partners

Data protection is part of responsible service delivery

Whether we are supporting a patient prescription, working with a healthcare professional, fulfilling a trade order or managing an online customer enquiry, we treat data protection and cyber security as core operational responsibilities.

We review our approach regularly so that our processes, systems and controls continue to support safe and reliable service delivery.

Patients and carers

Information is handled carefully to support prescription dispensing, delivery, customer service and appropriate follow-up.

Healthcare professionals

Processes are designed to support secure communication, accurate order handling and responsible information governance.

Partners and suppliers

Supplier and system governance helps us manage operational risk across the wider service environment.

Questions about data protection?

For questions about how Daylong Direct handles personal information, please contact us using the details on our contact page.