This is the gold.
It is the thing we hold that is worth something. A person's record. A reading from a machine. A number a nurse typed in.
The gold came with a promise.
Whoever gave it to us was told things.
The boxes are what we do with the gold.
The boxes are the computers. They sort the gold, move it about, and let the right people use it. Without them the gold just sits there.
We like the boxes.
Right now we count the boxes first.
We ask which boxes the hospital cannot run without. Then we ask how strong each one should be.
The gold gets a mention as the thing inside the important boxes.
We ask the wrong person.
We ask the people who look after the boxes. How strong does your box need to be?
The custodians of the gold made the promise. They hold it for the people it belongs to. They know what it needs. Nobody asks them.
The box people are in a hurry.
They are told: make more boxes, and make them fast. That is their job, and it is not a bad job.
Keeping the gold safe slows the boxes down. So when you ask the box people how strong a box should be, the answer is strong enough to keep going.
Nobody speaks both languages.
The custodians know the promise. They do not know boxes.
The box people know boxes. They do not know the promise.
So when a box changes, nobody can tell whether the promise just broke.
A strong box can still break the promise.
The box passed its check. The box is fine. Nobody was checking the promise. They were checking the box.
The rulebook already knows.
The rules have a line that says: if the gold is about a person, its box counts. It does not matter how small the box is or how often it is used.
That line is on the last page. The counting comes first. So people count the boxes and never turn the page.
Your turn.
A box is only needed once a month. It is full of people's records. Is it in or out?
Write the promise down so the box people can read it.
Not as a feeling. As things anyone can check. The custodian writes the condition. The box people write the check. A line is not done until both agree it means the same thing. Then every time a box changes, the box people tick which lines they touched, and the custodians say yes before the box closes.
What changes on Monday.
Custodian and cyber write the register together, one per set of gold. Scoping starts from it: a box is in if it touches a line. After that, every change to a box looks like this.
The DPO and GRC go through the touched lines together, so the DPO gets the technical side explained honestly by someone whose job is to explain it. No new tool. No change to the framework.
Yes, but.
The custodians want the box as strong as possible.
No. They want the promise kept. The promise is a list, not a maximum. Write it down and there is nothing left to argue for above it.
Risk management already balances security and operation.
It does, for everything the register does not fix. The register is the lines you cannot trade, because they were promised to someone else. Risk management is for everything else, and there is plenty of it.
What about OT? There is no personal data in a pump.
Gold is whatever the box exists to handle. A set point is gold. A sensor reading is gold. The promise on it is about staying right and staying available, and the custodian is whoever owns the plant.
We already have a DPIA.
Then you have the promise written as principles. The register is the same promise written as checks. Same document, made readable to the box people.
This will slow delivery.
It moves the promise to the front, where it is cheap, and adds one field to a change ticket. What it removes is the rework nobody planned for.
The framework is function-led and we are assessed against it.
The framework already says gold about a person pulls a box in, whatever the function needs. We are moving that line to the front, not replacing the framework.
Who owns this?
Custodians write it. Cyber checks it. The DPO and GRC go through the touched lines together. The seat between custodian and cyber, the one that turns a promise into a check, is empty in most places. Fill it, or do it explicitly in the room.
We do not know what our gold is.
Scoping already expects an information asset register as an input. Start there. If it does not exist, that is the first finding.
Start with the promise, written down.
Ask what was promised for this gold. Write it as things anyone can check. Then ask what any box holding it has to be.
You still get your list of boxes. You get it in the right order. And you get the boxes the counting missed.
For grown-ups.
The gold is information. The promise is the set of obligations on it. The boxes are systems. The counting is the CAF-aligned DSPT scoping exercise. The custodians are the information asset owners and the DPO, holding the information on behalf of the people it is about. The written promise is a conditions register: one line per obligation, stated as a checkable fact, set by the custodian, checked by cyber at every change. Wording below is quoted from the pages linked so you can check it.
IT COUNTS BOXES FIRST
The scoping exercise identifies essential functions, then "all information, systems and networks which support your essential functions" whose compromise would hit continuity of the service. NHS England, Scoping essential functions
BOXES ARE COUNTED OUT BY TOLERANCE
The same page allows systems to fall out of scope where disruption would only matter after "days, weeks or months, rather than hours". That is a tolerance, and a promise is not a tolerance.
THE RULEBOOK ALREADY HAS THE PROMISE IN IT
The same page says that where data is subject to UK GDPR and the DPA 2018, the underlying information, system or network "should be included in your DSPT assessment". For example: a research team's spreadsheet of patient records, used a few times a year, is in scope. This clause is written after the function scoping and the tolerance paragraph does not refer back to it.
IT ASKS THE BOX OWNERS
A1.b lists the key roles: DPO, SIRO, Caldicott Guardian, IG lead, cyber lead. Structuring teams is "a local decision". A1.c says the teams conducting cyber and IG activity are best placed to decide, under a risk appetite set "regarding the essential function(s)". No role for the owner of a particular set of information is named. NHS England, A1 Governance
THE BOX OWNERS HAVE A COMPETING GOAL
Engineering is measured on delivery. From that seat every obligation is a constraint. That is the incentive the role is built on, not a flaw. Put the "how strong" question to that seat and the floor is negotiated down. Put the "what does the gold need" question to the custodians and engineering gets a fixed floor to build to.
TWO LANGUAGES
A1.b requires "clear and well-understood channels for communicating and escalating risks". A2.a indicator A#7 requires DPIAs to be updated on technical change to systems. Neither defines what a relevant change looks like from cyber's side. The register is the definition. NHS England, A2 Risk management
THE EMPTY SEAT
IG owns the promise. Cyber owns the boxes. The work of turning one into checks on the other is information security, and in most organisations nobody is named for it. A1.b lists the DPO, SIRO, Caldicott Guardian, IG lead and cyber lead. None of them is that seat. The register session is where the work gets done until someone is.
THE PROMISE ITSELF
UK GDPR Article 5(1)(f) requires personal data to be processed in a manner that ensures appropriate security. The ICO calls this the security principle. For example: a discharge letter emailed to the wrong GP practice breaks it, and no system was involved. ICO, Principle (f)
STRONG BOX, BROKEN PROMISE
Principle B3 protects data "important to the operation of your essential function(s)". A leak from a system the function does not depend on is outside that sentence. NHS England, Principle B3
THE DPO CAN SEE THE REGISTER
Under UK GDPR Article 39 the DPO must monitor the DPIA's ongoing performance. For example: a new sharing route to a supplier opened with no system change is exactly what the DPO is meant to catch, and a register line makes it visible. ICO, How do we do a DPIA
SCOPE. This page makes one argument: the conditions on the information should be the first step in scoping, written as checkable facts, not the last. It does not say the CAF-aligned DSPT is wrong and it does not replace the scoping template or a DPIA. Quotes checked against the linked pages on 27 August 2026. The A1 and A2 pages showed a last-edit date of 26 August 2026, so re-check before publishing. Nothing on this page is recorded or sent anywhere.