Skip to main content

Help us improve the Digital Marketplace - send your feedback

ATLANTIC DATA LTD

Atlantic Data - NHS DBS Service

NHS DBS Service is a secure, cloud-hosted SaaS enabling NHS organisations to manage DBS checks at scale. It supports Trusts and related organisations managing checks for employees/volunteers/contractors. The service connects directly to the DBS e-Bulk system and provides role-based access controls, audit logging, management reporting, fully managed by Atlantic Data.

Features

  • DBS e-Bulk approved online criminal record checking service
  • Secure role-based access with multi-factor authentication
  • Approved digital identity checking aligned with UK Trust Framework
  • Configurable workflows supporting complex organisational structures
  • Advanced management reporting and audit capabilities
  • Administrator user management with granular permission control
  • Flexible subscription-based pricing and online billing
  • Automated validation ensuring data accuracy and completeness
  • Fully hosted cloud service requiring no local installation
  • Multi-Factor authentication for additional security

Benefits

  • Supports high-volume DBS processing within dedicated environments
  • Improves governance through configurable controls and audit trails
  • Reduces manual effort via automated workflows and validation
  • Enables complex organisational structures and delegated administration
  • Supports re-checks based on organisation policies
  • Enhanced security for sensitive personal data
  • Consistent experience across large or distributed organisations
  • Integrates with HR and onboarding systems via APIs
  • Scales to meet organisational growth and demand

Pricing

  • Education pricing available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@atlanticdata.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

1 7 0 6 8 5 0 1 2 0 2 2 1 7 0

Contact

ATLANTIC DATA LTD Client Services team
Telephone: 0333 320 7300
Email: legal@atlanticdata.co.uk

About your service

Service categories

Applications

Customer relationship management

  • Digital commerce
Multi cloud support
No

Service scope

Software add-on or extension
Yes, but can also be used as a standalone service
What software services is the service an extension to
The service integrates with identity verification, recruitment, HR, and workforce management systems. It connects to DBS e-Bulk and extends buyer systems using standard APIs without replacing core HR or case management platforms.
Cloud deployment model
Private cloud
Service constraints
None
System requirements
  • Modern web browser supporting HTML5 and TLS encryption
  • Reliable internet connection
  • Desktop, tablet, or mobile device
  • Windows, macOS, iOS, or Android operating systems
  • Secure email access for notifications and account management
  • No local software installation required

User support

Email or online ticketing support
Yes
Support response times
Support is provided during UK business hours, Monday to Friday. Initial response times are based on issue severity:
• Critical: same working day
• High: within 1 working day
• Medium: within 2 working days
• Low: within 3 working days
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
No
Support levels
Each Disclosures NHS customer is assigned a named account manager as the primary point of contact for service management and escalation. Support is provided through a dedicated helpdesk and client relationship management team, Teams provide technical and operational support and resolve most issues at first contact.
Issues requiring escalation are managed through a priority-based ticketing system and escalated to specialist technical teams where needed. Support services are included within annual account maintenance fees.
Support available to third parties
No

Onboarding and offboarding

Getting started
User onboarding is delivered through a structured process designed to support rapid adoption. The service is supported by online guidance, including a Quick Start Guide and video tutorials covering key functions. Inline help is available throughout the service to provide contextual guidance. Where required, additional remote or onsite training can be provided as an optional service.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Users can extract data using standard reports and APIs at the end of the contract. Where required, Atlantic Data can manage data extraction on the customer’s behalf in line with agreed requirements.
End-of-contract process
Off-boarding is managed through an agreed exit plan covering scope, actions, and timelines. This includes support for data export and secure removal of access in line with contractual and data protection requirements. Where requested, Atlantic Data can liaise with a replacement supplier. Any additional support beyond standard off-boarding is agreed in advance at an additional cost.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The service is delivered through a responsive web interface that adapts to the user’s device. Core functionality, data access, security controls, and user permissions are consistent across desktop and mobile use. On smaller screens, layouts and navigation are optimised for touch-based interaction. Some administrative and reporting functions are easier to use on desktop due to screen size. No separate mobile application is required.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
The service is accessed through a secure, web-based user interface via standard browsers. It provides role-based access to dashboards, reporting, and administrative functions, and adapts to desktop, tablet, and mobile devices. APIs are available to support integration with third-party systems where required.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
Accessibility testing has been undertaken with users of assistive technology as part of service development and improvement. A national disability charity supporting blind and partially sighted users has provided guidance to support WCAG 2.2 AA alignment. Testing has included JAWS screen readers and ZoomText magnification tools, with feedback used to improve interface design and usability.
API
Yes
What users can and can't do using the API
The service provides APIs to support secure integration with third-party systems. Authorised users can initiate DBS application invitations, submit and update applicant information, retrieve application status updates, and cancel applications where required. APIs use REST and SOAP standards and are protected by authentication and access controls.
API documentation
Yes
API documentation formats
PDF
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Disclosures NHS is implemented using a structured onboarding approach designed for NHS organisations. Atlantic Data works with NHS HR and workforce teams to configure the service to align with existing processes, organisational structures, and information governance requirements.
Onboarding typically includes service configuration, administrator training, and controlled rollout to support continuity of workforce operations.

Scaling

Independence of resources
The service uses logical isolation and automated resource management to ensure customer workloads are not affected by other users. Each customer operates within an isolated virtual environment, with resources dynamically allocated and monitored to maintain consistent performance.

Analytics

Service usage metrics
Yes
Metrics types
The service provides management information to monitor DBS activity, including application volumes, processing status, turnaround times, and completion outcomes. Metrics support operational oversight and compliance and are available through role-based dashboards.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Other security clearance
Government security clearance
Developed Vetting (DV)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
  • Other
Other data at rest protection approach
Data at rest is protected using encryption, logical access controls, and environment segregation. All data, including backups, is encrypted using strong cryptography (AES-256). Access is restricted using role-based access control and least-privilege principles. Data retention and secure deletion processes are applied throughout the data lifecycle.
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Data can be exported using secure APIs and standard export mechanisms. Configurable export formats and agreed data fields are supported where required. Atlantic Data can manage exports on the customer’s behalf if needed. All exports are performed securely and in line with data protection obligations.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • XML
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • Other
Other protection between networks
Data in transit is protected using layered security controls including firewalls, network segmentation, and strict access rules. API access is restricted using authentication, security keys, and IP controls. Role-based access control ensures only authorised users and systems can exchange data, providing defence in depth.
Data protection within supplier network
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
  • Other
Other protection within supplier network
Data within the supplier network is protected using encrypted communications (TLS 1.2+ and IPsec), network segmentation, and role-based access control. Internal systems are isolated into secure network zones, with administrative access restricted to authorised users. Security events are continuously monitored using centralised logging and alerting.

Availability and resilience

Guaranteed availability
The service is available 24 hours a day, 7 days a week, excluding planned maintenance. It is designed to deliver availability in excess of 99.9%, based on historic operational performance. Availability is continuously monitored to ensure consistent access.
Approach to resilience
The service is hosted in UK-based datacentres with a primary production environment and a mirrored disaster recovery environment. Customer services operate within isolated virtual environments. Resilience is supported by automated resource management, continuous monitoring, and tested disaster recovery and business continuity plans under an ISO/IEC 27001-certified ISMS.
Outage reporting
Service availability is monitored continuously using centralised logging and alerting. When outages or degradation occur, incidents are investigated, resolved, and reviewed. Affected customers are notified through system notifications, email alerts, or agreed communication channels.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Username or password
Access restrictions in management interfaces and support channels
Access to management interfaces and support channels is controlled using role-based access control and segregation of duties. Defined privilege levels ensure administrative and support functions are accessible only to authorised personnel.
Management access is granted through a formal authorisation process and restricted to registered accounts with appropriate privileges. Multi-factor authentication is supported for privileged access.
Support access is provided through authorised support accounts and subject to the same access control, authentication, and audit requirements. All access is logged and monitored to support audit, security oversight, and incident investigation.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Username or password

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Information security is managed through an ISO/IEC 27001-certified Information Security Management System (ISMS). Policies and processes cover access control, risk management, incident response, change management, secure software development, encryption, logging and monitoring, vulnerability management, business continuity, physical security, staff security, supplier security, and data protection. Compliance is assured through regular internal and external audits and continuous improvement.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Changes are managed through a formal change management process within the ISO/IEC 27001-certified ISMS. All changes are risk assessed, approved, tested in segregated environments, and deployed using controlled release processes. Changes are fully auditable and designed to protect security, availability, and service continuity.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Atlantic Data operates a formal vulnerability management process within its ISO/IEC 27001–certified Information Security Management System. Vulnerabilities are identified through continuous monitoring, system reviews, independent health checks, penetration testing, and threat intelligence sources including CISA advisories.
Findings are risk-assessed and prioritised based on potential impact to confidentiality, integrity, and availability. Critical or zero-day vulnerabilities trigger an emergency remediation process, including accelerated patching or mitigations outside standard change windows.
Governance is provided through the Internal Security Forum, which oversees remediation and emerging risks. Technical controls include IPS-protected network perimeters, hardened hosts, application firewalls, centralised logging, and regular patching with follow-up verification.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Atlantic Data operates protective monitoring through centralised log analysis and automated service-level monitoring.

Security and operational logs from all services are collected in a centralised log management platform, reviewed daily by authorised administrators, and retained to provide a complete audit trail. The platform generates automated alerts for suspicious activity, including authentication failures and potential security incidents.

Services are continuously monitored using threshold-based alerts for availability, performance, and abnormal behaviour, which trigger automatically when limits are exceeded.

All alerts are investigated promptly in accordance with incident management procedures. Where appropriate, root cause analysis is conducted and corrective actions are implemented.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Atlantic Data manages incidents through a formal, ISO/IEC 27001-certified incident management process. Pre-defined procedures are in place for common security and service events, ensuring consistent identification, classification, escalation, and resolution by the incident response team.
Users can report incidents via designated support channels, which are monitored continuously. Incident updates and post-incident reports, including root cause analysis and corrective actions for significant incidents, are provided to customers in line with agreed communication and reporting arrangements.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
Yes
Connected networks
Other
Other public sector networks
The Disclosures and Barring Service's e-Bulk network

Pricing

Discount for educational organisations
Yes
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
1%
Between £250,000 and £500,000
2%
Between £500,001 and £1,000,000
3%
Between £1,000,001 and £2,500,000
4%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
6%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Bureau Veritas
ISO/IEC 27001 accreditation date
Monday 31 March 2025
What the ISO/IEC 27001 doesn’t cover
Our ISMS certification covers all our services
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Cyber essentials plus
No
Cyber Essentials Alternative
In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
Other security certifications
Yes
Any other security certifications
  • IDSP Certification under UKDIATF
  • HSP Certification under UKDIATF

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at legal@atlanticdata.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.