Skip to content

NHS data sharing from primary care

This wiki turns the overlapping law, confidentiality rules, NHS duties, information standards, technical specifications, and assurance controls into a flow-specific decision.

The short answer

There is no single universal “minimum dataset” or “maximum dataset” for every primary-care disclosure.

1. Mandatory floor

Share only when every applicable legal layer has passed: a defined purpose and authority, UK GDPR Articles 6 and 9 where personal health data is involved, confidentiality authority, necessity and minimisation, transparency, security, rights and objections, and every applicable statutory information standard.

2. Conditional sharing envelope

For direct individual care, relevant information may—and sometimes must—be shared on a need-to-know basis when it is likely to facilitate care and is in the person’s best interests, subject to objections and other legal constraints. Beyond individual care, confidential patient information normally needs a different route such as explicit confidentiality consent, a statutory requirement, or section 251/COPI support.

3. Higher-assurance interoperable ceiling

The broadest defensible implementation is purpose-specific and role-filtered. It combines applicable standards such as NHS Number, SNOMED CT, dm+d, GP Connect/FHIR, clinical-safety controls, DSPT assurance, least-privilege access, audit, and lifecycle governance. “Maximum” means maximum useful conformance and safe availability—not maximum data volume.

Start with the decision guide, then use the minimum-to-maximum requirement model and flow decision workflow. The NHS standards applicability register distinguishes statutory standards, active specifications, guidance, and future change.

For current digital policy, use the 10 Year Health Plan and digital-first implications analysis. It distinguishes today’s contractual and standards floor from NHS App, Single Patient Record and wider transformation ambitions.

Scope

The primary scope is England because NHS England standards, section 251B, Caldicott governance, and the national data opt-out have England-specific application. UK-wide data-protection law is included. Scotland, Wales, and Northern Ireland require separate sector-law and policy validation.

The audiences and destinations include:

  • GP practices and primary-care networks;
  • integrated care boards and shared-care-record programmes;
  • NHS trusts, community, mental-health, ambulance, pharmacy, dental and urgent-care services;
  • commissioned independent, voluntary, social-care and other providers;
  • research, audit, planning, commissioning and population-health teams.

Safety boundary

This is evidence-linked decision support, not legal advice. A real flow needs its own facts, current source checks, controller decisions, DPO and Caldicott input, clinical-safety and security assessment, contracts, and—where applicable—specialist approvals.