Information sharing into and out of UK primary healthcare
This wiki answers one question:
What legislation, regulations, standards, confidentiality rules, guidance and other controls govern information sharing into and out of UK primary healthcare (PHC)?
The short answer
No single Act, regulation, NHS standard or policy governs every PHC information flow. The answer is a cumulative, flow-specific set of instruments:
- UK-wide Data protection law, including the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018 and amendments made by the Data (Use and Access) Act 2025;
- the Legislation, powers and duties that authorise, require or constrain the organisations and purpose;
- any purpose- or service-specific regulations, including the Section 251 and COPI routes where their exact conditions are met;
- Common law confidentiality and Caldicott governance, considered separately from data protection;
- NHS information standards whose notice, scope, status, version and conformance dates apply to the organisations, systems and use case; and
- applicable guidance, patient choices, contracts, professional duties, clinical-safety, security, assurance and local operational controls.
These layers are cumulative. A legal power does not remove the data-protection or confidentiality analysis; a standard, product or contract does not create permission to disclose; and a directory listing does not prove that a standard is mandatory.
UK question; principally England coverage
UK GDPR and the Data Protection Act provide a UK-wide baseline. Health-service legislation, confidentiality routes, standards, policy and delivery arrangements also differ among England, Scotland, Wales and Northern Ireland. The detailed operational coverage in this wiki is currently principally for England. Treat it as a structured starting point—not a complete nation-specific answer outside England.
Main reading route
| Step | Open | What to do |
|---|---|---|
| 1 | Executive summary | Read the direct answer and distinguish the six governing-instrument families. |
| 2 | Information sharing out of primary healthcare or Information sharing into primary healthcare | Choose the direction, then find the relevant workflow activity and its candidate legislation, regulations, standards and other controls. |
| 3 | Open the workflow activity linked from the directional table, or browse the Workflow reference | Check its operational boundary, hand-offs, candidate instruments, failure controls and unresolved applicability questions. |
| 4 | Decision guide | Test which candidate instruments actually apply to one precisely defined flow, then record an approve, condition, stop or redesign decision. |
Use the NHS standards applicability register to check the authority, status and scope of a candidate standard. Use the Evidence matrix and Primary source register to trace maintained claims. Keep Current requirements separate from future policy, including the 10 Year Health Plan and digital-first implications.
The supporting decision model
Only after identifying the candidate instruments should you decide the permitted information envelope. There is no universal minimum or maximum PHC dataset.
- Minimum is the least information necessary for the purpose, together with every applicable legal, confidentiality, standards, safety, security and operational control.
- Maximum is the widest justified, role-authorised and safely controlled availability—not the whole record or everything technically accessible.
The maintained method is in the Minimum-to-maximum requirement model.
Safety
This is evidence-linked decision support, not legal advice. A live flow requires current primary-source checks, accountable controller decisions and proportionate information-governance, Caldicott, clinical-safety, security, contractual and specialist review.