Sharing with other providers
Independent, voluntary, charitable, community, social-care and other providers can be legitimate recipients where they are actually delivering the defined service and every legal layer is satisfied. Their non-NHS ownership does not automatically prohibit sharing; a contract or NHS badge does not automatically authorise it.
Required checks
- Confirm the service, population, care relationship and recipient staff roles.
- Identify controller, joint-controller and processor responsibilities from facts, not contract labels.
- Confirm each controller’s function, Article 6/9 route and confidentiality authority.
- Limit access and onward use to the commissioned or otherwise authorised purpose.
- Apply equivalent identity, access, audit, incident, retention, deletion and subcontractor controls.
- Check DSPT and the scope of each ISN, supplier obligation and NHS Standard Contract term.
- Ensure people are not surprised by the organisation or purpose receiving their information.
- Plan service exit: access revocation, record return, continuity, deletion and audit preservation.
If data is reused for planning, research, marketing, product improvement or workforce management, run a separate beyond-care sharing route.
Use the sharing route decision workflow, minimum-to-maximum requirement model, and NHS standards applicability register.
For GP Connect, NHS England’s current materials distinguish NHS direct-care providers from private healthcare providers: the latter route requires explicit patient permission as well as actual direct care. That product/contract rule does not replace the controller’s wider legal analysis. SRC-038 SRC-039