Skip to content

Decision guide

Use this page before choosing an API, shared-care platform, contract, or dataset.

Stop/go sequence

flowchart TD
  A["Define purpose, benefit, parties and data"] --> B{"Anonymous to the recipient?"}
  B -- "Yes, robustly anonymous" --> C["Check residual confidentiality, contract and re-identification risk"]
  B -- "No or uncertain" --> D["Identify controllers/processors and legal authority"]
  D --> E["Select Article 6 basis + Article 9 condition"]
  E --> F{"Individual direct care?"}
  F -- "Yes" --> G["Test confidentiality implied-consent conditions, objection and section 251B duty"]
  F -- "No" --> H["Find explicit confidentiality consent, legal requirement, section 251/COPI or public-interest route"]
  H --> I["Apply national data opt-out test"]
  G --> J["Minimise, secure, explain, audit and retain appropriately"]
  I --> J
  C --> J
  J --> K["Apply relevant ISNs, technical standards and clinical-safety controls"]
  K --> L{"Every applicable layer passes?"}
  L -- "No" --> M["Do not proceed; redesign or obtain missing authority"]
  L -- "Yes" --> N["Approve, implement, monitor and review"]

The governing rule is cumulative: one lawful basis does not cure a failure in another layer. A sharing agreement documents governance but does not create legal authority. DSPT completion demonstrates assurance but does not prove a particular flow lawful.

Five decisive questions

  1. What exact purpose and benefit? Record the care activity or beyond-care purpose, parties, frequency, geography, data items, likely harms, and consequence of not sharing.
  2. What information state? Distinguish anonymous data, pseudonymised personal data, special-category health data, and confidential patient information.
  3. Who decides and who acts? Identify each controller, joint controller and processor. Do not infer the role from a supplier or commissioner label.
  4. Which route passes every layer? Record statutory power or duty, Article 6, Article 9, any DPA Schedule 1 condition, confidentiality route, and opt-out position.
  5. Which controls and standards actually apply? Check each Information Standards Notice for scope and dates; then add appropriate interoperability, clinical-safety, security, access, audit, retention, and incident controls.

Use the minimum-to-maximum requirement model for the answer shape, the sharing route decision workflow for an auditable record, the direct-care sharing route or beyond-care sharing route, and the NHS standards applicability register.

Technical implementations also need the clinical safety and security controls appropriate to manufacturer, deployer and operating roles.

Evidence: SRC-001, SRC-005, SRC-006, SRC-007, SRC-008, SRC-009, SRC-010, SRC-012.