Skip to content

Evidence method

Source hierarchy

  1. In-force legislation and official consolidated/amending text.
  2. Statutory codes, Information Standards Notices and regulator statements.
  3. Official NHS England, Department of Health and Social Care, National Data Guardian and Standards Directory publications.
  4. Current technical specifications and operational guidance from the responsible national body.
  5. Secondary commentary only as discovery input; it is not used to establish maintained claims here.

Claim classification

Each important statement is classified by:

  • legal layer: data protection, confidentiality, sector power/duty, information standard, contract/policy, ethics, safety or assurance;
  • purpose: individual care or beyond individual care;
  • data dimensions: record identifiability, special-category status, and confidentiality/CPI status independently because they overlap;
  • role: controller, joint controller, processor, manufacturer, deployer or recipient;
  • jurisdiction: UK, England or another territory requiring validation;
  • status: current, conditional, guidance under review, consultation, draft/future, or validation required.

Requirement vocabulary

  • Mandatory: primary authority or an applicable ISN uses a binding requirement for the organisation/use case and the date has arrived.
  • Conditional: mandatory only when the stated scope, role, data, purpose or technical use case applies.
  • Guidance / ceiling: approved or active good practice without a demonstrated universal mandate.
  • Future: Bill, consultation, draft, in-development or not-yet-commenced change.
  • Validate: the generic source cannot decide the local facts.

“MUST” inside a technical specification can be a conformance rule for adopters without making adoption itself statutory.

Maintenance protocol

For substantive edits:

  1. open the primary source and confirm title, publisher, status, date and scope;
  2. update the source register, then the evidence matrix;
  3. revise synthesis and add unresolved points to the validation queue;
  4. update the standards dataset if applicable;
  5. run npm run citations:update, npm run kb:update, and npm run verify;
  6. record the change in the research log.