Confidentiality and Caldicott
Confidentiality and data protection are separate. A flow involving personal health data normally needs both a UK GDPR/DPA route and authority to disclose information given in confidence.
Individual care
NHS England guidance supports implied consent under the common-law duty of confidentiality where:
- sharing is for the person’s individual care;
- the person has a reasonable expectation that relevant information will be shared;
- information is limited to those who need it;
- meaningful information about sharing is available; and
- the person has not objected.
This is not “GDPR consent.” Public healthcare controllers often rely on public task or legal obligation under Article 6 and health/social-care provision under Article 9, but each controller must choose and document its actual bases. SRC-007
Beyond individual care
Implied confidentiality consent for care does not normally carry into research, planning, commissioning, audit or service management. Use anonymous information where practicable. CPI otherwise needs a distinct route such as explicit confidentiality consent, a legal requirement, section 251/COPI support, or an exceptional public-interest justification.
Eight Caldicott Principles
The principles require justified purpose, necessity, minimum information, need-to-know access, accountable staff, compliance with law, confidence to share for individual care, and no surprises. Principle 7 encourages necessary care sharing; it does not cancel the other principles. SRC-010
For a real flow, the Caldicott Guardian should help resolve difficult purpose, confidence, objection and public-interest questions. The controller remains accountable.