Skip to content

Confidentiality and Caldicott

Confidentiality and data protection are separate. A flow involving personal health data normally needs both a UK GDPR/DPA route and authority to disclose information given in confidence.

Individual care

NHS England guidance supports implied consent under the common-law duty of confidentiality where:

  • sharing is for the person’s individual care;
  • the person has a reasonable expectation that relevant information will be shared;
  • information is limited to those who need it;
  • meaningful information about sharing is available; and
  • the person has not objected.

This is not “GDPR consent.” Public healthcare controllers often rely on public task or legal obligation under Article 6 and health/social-care provision under Article 9, but each controller must choose and document its actual bases. SRC-007

Beyond individual care

Implied confidentiality consent for care does not normally carry into research, planning, commissioning, audit or service management. Use anonymous information where practicable. CPI otherwise needs a distinct route such as explicit confidentiality consent, a legal requirement, section 251/COPI support, or an exceptional public-interest justification.

Eight Caldicott Principles

The principles require justified purpose, necessity, minimum information, need-to-know access, accountable staff, compliance with law, confidence to share for individual care, and no surprises. Principle 7 encourages necessary care sharing; it does not cancel the other principles. SRC-010

For a real flow, the Caldicott Guardian should help resolve difficult purpose, confidence, objection and public-interest questions. The controller remains accountable.