Legislation and duties
Core cross-cutting framework
This table is deliberately non-exhaustive. A flow can also engage a use-case-specific gateway or duty—for example an NHS England information request/direction, safeguarding, notifiable-disease/public-health, court, regulator, medicines, human-rights or professional rule. The owner must search for the exact statutory gateway rather than infer authority from this summary.
| Instrument | Contribution | Does not do |
|---|---|---|
| UK GDPR | Principles, Article 6 lawful bases, Article 9 health-data conditions, transparency, rights, security, accountability and DPIA. | Does not supply common-law confidentiality authority or a sector function by itself. |
| Data Protection Act 2018 | UK conditions and safeguards, including Schedule 1 health/social-care, public-health, research/statistics and substantial-public-interest conditions. | A Schedule 1 condition does not replace Article 6, necessity or confidentiality. |
| Data (Use and Access) Act 2025 | Amends UK GDPR/DPA and strengthens the information-standards framework. All its data-protection provisions were in force by 19 June 2026. | It does not replace UK GDPR/DPA or mean every non-data-protection provision commenced on the same date. |
| Health and Social Care (Safety and Quality) Act 2015, section 3 | Inserts NHS Act section 251B, a qualified direct-care information-sharing duty. | Does not authorise unrelated beyond-care reuse or override data protection/confidentiality. |
| NHS Act 2006, section 251 and COPI Regulations 2002 | Enables defined support for processing CPI without consent for specified medical purposes, subject to approval and conditions. | Not self-executing and not a blanket legal basis. |
| Equality Act 2010, sections 20, 29 and 149 | Reasonable-adjustment/service duties and the public-sector equality duty according to actor and function. | Does not itself prescribe a digital channel, product or health-data disclosure. |
| NHS Act 2006, sections 13G and 14Z35 | Requires NHS England and ICBs respectively to have regard to reducing inequalities in access to and outcomes from health services. | Does not create a general provider duty or data-sharing authority. |
| Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, as amended | Accessibility requirements and statements for in-scope public-sector websites and mobile apps. | Definitions, exclusions and disproportionate-burden rules matter; do not assume every independent contractor is in scope. |
| Health and Social Care Act 2012, Part 9 Chapter 1, sections 250–251, as amended | Supports mandatory information standards for specified health/adult-social-care and relevant IT organisations when the published standard applies. DUAA Schedule 15 expressly extends the framework to IT/IT services and strengthens compliance; the amendments commenced on 5 February 2026. | A directory listing or “Active” label alone does not prove a mandate; the published standard must identify who must comply or have regard. |
Evidence: SRC-001, SRC-002, SRC-003, SRC-004, SRC-006, SRC-008, SRC-011, SRC-030, SRC-034, SRC-035, SRC-036, SRC-037, SRC-061, SRC-062, SRC-063.
Section 251B direct-care duty
The duty applies only where the statutory conditions and organisational scope are met. Owners must document:
- why the information is likely to facilitate this person’s care;
- why disclosure is in their best interests;
- the relevant recipient and need;
- any objection, anonymous-access context, statutory restriction or other exception;
- how data-protection and confidentiality requirements are independently satisfied.
The existence of a duty increases the importance of confident, safe sharing; it does not justify an unfiltered technical access model.
Territorial boundary
UK GDPR and DPA 2018 are UK-wide. The NHS England information-standards regime, Caldicott materials and national data opt-out discussed here are principally England-facing. Cross-border flows need the applicable devolved legal and policy position.