Skip to content

Legislation and duties

Core cross-cutting framework

This table is deliberately non-exhaustive. A flow can also engage a use-case-specific gateway or duty—for example an NHS England information request/direction, safeguarding, notifiable-disease/public-health, court, regulator, medicines, human-rights or professional rule. The owner must search for the exact statutory gateway rather than infer authority from this summary.

Instrument Contribution Does not do
UK GDPR Principles, Article 6 lawful bases, Article 9 health-data conditions, transparency, rights, security, accountability and DPIA. Does not supply common-law confidentiality authority or a sector function by itself.
Data Protection Act 2018 UK conditions and safeguards, including Schedule 1 health/social-care, public-health, research/statistics and substantial-public-interest conditions. A Schedule 1 condition does not replace Article 6, necessity or confidentiality.
Data (Use and Access) Act 2025 Amends UK GDPR/DPA and strengthens the information-standards framework. All its data-protection provisions were in force by 19 June 2026. It does not replace UK GDPR/DPA or mean every non-data-protection provision commenced on the same date.
Health and Social Care (Safety and Quality) Act 2015, section 3 Inserts NHS Act section 251B, a qualified direct-care information-sharing duty. Does not authorise unrelated beyond-care reuse or override data protection/confidentiality.
NHS Act 2006, section 251 and COPI Regulations 2002 Enables defined support for processing CPI without consent for specified medical purposes, subject to approval and conditions. Not self-executing and not a blanket legal basis.
Equality Act 2010, sections 20, 29 and 149 Reasonable-adjustment/service duties and the public-sector equality duty according to actor and function. Does not itself prescribe a digital channel, product or health-data disclosure.
NHS Act 2006, sections 13G and 14Z35 Requires NHS England and ICBs respectively to have regard to reducing inequalities in access to and outcomes from health services. Does not create a general provider duty or data-sharing authority.
Public Sector Bodies (Websites and Mobile Applications) (No. 2) Accessibility Regulations 2018, as amended Accessibility requirements and statements for in-scope public-sector websites and mobile apps. Definitions, exclusions and disproportionate-burden rules matter; do not assume every independent contractor is in scope.
Health and Social Care Act 2012, Part 9 Chapter 1, sections 250–251, as amended Supports mandatory information standards for specified health/adult-social-care and relevant IT organisations when the published standard applies. DUAA Schedule 15 expressly extends the framework to IT/IT services and strengthens compliance; the amendments commenced on 5 February 2026. A directory listing or “Active” label alone does not prove a mandate; the published standard must identify who must comply or have regard.

Evidence: SRC-001, SRC-002, SRC-003, SRC-004, SRC-006, SRC-008, SRC-011, SRC-030, SRC-034, SRC-035, SRC-036, SRC-037, SRC-061, SRC-062, SRC-063.

Section 251B direct-care duty

The duty applies only where the statutory conditions and organisational scope are met. Owners must document:

  • why the information is likely to facilitate this person’s care;
  • why disclosure is in their best interests;
  • the relevant recipient and need;
  • any objection, anonymous-access context, statutory restriction or other exception;
  • how data-protection and confidentiality requirements are independently satisfied.

The existence of a duty increases the importance of confident, safe sharing; it does not justify an unfiltered technical access model.

Territorial boundary

UK GDPR and DPA 2018 are UK-wide. The NHS England information-standards regime, Caldicott materials and national data opt-out discussed here are principally England-facing. Cross-border flows need the applicable devolved legal and policy position.