Skip to content

Requirement envelope

This is the reference model applied after a reader has selected a direction and workflow and identified candidate instruments. Follow the operational sequence:

  1. Select Information sharing out of primary healthcare or Information sharing into primary healthcare.
  2. Open the linked workflow detail and preserve its direction, workflow family and exact message leg.
  3. Use the Decision guide to test whether each candidate legislation, regulation, standard, confidentiality rule, guidance item and other control applies.
  4. Use the Minimum-to-maximum requirement model to assess the cumulative envelope.
  5. Complete Record a sharing decision with an explicit approve, approve-with-conditions or stop/redesign outcome.

The requirement model separates three questions that are often collapsed:

  1. What must be true before any sharing? The mandatory legal and governance floor.
  2. What may or must be shared for this precise flow? The conditional envelope created by purpose, authority, role, data, objection and applicable standards.
  3. What does a mature implementation add? Stronger interoperability, safety, security, audit and operational assurance without widening access beyond purpose.

Within the Decision guide, choose the Direct-care sharing route or Beyond-care sharing route. Consult the NHS standards applicability register for a candidate standard, but retain its apply/not-apply rationale, current status, scope, notice and evidence in the decision record.

Non-negotiable distinctions

  • UK GDPR consent and common-law confidentiality consent are different legal concepts.
  • A statutory power or duty does not replace the Article 6/Article 9 analysis, and those data-protection conditions do not replace confidentiality authority.
  • A standard can require format, terminology, safety or assurance; it does not by itself make a disclosure lawful.
  • A directional or workflow table identifies candidate instruments; it does not determine that an instrument applies.
  • Pseudonymisation reduces risk but normally does not make data anonymous.
  • “Need to share” for care does not mean unrestricted access or an entire-record default.

Evidence: CLM-001, CLM-002, CLM-003, CLM-009, CLM-010, CLM-014.