Skip to content

Record a sharing decision

Create one completed record per materially distinct purpose. A platform with ten use cases may need ten decisions.

Use the Executive summary as the board cover note. The Information sharing out of primary healthcare and Information sharing into primary healthcare summaries identify the workflow and candidate instruments. Apply the Decision guide to test those candidates before completing this record.

Decision record

Field Required entry
Jurisdiction England, Scotland, Wales, Northern Ireland or a named cross-border combination; identify the organisations and processing activities that create each connection.
Direction Into PHC, out of PHC, or separately assessed legs in both directions.
Workflow and source row Linked workflow-family page, selected directional-table row and exact operational use case.
Message leg or event Request, response, notification, retrieval, disclosure, acknowledgement, correction or other discrete transfer; create separate records where purpose, parties, content or authority differ.
Proposition One sentence: who shares what with whom, for which person or population, for what purpose and benefit.
Purpose class Individual care, or a named beyond-care purpose such as audit, commissioning, research, planning or service management.
Identifiability Anonymous to each recipient / identifiable / pseudonymised; explain reasonably likely re-identification.
Article 9 status Whether the personal data are special-category data and which types.
Confidentiality status Whether the information is confidential and/or CPI; record third-party confidence separately.
Parties and roles Controller, joint controller, processor; statutory functions and contracting chain.
Authority Statutory power/duty; Article 6; Article 9; DPA Schedule 1; confidentiality route; opt-out result.
Necessity Item-level justification and less-intrusive alternatives.
Instrument schedule One row per candidate or subsequently discovered instrument using the schedule below; retain both apply and does-not-apply findings.
Controls Access, transfer, audit, retention, deletion, accuracy, incident, onward-sharing and supplier controls.
Assurance DPIA outcome, DPO/Caldicott/clinical-safety/security approvals, tests and residual risks.
Transparency and rights Privacy information, objections, Type 1 result, national data opt-out result, SAR/correction/complaint handling.
Outcome Approve, Approve with conditions, or Stop / redesign; give reasons and record any residual risks.
Conditions For conditional approval, record every condition, owner, due date, evidence required and pre-processing or pre-release completion gate.
Ownership and review Accountable decision owner, implementation owner, instrument/standard owners, monitoring owner, approval date, expiry/review date and change triggers.

Instrument applicability schedule

Do not delete a candidate because it does not apply. A recorded non-applicability decision prevents the same instrument being silently assumed later.

Field Required entry for each instrument
Category and instrument Legislation; regulation/statutory duty; standard; confidentiality rule; guidance; contract; local control; or future proposal, plus formal title or maintained abbreviation.
Candidate origin Directional-table row, workflow detail or review discovery.
Jurisdiction and current status Nation/addressees and in-force/current, conditionally applicable, guidance, contractual/local, draft/future, superseded or unresolved status, with effective date.
Scope test Relevant actor, purpose, direction, message leg, data, recipient, trigger, version, conformance date and applicable organisations.
Applicability decision Applies, does not apply, or unresolved, with a concise reason.
Effect Duty, permission, prohibition, confidentiality route, required content/format, conformance control, assurance, guidance or no current effect.
Evidence Exact registered primary source, Evidence-matrix claim and any Validation-queue item; for an information standard, link its ISN and specification.
Owner and recheck Person accountable for the interpretation and the event/date that requires it to be rechecked.

Stop conditions

Do not proceed if:

  • the purpose is vague, bundled, speculative, or cannot support data-item necessity;
  • jurisdiction, direction, workflow or message leg is not defined;
  • controller roles or a controller’s authority are unresolved;
  • Article 6, Article 9, or confidentiality authority is missing;
  • a direct-care objection, Type 1 opt-out or applicable national data opt-out cannot be honoured and no lawful, documented exception applies;
  • a high-risk flow starts before its DPIA and mitigations are complete;
  • a candidate instrument remains unresolved at the processing or release gate;
  • an applicable mandated standard, clinical-safety requirement or security control is unmet;
  • the recipient’s use, onward disclosure, retention or deletion cannot be controlled;
  • a future Bill, draft standard or directory summary is being treated as current authority.

Approval route

Select exactly one recorded outcome: Approve, Approve with conditions, or Stop / redesign. Routine low-risk implementations still need accountable controller approval. Conditional approval is valid only when the remaining conditions are remediable, have named owners and due dates, and are completed before their recorded processing or release gate. Escalate novel, large-scale, sensitive, cross-sector, automated, contested, or high-risk flows to the DPO, Caldicott Guardian, clinical-safety and cyber leads. Seek Confidentiality Advisory Group or other specialist approval where the chosen route requires it.

This workflow implements the Minimum-to-maximum requirement model, branches to the Direct-care sharing route and Beyond-care sharing route, and records the NHS standards applicability register result.

The approval record must also link the applicable Clinical safety and security controls.

Where the proposition relies on an NHS App, Single Patient Record, neighbourhood, digital-by-default or other programme commitment, apply the status and delivery gates in 10 Year Health Plan and digital-first implications before treating it as available or required.

For a named App tool, HealthStore product, wearable, AI function, proxy feature or proactive-care platform, also locate it in the Chapter 3 analogue-to-digital commitment map and create a separate decision record for every materially different purpose.

Evidence boundary: listing an instrument does not establish applicability or authority. See CLM-009, CLM-010, CLM-014, CLM-020, VAL-003 and VAL-004.