Skip to content

Sharing route decision workflow

Create one completed record per materially distinct purpose. A platform with ten use cases may need ten decisions.

Decision record

Field Required entry
Proposition One sentence: who shares what with whom, for which person or population, for what purpose and benefit.
Purpose class Individual care, or a named beyond-care purpose such as audit, commissioning, research, planning or service management.
Identifiability Anonymous to each recipient / identifiable / pseudonymised; explain reasonably likely re-identification.
Article 9 status Whether the personal data are special-category data and which types.
Confidentiality status Whether the information is confidential and/or CPI; record third-party confidence separately.
Parties and roles Controller, joint controller, processor; statutory functions and contracting chain.
Authority Statutory power/duty; Article 6; Article 9; DPA Schedule 1; confidentiality route; opt-out result.
Necessity Item-level justification and less-intrusive alternatives.
Standards Applicable ISNs, technical specifications, versions, conformance dates and recorded non-applicability reasons.
Controls Access, transfer, audit, retention, deletion, accuracy, incident, onward-sharing and supplier controls.
Assurance DPIA outcome, DPO/Caldicott/clinical-safety/security approvals, tests and residual risks.
Transparency and rights Privacy information, objections, Type 1 result, national data opt-out result, SAR/correction/complaint handling.
Review Owner, approval date, expiry/review date and change triggers.

Stop conditions

Do not proceed if:

  • the purpose is vague, bundled, speculative, or cannot support data-item necessity;
  • controller roles or a controller’s authority are unresolved;
  • Article 6, Article 9, or confidentiality authority is missing;
  • a direct-care objection, Type 1 opt-out or applicable national data opt-out cannot be honoured and no lawful, documented exception applies;
  • a high-risk flow starts before its DPIA and mitigations are complete;
  • an applicable mandated standard, clinical-safety requirement or security control is unmet;
  • the recipient’s use, onward disclosure, retention or deletion cannot be controlled;
  • a future Bill, draft standard or directory summary is being treated as current authority.

Approval route

Routine low-risk implementations still need accountable controller approval. Escalate novel, large-scale, sensitive, cross-sector, automated, contested, or high-risk flows to the DPO, Caldicott Guardian, clinical-safety and cyber leads. Seek Confidentiality Advisory Group or other specialist approval where the chosen route requires it.

This workflow implements the minimum-to-maximum requirement model, branches to the direct-care sharing route and beyond-care sharing route, and records the NHS standards applicability register result.

The approval record must also link the applicable clinical safety and security controls.

Where the proposition relies on an NHS App, Single Patient Record, neighbourhood, digital-by-default or other programme commitment, apply the status and delivery gates in 10 Year Health Plan and digital-first implications before treating it as available or required.

For a named App tool, HealthStore product, wearable, AI function, proxy feature or proactive-care platform, also locate it in the Chapter 3 analogue-to-digital commitment map and create a separate decision record for every materially different purpose.