Sharing route decision workflow
Create one completed record per materially distinct purpose. A platform with ten use cases may need ten decisions.
Decision record
| Field | Required entry |
|---|---|
| Proposition | One sentence: who shares what with whom, for which person or population, for what purpose and benefit. |
| Purpose class | Individual care, or a named beyond-care purpose such as audit, commissioning, research, planning or service management. |
| Identifiability | Anonymous to each recipient / identifiable / pseudonymised; explain reasonably likely re-identification. |
| Article 9 status | Whether the personal data are special-category data and which types. |
| Confidentiality status | Whether the information is confidential and/or CPI; record third-party confidence separately. |
| Parties and roles | Controller, joint controller, processor; statutory functions and contracting chain. |
| Authority | Statutory power/duty; Article 6; Article 9; DPA Schedule 1; confidentiality route; opt-out result. |
| Necessity | Item-level justification and less-intrusive alternatives. |
| Standards | Applicable ISNs, technical specifications, versions, conformance dates and recorded non-applicability reasons. |
| Controls | Access, transfer, audit, retention, deletion, accuracy, incident, onward-sharing and supplier controls. |
| Assurance | DPIA outcome, DPO/Caldicott/clinical-safety/security approvals, tests and residual risks. |
| Transparency and rights | Privacy information, objections, Type 1 result, national data opt-out result, SAR/correction/complaint handling. |
| Review | Owner, approval date, expiry/review date and change triggers. |
Stop conditions
Do not proceed if:
- the purpose is vague, bundled, speculative, or cannot support data-item necessity;
- controller roles or a controller’s authority are unresolved;
- Article 6, Article 9, or confidentiality authority is missing;
- a direct-care objection, Type 1 opt-out or applicable national data opt-out cannot be honoured and no lawful, documented exception applies;
- a high-risk flow starts before its DPIA and mitigations are complete;
- an applicable mandated standard, clinical-safety requirement or security control is unmet;
- the recipient’s use, onward disclosure, retention or deletion cannot be controlled;
- a future Bill, draft standard or directory summary is being treated as current authority.
Approval route
Routine low-risk implementations still need accountable controller approval. Escalate novel, large-scale, sensitive, cross-sector, automated, contested, or high-risk flows to the DPO, Caldicott Guardian, clinical-safety and cyber leads. Seek Confidentiality Advisory Group or other specialist approval where the chosen route requires it.
This workflow implements the minimum-to-maximum requirement model, branches to the direct-care sharing route and beyond-care sharing route, and records the NHS standards applicability register result.
The approval record must also link the applicable clinical safety and security controls.
Where the proposition relies on an NHS App, Single Patient Record, neighbourhood, digital-by-default or other programme commitment, apply the status and delivery gates in 10 Year Health Plan and digital-first implications before treating it as available or required.
For a named App tool, HealthStore product, wearable, AI function, proxy feature or proactive-care platform, also locate it in the Chapter 3 analogue-to-digital commitment map and create a separate decision record for every materially different purpose.