Minimum and maximum requirements
Minimum: the mandatory floor
A proposed flow does not proceed until its owners can evidence all applicable items.
| Layer | Status / basis | Minimum evidence |
|---|---|---|
| Purpose and necessity | Legal minimum | A specific purpose, expected benefit, required data items, recipients, frequency, consequence of non-sharing, and less-intrusive alternatives. |
| Authority and roles | Legal / role-conditional | Each controller’s statutory function, power or duty; controller/joint-controller/processor roles; Article 26/28 arrangements where those roles apply. |
| Data protection | Legal when personal data is involved | Article 6 lawful basis; Article 9 condition for health data; any required DPA Schedule 1 condition/policy document; Article 5 compliance; DPIA where likely high risk. |
| Confidentiality | Legal when information is confidential | Implied confidentiality consent conditions for appropriate individual care, or explicit consent / legal requirement / section 251-COPI / defensible public-interest route beyond care. |
| Choice and objections | Legal/policy and flow-conditional | Direct-care objection considered; Type 1 opt-out checked for identifiable GP data leaving the practice beyond care; national data opt-out applied where in scope for CPI; rights and complaint route. |
| Transparency | Legal minimum | Clear, accessible privacy information and no-surprises communication appropriate to the people and purpose. |
| Security and lifecycle | Legal outcomes with risk-based controls | Least privilege, identity and access control, secure transfer, audit, accuracy, retention/deletion, incident response and supplier controls. |
| Sector requirements | Conditional mandate | Every applicable current ISN and conformance date; DSPT; clinical-safety standard according to manufacturer/deployer role; GP contractual requirements where applicable. |
| Decision record | Accountability plus assurance/local gate | Named accountable owners, required approvals, residual risks, implementation conditions, monitoring and re-review triggers. Additional specialist approvals apply only where the route or risk requires them. |
The floor is cumulative. If an applicable layer fails, another layer cannot compensate.
Conditional envelope: what may or must be shared
The lawful envelope is the intersection of:
purpose ∩ legal authority ∩ confidentiality route ∩ role/need-to-know
∩ patient choice ∩ applicable standards ∩ safety/security controls
For individual care, section 251B can create a qualified duty to disclose relevant information likely to facilitate care when disclosure is in the person’s best interests. NHS England guidance supports appropriate need-to-know sharing under implied confidentiality consent unless the person objects. Neither proposition permits indiscriminate access. SRC-006 SRC-007
For purposes beyond individual care, the envelope is normally narrower for identifiable information. Anonymous information should be used where practicable. CPI generally needs explicit confidentiality consent, a legal requirement, section 251/COPI support, or a carefully documented public-interest route. A Type 1 opt-out can prevent identifiable GP record data leaving the practice/system, and the national data opt-out may apply to later use or disclosure. SRC-008 SRC-009 SRC-033
Maximum: the higher-assurance ceiling
There is no lawful “share everything” ceiling. The maximal defensible pattern is:
- the widest purpose-relevant information set, not the largest available record;
- filtered by professional role, care relationship, context and current need;
- structured and coded to applicable standards so meaning travels safely;
- exposed through supported APIs or shared-care views with strong identity, authorisation, audit and break-glass controls;
- assessed across source, transfer, receiving workflow and onward use;
- capable of honouring corrections, restrictions, objections, retention and withdrawal;
- continuously monitored, with clinical-safety hazards and data-quality feedback closed.
The Core Information Standard describes a broad potential set for shared-care records, but local use cases, information governance and role-specific views still determine what should appear. GP Connect, FHIR, NHS Number, SNOMED CT and dm+d can strengthen the technical ceiling where applicable; they do not widen legal purpose. See shared-care and GP Connect, terminology and identifiers, and clinical safety and security.
Practical interpretation
“Minimal” is the least information and control set that lawfully achieves the defined purpose—not the least governance. “Maximal” is the greatest justified availability and interoperability inside the same purpose—not the most data.