Skip to content

Executive summary

What legislation, regulations, standards, confidentiality rules, guidance and other controls govern information sharing into and out of UK primary healthcare (PHC)?

The answer in 60 seconds

No single instrument governs every PHC information flow. The answer is the cumulative set of instruments that applies to one defined purpose, sender, recipient, person or population, dataset and workflow.

Begin with the UK-wide data-protection baseline. Add the nation-specific health-service legislation and regulations, a separate confidentiality route, every applicable information standard, and the guidance, contracts, patient choices, safety, security and operational controls that govern implementation. Passing one layer does not cure failure in another.

Direction changes the operational evidence, not the basic governing stack. Information leaving PHC needs a justified disclosure, an identified recipient and controlled onward use. Information entering PHC needs justified collection and use plus reliable matching, provenance, preserved meaning, ownership, acknowledgement, correction and managed failure states.

UK question; principally England coverage

UK GDPR and the Data Protection Act provide a UK-wide baseline. Health-service legislation, confidentiality routes, standards, policy and delivery arrangements differ among England, Scotland, Wales and Northern Ireland. This wiki's detailed legislation, regulation, standards and operational mapping is currently principally for England, as at 29 July 2026. A flow in another UK nation needs a separate check against that nation's current health-service framework and guidance.

The governing-instrument map

The table names the principal instrument families and the England-focused baseline covered here. It is an orientation map, not a universal list or an applicability decision.

Instrument family Principal instruments and controls covered What the reader must establish
Data-protection law UK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025 Controller and processor roles; purpose; Article 6 basis; Article 9 condition; DPA condition where needed; necessity, minimisation, transparency, rights, security and accountability.
Legislation, powers and duties NHS Act 2006 section 251; Health and Social Care Act 2012 sections 250–251 and 251B; and workflow-specific legislation Whether the exact organisation, purpose, recipient, information, duty, power, exception, safeguard and territorial scope apply. A power or duty does not replace data protection or confidentiality.
Regulations Health Service (Control of Patient Information) Regulations 2002; Health and Social Care Information Standards (Procedure) Regulations 2025; contractual and workflow-specific regulations The regulation, paragraph, organisations, purpose, conditions, approval, duration and exceptions that govern the actual flow.
Confidentiality rules Common law confidentiality, direct-care and beyond-care routes; Patient objections, Type 1 opt-outs, national data opt-out and section 251 routes Whether the information is confidential, what confidentiality route permits or requires its use or disclosure, what expectations and objections apply, and whether an opt-out must be honoured.
Information and interoperability standards NHS standards and interoperability, including applicable Information Standards Notices, DAPB/DCB standards, terminology, identifiers, messaging, content and clinical-safety requirements Exact title, reference, authority, version, status, scope, applicable organisations and systems, use case, conformance dates and dependencies. A directory listing alone is insufficient.
Guidance and other controls Caldicott Principles, ICO Data Sharing Code and governance controls, Clinical safety and security controls, contracts, professional duties, DSPT, DPIAs, agreements, identity, access, audit, correction, incident and continuity controls Which controls are legal or contractual requirements, which are authoritative guidance, which are local policy, and how each will be evidenced without treating guidance as legal permission.

Choose the direction and workflow

The directional tables are the comparison layer. Each row identifies a workflow family and separates its candidate legislation, regulations, standards, and confidentiality, guidance and other controls. A listed instrument is a prompt to test applicability, not proof that it governs every instance of that workflow.

Direction Governing question Continue
Information leaving PHC Which instruments authorise, require, constrain and standardise disclosure to this recipient, and how is onward use controlled? 1. Information sharing out of primary healthcare
Information entering PHC Which instruments authorise, require, constrain and standardise receipt and use by PHC, and how will the information be matched, understood and acted on safely? 2. Information sharing into primary healthcare

Open the named workflow activity from the selected table. Its detail page defines the operational boundary, directional hand-offs, candidate instruments, failure controls, evidence and open checks. If no row clearly fits, use the Workflow reference.

Candidate does not mean applicable

For every candidate, establish its authority type, jurisdiction, organisations, purpose, people, information, systems, version, status, dates, conditions and accountable owner. Then apply the Decision guide. A standard, contract, product or programme cannot supply a missing purpose, lawful basis or confidentiality route.

Minimum, conditional and maximum

The minimum-to-maximum model is the supporting decision model after the governing instruments have been identified. There is no universal minimum or maximum PHC dataset.

1. Minimum: required floor

Use the least information necessary for the defined purpose and satisfy every applicable legal, confidentiality, patient-choice, transparency, contractual, standards, safety, security and operational requirement. Passing one layer does not cure failure in another.

2. Conditional: purpose-specific envelope

Apply each duty, power, regulation, approval, contract and information standard only within its stated organisations, purpose, content, conditions, version and dates. Individual care and beyond-care uses require distinct routes; anonymous information should be used for beyond-care purposes where practicable.

3. Maximum: safe ceiling

Make no more than the necessary, proportionate and purpose-relevant information available to authorised roles. Preserve meaning and provenance, and provide reliable identity, access, audit, correction, safety, security and lifecycle controls. Technical access must never become default whole-record entitlement.

The maintained reasoning is in the Minimum-to-maximum requirement model.

The board approval test

Require one completed decision record for each materially different purpose:

  1. What exact information flow and practical benefit are being approved?
  2. Which legislation, regulations, confidentiality route, standards, guidance, contracts and local controls actually apply—and which candidates were ruled out?
  3. What is the minimum necessary information, and what role-specific maximum view is justified?
  4. Who controls and processes the information, and who owns matching, review, action, correction, incidents, fallback, service exit and revalidation?
  5. Where is the current primary-source, scope, version, status, approval and conformance evidence?

Stop or redesign

Do not proceed where the purpose or recipient is vague, a governing layer is missing, an instrument's scope cannot be evidenced, whole-record access is the default, direct-care information is silently reused beyond care, or a future proposal is treated as current authority.

Continue with one flow

  1. Choose Information sharing out of primary healthcare or Information sharing into primary healthcare.
  2. Open the relevant workflow row and its detail page.
  3. Apply the Decision guide.
  4. Use Record a sharing decision for the auditable outcome.

Use the Evidence matrix and Primary source register for proof.