Skip to content

1. Information sharing out of primary healthcare (PHC)

Core answer

Information leaving PHC is governed by a cumulative set of instruments, not one “data-sharing law” or standard. For an England PHC workflow, start with the UK-wide data-protection baseline, add the separate confidentiality route, then test any purpose-specific legislation or regulations, contract, information standard, guidance and local delivery controls shown in the selected row. Every applicable layer must pass.

Return to the Executive summary, or continue to Information sharing into primary healthcare.

Choose a workflow activity

Start with the work being done, then classify its purpose and recipients in the next section. Use the full record-service name rather than “SCR” alone, and name the exact order-communications system and workflow; similar shorthand can conceal different content, access and failure behaviour. A workflow or product name never supplies authority by itself.

Select a workflow activity in the first column to open its detailed reference page. The detail page keeps the selected workflow in view while explaining both directions, boundaries, instruments, controls and failure states.

Each row separates the decision route from candidate legislation, regulations, standards, and confidentiality, guidance and other controls. Read across one row, then check every linked instrument for the actual purpose, parties, scope, status, version and dates. Listing does not itself establish authority, applicability or conformance. For this matrix, Legislation groups Acts and the UK GDPR; Regulations means statutory instruments made under Acts. At standard and narrow widths, scroll horizontally to compare all columns. The linked canonical law, standards and evidence pages remain authoritative for status and scope.

Compact link labels use authoritative abbreviations, statutory citations or formal NHS identifiers—for example UK GDPR, DPA 2018, DUAA, SI 2025/950, DCB0129 and DAPB4101. Follow the link for the full title, amendment, version, status and scope.

Workflow activity Typical outward PHC activity Main route Legislation Regulations Standards Confidentiality, guidance and other controls First workflow question
Shared-care and summary-record access PHC makes a role-filtered record view, summary or care-plan contribution available to an authorised direct-care team through a specifically named service Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional direct-care duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Contract-dependent: GMS Regulations 2015; SI 2026/532 (GMS/PMS amendments)
Standards framework only: SI 2025/950
Scope-dependent: Core Information Standard; GP Connect Access Record: Structured – FHIR API; NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020); Personalised Care and Support Plan (DAPB4022); DCB0129; DCB0160; DSPT Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; executed Standard GMS Contract 2026/27; current care relationship, role filtering, objection, override, audit, provenance and correction Which exact record service, care relationship, role and information view are being approved, and how are objection, override, audit and correction handled?
Diagnostic test ordering and results PHC sends a test request, patient and recipient identifiers and the necessary clinical context; acknowledgements, status changes and the later report form linked but distinct message legs Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional direct-care duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
No additional workflow-specific regulation identified: check the exact test, service and contract.
Standards framework only: SI 2025/950
Scope-dependent: NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020); DCB0129; DCB0160; DSPT
Separate incoming report leg only: DAPB4101 (Pathology reporting)
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; end-to-end correlation, acknowledgement, cancellation, correction, abnormal-result handling, clinical ownership and downtime Can the order, patient, requester, specimen or procedure, acknowledgement, cancellation, correction and final result be correlated end to end?
Referrals, triage and bookings PHC sends referral content or a booking request and receives acknowledgement, triage, acceptance, rejection, appointment and cancellation states Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional direct-care duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Contract-dependent: GMS Regulations 2015; SI 2026/532 (GMS/PMS amendments)
Standards framework only: SI 2025/950
Scope-dependent: Clinical Referral Information Standard; BaRS (DAPB4060); NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020); DCB0129; DCB0160; DSPT Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; commissioned-pathway and supplier terms; acknowledgement, acceptance or rejection, safety-netting, closure, audit, correction and failure ownership Which exact referral or booking use case applies, and who closes rejected, returned, cancelled, failed or unanswered work?
Transfers of care and clinical correspondence PHC sends a care summary, handover, care plan, clinical letter or other purpose-specific information to another team Direct-care sharing route
Sharing with the wider NHS
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional direct-care duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
No additional universal outward-transfer regulation identified: validate the exact service and contractual requirements.
Standards framework only: SI 2025/950
Scope-dependent: Core Information Standard; Personalised Care and Support Plan (DAPB4022); NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020); DCB0129; DCB0160; DSPT
Directional exclusion: DAPB4042 (Acute discharge) governs the incoming acute-provider-to-GP leg, not outward PHC correspondence.
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; purpose-specific content, receipt, reconciliation, follow-up, correction, onward use and clinical ownership What event triggers the transfer, which content is necessary now, and who owns receipt, reconciliation, follow-up and correction?
Medicines, prescribing and pharmacy PHC sends prescription, medication, allergy, administration, review or reconciliation information to a pharmacy or another care team Direct-care sharing route
Pharmacy and medicines
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional direct-care duty: Section 251B direct-care duty
Standards framework only: HSCA 2012 ss. 250–251
Known limitation: this wiki has not registered a complete medicines, prescribing or controlled-drug regulatory set; validate the exact prescribing, dispensing and commissioned-service regime.
Standards framework only: SI 2025/950
Scope-dependent: dm+d; NHS Number (ISB 0149-01); SNOMED CT; UK Core FHIR R4 (DAPB4020); DCB0129; DCB0160; DSPT
Separate incoming return leg only: DAPB4008 (Community pharmacy)
Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; authoritative prescription and medication state, substitutions, cancellation, dispensing, reconciliation, allergy handling and safety-case evidence What is the authoritative medicine or prescription state, and how are changes, duplicates, substitutions, cancellation, dispensing and reconciliation represented?
Patient access, requests and communications PHC provides record access, proxy access, messages, appointment or prescription transactions and accessible digital or non-digital communications Five distinct data routes, selecting patient access, transaction, communication or direct-care disclosure explicitly Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Accessibility and equality: Equality Act 2010 ss. 20, 29 & 149
Standards framework only: HSCA 2012 ss. 250–251
Contract-dependent: GMS Regulations 2015; SI 2026/532 (GMS/PMS amendments)
Actor- and service-dependent: Accessibility Regulations 2018
Standards framework only: SI 2025/950
Scope-dependent: AIS (DAPB1605); DAPB4031 (Online/video consultation collection), which is a usage-data collection rather than authority for the service; NHS App API; WCAG 2.2; DAPB3051 (Identity and authentication); DCB0129; DCB0160; DSPT Common law confidentiality; Caldicott Principles; ICO Data Sharing Code; executed Standard GMS Contract 2026/27; NHS Notify Directions 2025; third-party confidentiality, serious-harm review, child or proxy access, identity, correction, accessibility and non-digital fallback Is this record access, delegated access, a transaction or a message, and what safeguarding, accessibility, response and fallback controls apply?
Population health, research, audit and reporting PHC supplies a defined extract, collection, disclosure or approved access route beyond an individual-care workflow Beyond-care sharing route
Research, planning and audit
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Conditional statutory route: NHS Act 2006 s. 251
Standards or collections framework only: HSCA 2012 ss. 250–251
Conditional confidentiality route: COPI Regulations 2002, under the exact regulation, approval, conditions and period
Standards framework only: SI 2025/950
Scope-dependent: DCB3058 (National data opt-outs); DSPT; the exact collection or information standard for the purpose; DCB0129 and DCB0160 only where their role-specific scope is created Common law confidentiality, through a route distinct from direct care; Type 1 and national data opt-outs; Caldicott Principles; ICO Data Sharing Code; anonymisation and minimisation, DPIA, controller agreement, specialist approval where required, access, linkage, output, retention, deletion and re-identification controls Can anonymous information achieve the purpose; if not, what exact authority, confidentiality route, opt-out result, specification and recipient apply?
Patient registration, demographics and GP-record transfer The current practice responds to the new practice’s request, transfers the applicable electronic record and routes unconfirmed or paper-only portions through the specified fallback Registration and record-transfer workflow
Current primary-care contract position
Baseline when personal data are involved: UK GDPR; DPA 2018; DUAA
Service powers only: HSCA 2012 does not by itself establish the practice’s purpose or confidentiality route.
Contract-type and case dependent: GMS Regulations 2015, PMS Regulations 2015, SI 2021/995, SI 2024/575 and SI 2026/532 Scope-dependent: NHS Number (ISB 0149-01); GP2GP HL7 V3 production integration; DCB0129; DCB0160; DSPT Common law confidentiality; executed GMS/PMS/APMS terms; Register, PDS, PCRM and GP2GP service rules; correct patient/practice, completeness, provenance, redaction, positive acknowledgement, 28-day transfer requirement and unconfirmed/paper fallback Is this a permanent transfer between the actual supported systems, and who owns completeness, acknowledgement, paper-only content and failed transfer?
Safeguarding, public-health notifications and required disclosures PHC responds to a defined safeguarding trigger, notification duty, binding order or notice, regulator power, or current NHS England provider collection Required-disclosure route
Legislation, powers and duties
Gateway-specific: verify the exact safeguarding, health-protection, court, coroner, regulator or collection provision.
Baseline when personal data are involved: UK GDPR; DPA 2018
Trigger-specific: Health Protection (Notification) Regulations 2010, as amended; other regulations only within their exact scope.
Conditional confidentiality route: COPI Regulations 2002, only where the stated regulation and conditions apply.
Specification-dependent: the exact notice, order, DPN or reporting specification; NHS Number (ISB 0149-01), DCB0129, DCB0160 and DSPT where scoped Common law confidentiality; current safeguarding guidance; verified requester and recipient; required/permitted/requested distinction; necessity, proportionality, best interests or public-interest reasoning; secure delivery, audit, correction and onward-use limits What exact current trigger, actor, recipient and gateway applies, and does it require, permit or merely request this disclosure?

The National Imaging Registry (NIR) sits primarily in the incoming diagnostic-imaging discovery and retrieval route. It does not transport a PHC test order and is not the DAPB4101 pathology-reporting standard. Where an eligible PHC organisation is accepted to publish locally held imaging, treat that as a separate outward direct-care flow with NIR onboarding, controller, supplier and deployment controls. SRC-077

These rows are operational entry points, not universal mandates. The maintained source evidence is attached to the linked route and standards pages.

Check the purpose after choosing the workflow

The workflow narrows the candidate instruments, but purpose decides which route can apply:

Purpose Maintained route Boundary to preserve
Individual care Direct-care sharing route A current care relationship does not permit the whole record or every recipient.
Planning, research, commissioning, audit or another beyond-care use Beyond-care sharing route Earlier direct-care access does not authorise reuse; test anonymous information first.
Safeguarding, notification, collection, court, coroner or regulator disclosure Required-disclosure workflow Verify the exact current gateway and whether it requires, permits or merely requests disclosure.

Read the authority columns as a screen

The matrix owns the cross-workflow comparison. The four authority columns answer different parts of the exam question:

  • Legislation identifies the data-protection baseline and any purpose- or actor-specific Act. It does not settle confidentiality.
  • Regulations identifies statutory instruments and contract-dependent requirements only where their exact scope fits.
  • Standards identifies candidate information, terminology, interoperability, safety and assurance standards. “Active” or listed in the directory does not mean universally mandatory.
  • Confidentiality, guidance and other controls identifies the separate common-law route, patient choices, statutory guidance, contracts and operational controls.

The Main route column is a decision route, not a fifth source of authority. Use the linked Legislation, powers and duties, Confidentiality and Caldicott, NHS standards applicability register and maintained evidence to confirm full titles, current status and scope.

Confirm applicability on the workflow page

Open the workflow link in the first column before making a decision. Its scope and boundary sections distinguish message legs that look similar but can be governed by different instruments—for example an outward diagnostic order and an incoming pathology report.

The detail page owns the operational application: exact service or pathway, direction, message leg, matching, provenance, clinical ownership, acknowledgement, correction, failure states and unresolved checks. It does not repeat the full cross-workflow register.

Continue with one outward flow

Follow one route without skipping a stage:

  1. Direction: remain on this outward-PHC matrix and select one row.
  2. Workflow: on the linked detail page, confirm the exact outward message leg and candidate instruments.
  3. Decision guide: carry the direction, workflow, sender, recipient, message leg and purpose into Decide a data flow.
  4. Decision record: follow the decision guide to the auditable record only after every applicable layer has been tested.

Do not proceed if the purpose, recipient, authority or confidentiality route is missing, or if technical access defaults to the whole record.