Planning, commissioning, population health, research and audit
At a glance
These are normally beyond individual care even when the user works for an NHS organisation or already has direct-care access. Separate each purpose and use anonymous information where it can achieve it.
Return to the Out-of-PHC row.
Scope and boundaries
Use this family for planning, commissioning, service management, population health, audit, research and evaluation where the purpose is not the care of an identified person. Required statutory or directed reporting belongs to Safeguarding, public-health notifications and other required disclosures, because a specific duty or power can materially change the route.
An NHS destination, shared platform, prior direct-care access or “audit” label does not settle purpose or authority. Use the Beyond-care sharing route and the more detailed Research, planning and audit page.
Out of primary healthcare
PHC may supply a defined extract, collection, disclosure or approved access route. Record the exact purpose, population, variables, frequency, recipient, controller function, anonymous alternative and consequences of not providing the information. Treat every materially different purpose as a separate decision.
How the requirement layers apply
| Layer | Workflow-specific position |
|---|---|
| Legislation | UK GDPR and DPA 2018 require a controller function, Article 6 basis, Article 9 condition and applicable Schedule 1 safeguards. NHS Act 2006 section 251 is a route to regulations, not blanket permission. |
| Regulations | COPI Regulations 2002 support only their exact purposes, conditions, approvals and periods. The standards-procedure regulations do not authorise a collection or disclosure. |
| Standards | Apply the exact collection or information standard, National data opt-outs, DSPT and any role-specific DCB0129/DCB0160 scope. A directory entry does not prove applicability. |
| Confidentiality and other controls | Establish a confidentiality route distinct from direct care; apply Type 1 and national data opt-outs where in scope, anonymisation/minimisation, DPIA, agreements, specialist approvals, secure access, linkage/output controls, retention, deletion and re-identification controls. |
Minimum, conditional and higher assurance
- Required floor: a specific beyond-care purpose, anonymous-option assessment, controller authority, data-protection and confidentiality routes, opt-out result, minimum variables, security and accountable decision record.
- Conditional envelope: identifiable or confidential patient information is used only where the exact consent, legal requirement, COPI/section-251 support or defensible exceptional route applies.
- Higher-assurance ceiling: controlled secure access to the minimum necessary data with separation from direct-care systems, monitored linkage and outputs, transparent governance and reliable deletion/review—not convenient reuse of the clinical record.
Failure states and ownership
Test purpose drift, direct-care access reused for analytics, weak anonymisation, ignored opt-outs, over-broad extracts, recipient or processor changes, uncontrolled linkage or outputs, re-identification, retention beyond need, onward use, absent deletion and conclusions used for individual care without validation.
Evidence and open checks
Maintained evidence: SRC-001, SRC-002, SRC-005, SRC-007, SRC-008, SRC-009, SRC-021, SRC-030, SRC-033, SRC-040. Confirm the real controller, confidentiality and opt-out route through VAL-003.
Continue to Assess and record this workflow.