Skip to content

Safeguarding, public-health and required-disclosure routes

No universal disclosure authority

A safeguarding concern, public-health purpose, official request or NHS collection label does not supply one blanket permission. Identify the exact current actor, trigger, recipient, statute, order, notice, direction, Data Provision Notice or defensible confidentiality route—and whether it requires, permits or merely requests disclosure—before sharing.

Return to the Out-of-PHC row.

Scope and boundaries

Use this page for four gateway families that are often incorrectly bundled together:

  1. child or adult safeguarding;
  2. notifiable disease, causative-agent and other defined public-health reporting;
  3. court, coroner or regulator powers and orders; and
  4. NHS England collections made through a current direction, request or Data Provision Notice.

Routine individual care and voluntary information sharing use their own routes. A professional, public-interest or confidentiality justification may sometimes apply where no specific statutory gateway does, but that requires a fact-specific accountable decision rather than a generic “safeguarding” or “public interest” label. CLM-056

Out of primary healthcare

Classify the trigger before selecting the data or recipient.

Trigger family Exact gateway to verify Do not assume
Child safeguarding Current safeguarding legislation, statutory guidance, local safeguarding functions, the recipient’s role and a documented necessity/proportionality and confidentiality decision That consent is always required, or that a safeguarding label authorises the whole record
Adult safeguarding The Care Act function, responsible local-authority or partner role, facts and any separate statutory or public-interest route That a section 42 enquiry creates a universal reciprocal GP disclosure duty
Notifiable disease or organism The exact Health Protection (Notification) Regulations schedule, reporting actor, recipient, content, channel and deadline That every “public health” request is a notifiable-disease duty
Court, coroner or regulator The binding order, notice, statutory power, function, relevance and production limits That a police, solicitor, court, coroner or regulator label alone makes a request compulsory
NHS England collection The current section 259 Data Provision Notice or other exact instrument addressed to the provider, including scope, data, form, manner and period That a section 254 direction to NHS England automatically imposes the same requirement on a GP practice

The distinction between a section 254 direction and a provider-facing section 259 Data Provision Notice is material. A current DPN—not a programme name or withdrawn proposal—must establish any provider obligation and its limits. CLM-058

How the requirement layers apply

Layer Workflow-specific position
Legislation UK GDPR and DPA 2018 remain applicable where personal data are processed. Safeguarding, health-protection, coroner, regulator and NHS England collection powers are actor-, function- and trigger-specific; verify the exact current provision rather than citing an Act generally.
Regulations The Health Protection (Notification) Regulations 2010, as amended, create specific notification duties for stated reporters, events, recipients and times. Other statutory instruments apply only within their exact scope. CLM-057
Standards and specifications A collection, notification or disclosure may prescribe a dataset, code set, channel, form or period. Treat that specification as part of the applicable instrument; it does not expand the underlying purpose or recipient. Apply clinical-safety, security and identity standards where the technical workflow creates their scope.
Confidentiality and other controls Establish whether disclosure is required, permitted or requested; record necessity, proportionality, best interests or public interest where relevant; disclose only relevant information; verify identity and authority; use a secure route; retain the order/notice and decision; control onward use and correction.

Minimum, conditional and higher assurance

  • Required floor: the exact trigger, responsible actor, intended recipient, current gateway, required or permitted status, necessary data, deadline, confidentiality analysis, secure transmission and auditable decision.
  • Conditional envelope: disclose only the data and time period within the gateway or documented public-interest decision; separate multiple purposes and recipients.
  • Higher-assurance ceiling: structured trigger and authority records, validated recipient endpoints, data-field minimisation, dual review for exceptional disclosures, delivery acknowledgement, correction and revocation handling, and scheduled revalidation of notices and guidance.

Future boundary

The Children’s Wellbeing and Schools Act 2026 contains a new child information-sharing duty, but as at 28 July 2026 the government expected it to apply from 30 September 2026 and final statutory guidance remained pending. Treat it as a Horizon and validation item, not current operational authority. CLM-059

Failure states and ownership

Test generic requests without a cited power, withdrawn or expired notices, wrong actor or recipient, overbroad date ranges, whole-record default disclosure, confusion between required and permitted sharing, omitted confidentiality analysis, unverified requester identity, insecure delivery, missing court-order limits, silent reuse, and future legislation treated as commenced.

Evidence and open checks

Maintained evidence: SRC-078, SRC-079, SRC-080, SRC-081 and SRC-082. Use VAL-031–VAL-034 to recheck the specific safeguarding, public-health, court/regulator or collection route. The umbrella stop condition in VAL-010 still applies.

Continue to Assess and record this workflow.