Skip to main content

Part of Objective E - Using and sharing information appropriately

Principle: E2 Upholding the rights of individuals

Current Chapter

Current chapter – Principle: E2 Upholding the rights of individuals


E2.a Managing data subject rights under UK GDPR

“You appropriately assess and manage information rights requests such as subject access, rectification and objections.”

Overview

To achieve this contributing outcome, your organisation needs to assure that it supports individuals in exercising their information rights such as subject access, rectification and objections.

Information rights requests

Individuals have information rights under UK GDPR and the Data Protection Act 2018 which allow them to request to access, amend, erase, restrict or object to the processing of their personal information in specific circumstances.

An information rights request is any request made by an individual seeking to exercise one of these rights.

Examples of individual rights are outlined below, together with an explanation of whether they are relevant to this contributing outcome.

Individual right Relevance to outcome E2.a Additional information
Right to be informed Not relevant to this outcome Requirements relating to the right to be informed are addressed under E1.a Privacy information.
Right of access Organisations should have procedures in place relating to subject access requests (SARs).  For practical guidance on responding to SARs including the procedures you must follow, the necessary timescales, and the situations in which they can be refused, see SAR guidance on the NHS England Information Governance (IG) pages.
Right to rectification Organisations should have procedures in place relating to requests to amend information. NHS England’s IG pages contains guidance on amending patient and service user records.
Right to erasure Organisations should have procedures in place relating to requests for information to be deleted.

The right to erasure is not absolute and only applies in certain circumstances.

However, it should be considered in situations where it becomes relevant.

For example, if an individual consents to their patient story being used in promotional materials, and then changes their mind, you would have to remove that specific information to comply with the right to erasure.

Right to restrict processing Organisations should have procedures in place relating to limiting use of data subjects’ personal information where a request leads to one of the legal conditions for the right to restrict processing being met. You should restrict processing of information when a request from a data subject leads to you consider its accuracy or the legitimate grounds for processing it.
Right to data portability Organisations should have procedures in place relating to requests to provide personal information in structured, commonly used and machine-readable formats where one of the legal conditions for the right to data portability are met.

This right only applies when the processing is carried out under specific lawful bases – consent or for the performance of a contract - which may not be often used by health and care organisations. 

If, after reviewing your organisation's processing activities, you cannot identify any realistic circumstances in which this right would apply, you may be able to justify not having a specific procedure for managing such requests.

Right to object Organisations should have procedures in place relating to objections to information being processed.

Patients and service users have the right to object to the processing of their data. These should be considered on a case-by-case basis, and where it is not upheld, compelling legitimate grounds must be demonstrated by the organisation. 

Where data is being processed for direct marketing purposes, the right to object is absolute.

Rights related to automated decision making including profiling Not relevant to this outcome. The right not to be subject to decisions based solely on automated processing, while not explicitly measured through the CAF-aligned DSPT, is likely to be assessed by your organisation through your risk assessments for AI-driven technologies under A2.a Risk management process.

Recognising and responding to requests

Your organisation should have a documented process for identifying, assessing and responding to information rights requests. 

The process should include:

  • recognising when an individual is seeking to exercise a right under data protection legislation, regardless of the channel through which the request is received
  • verifying the identity of the requester where appropriate
  • gathering the information needed to assess and respond to the request
  • determining whether the relevant legal conditions and exemptions apply
  • providing a response and maintaining records of the request, decision-making and outcome
  • ensuring requests are completed within the applicable statutory timescales, including any permitted extensions for complex requests

Staff knowledge for requests

Training should be proportionate to an individual's role and responsibilities within the information rights request process. 

For example:

  • Frontline staff, reception staff, administrative staff and contact centre staff should be able to recognise when an individual may be exercising an information right, understand that specific terminology is not required for a request to be valid, and know how to escalate or refer the request in line with organisational procedures
  • SAR administrators, IG staff and case handlers should receive more detailed training covering the different categories of information rights requests, identity verification, statutory timescales, exemptions and redaction requirements
  • Clinicians involved in reviewing records should understand their role in supporting decisions on disclosure where clinical judgement is required
  • Caldicott Guardians and senior IG decision-makers should understand the legal, professional and ethical considerations relevant to information disclosure

Responsibilities for requests

Relevant staff members should understand that individuals can exercise a range of rights under data protection legislation and be able to recognise when a request is being made. 

Roles and responsibilities for managing information rights requests should be clearly defined and documented. Examples are provided below, although your organisation may define and allocate these stages in a way that reflects its own structure and processes.

Stage Example role(s)
Receipt and identification of requests Frontline staff, reception staff, customer service teams, administrative staff, contact centre staff
Logging and tracking requests IG team, SAR administrators
Identity verification IG team, SAR administrators, patient services team
Provision of information System administrators, relevant business areas, clinical departments
Case assessment and application of exemptions IG professionals, data protection officers (DPOs), legal advisers, senior IG staff
Clinical review of records (where required) Clinicians, Caldicott Guardians
Authorisation of complex or high-risk disclosures Caldicott Guardian, DPO, senior responsible managers
Responding to the requester IG team, SAR administrators
Escalation and oversight DPO, Head of Information Governance, Caldicott Guardians

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • process for responding to information rights requests 
  • proof of training undertaken, qualifications held, or experience acquired by staff members for responding to information rights requests

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.

Interpreting indicators of good practice

Indicator(s) of good practice Term Interpretation

A#3

Responsibilities for information rights requests have been delegated to appropriately trained and resourced staff members who can manage them in line with legal requirements.

'appropriately trained' You should define the training required for managing information rights requests in your training needs analysis.

“You have a good understanding of requirements around consent and privacy, including the common law duty of confidentiality, and use these to manage consent.”

Overview

This contributing outcome requires your organisation to have efficient and informed procedures for managing consent.

Consent

The common law and UK GDPR cover 2 definitions of consent in law.

Consent under common law Consent under UK GDPR

In common law, there is a duty of confidentiality which governs when you can disclose personal information. One such circumstance is where the patient or service user consents to the sharing.

An individual’s consent may be implied where their health and care information is used or shared for the purposes of their individual care, but explicit consent must be obtained otherwise. 

See NHS England’s guidance on consent and confidential patient information.

Under UK GDPR requirements, consent is one of several legal bases for processing personal data. However, you cannot usually rely on consent as a legal basis when you are processing personal data for individual care or health research.

See NHS England's guidance on consent and confidential patient information and the HRA GDPR guidance for researchers and study co-ordinators for further details.

An example of where you might rely on UK GDPR consent is when you use photography of patient groups on your website. This would be a use of their personal data which falls outside of other Article 6 legal bases, so UK GDPR consent would be required under Article 6. 

If you were also to include a patient testimonial containing the patient’s health information, an Article 9 legal basis would be required for sharing special category data in addition to the Article 6 legal basis.

Relevant staff member understanding of consent 

Your organisation should ensure that staff understand how consent applies to their role. Training should be proportionate to the decisions staff are expected to make and the types of information they use or share.

For staff who are not information governance specialists, training should focus on practical recognition of common scenarios. For example, frontline, clinical and administrative staff should understand:

  • when patient information can usually be shared for direct care on the basis of implied consent
  • when explicit consent may be needed, such as sharing information with a family member, unpaid carer or solicitor
  • how to check whether a patient has objected to information sharing
  • when to seek advice rather than making a decision independently

Scenario-based training can help staff understand how consent works in practice. This may include examples involving direct care, requests from relatives or carers, use of patient images, disclosure to third parties, or sharing information for purposes outside direct care.

For IG staff, Caldicott Guardians and other staff involved in higher-risk or more complex decisions, training and supporting materials should cover the relationship between UK GDPR, the common law duty of confidentiality, the Caldicott Principles and relevant professional guidance.

Policies and procedures for managing consent

Your organisation should have documented policies and procedures that explain how consent is managed for the use and sharing of information. 

Your policies and procedures should cover the main scenarios where consent may be relevant, including:

  • use and sharing of confidential patient information for direct care, where implied consent may usually be relied upon where the sharing is within the patient’s reasonable expectations
  • use or sharing of confidential patient information for purposes outside direct care, where explicit consent or another common law basis may be needed
  • disclosures to third parties, such as family members, unpaid carers, solicitors, police, insurers or other external organisations
  • use of patient stories, photographs, or information which could reasonably be used to identify them in communications, publications or medical conference materials

Policies and procedures covering consent may be standalone documents or incorporated into related information governance documentation. Examples include: 

  • confidentiality policies
  • information sharing policies
  • disclosure procedures
  • research approvals procedures
  • communications and media consent procedures
  • guidance relating to disclosures to family members, carers, legal representatives, police and other third parties

Collectively, these should provide staff with clear direction on when consent is required, how it should be obtained, recorded and withdrawn. 

It should also be made clear to staff members that they should seek advice from the Caldicott Guardian, information governance team or other appropriate decision-makers where there is uncertainty about whether consent is needed, or where the proposed use or sharing is unusual.

Recording consent

An important part of obtaining, recording and managing consent appropriately is maintaining up-to-date records. These records of consent should be made wherever a legal, regulatory or professional need arises to document an individual’s consent or decision not to give consent, whether under common law or UK GDPR. 

For common law consent, it is up to your organisation how you manage this. 

For planned activities with established governance structures, such as research studies or service evaluations, consent forms are likely to be used. These forms will normally serve as the organisation’s record of the individual’s consent.

In other situations, consent decisions may arise on a more ad hoc basis. For example, a patient may contact your organisation to withdraw consent for a particular use of their information. In these cases, your organisation’s process might be recording the individual’s wishes and the action taken as a note in the patient record.

For UK GDPR consent, see the ICO’s practical guidance for legal expectations on obtaining, recording and managing an ongoing consent record under UK GDPR.

Providing information about consent

Your organisation should provide clear information to patients and service users about when consent may be asked for before information is used or shared.

This information should help people understand:

  • when their information may be used or shared on the basis of implied consent, for example where information is shared with health and care professionals involved in their direct care
  • when explicit consent may be needed, for example where information is being used for purposes outside of the individual’s direct care 

You should consider the common situations where staff may need to explain or ask for consent and provide suitable wording or prompts to support consistent communication. This may include written templates, consent forms, patient leaflets, website content, call scripts, appointment letters or verbal explanations that staff can use when speaking with patients and service users.

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • documents showing organisation’s policies and processes relating to consent 
  • public materials about consent (for example, privacy information) 
  • records of consent 
  • training materials 
  • documents from steering group meetings

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.


E2.c National data opt-out policy

“A robust policy and system is in place to ensure opt-outs are correctly applied to the information being used and shared by your organisation.”

Overview

To meet this contributing outcome, your organisation needs to ensure opt-outs are correctly applied to the information you use and share.

National data opt out

The national data opt-out allows patients and service users to opt out of their confidential patient information being used for purposes beyond their individual care, such as research and planning.

There are a number of exemptions to the national data opt-out. For example, where people are using anonymous data such as statistics of how many people received a specific treatment, or where use of the confidential patient information is required by law. NHS England has also published a list of specific programmes that are exempt from the national data opt-out.

Your organisation should have clear arrangements in place to identify where the national data opt-out applies, ensure opt-outs are correctly recorded and processed, and provide assurance that they are consistently applied whenever relevant information is used or shared.

Identifying where the national data opt-out applies

You should understand which of your organisation’s uses and disclosures of information may be affected by the national data opt-out. Examples may include the use or sharing of confidential patient information for:

  • research
  • planning
  • service evaluation
  • population health management
  • business intelligence

You should maintain a record of where the national data opt-out may apply to your organisation’s activities. This may be documented through:

  • your information assets and flows registers, identifying particular data flows associated with confidential patient information being used for secondary purposes where the national data opt-out may need to be considered
  • an equivalent standalone document that identifies your organisation’s uses and disclosures of confidential patient information for secondary purposes where national data opt-out consideration is required

The format is less important than being able to demonstrate that you have identified the relevant activities and that you understand where national data opt-out controls need to be applied.

Identifying these activities helps you determine which teams need to understand the national data opt-out and their responsibilities for applying it correctly. For example, it is likely that research and quality improvement teams will require a practical understanding of the applications of the policy. Other teams may have little or no need to apply the policy if their activities are limited to direct care.

Providing information about the national data opt-out

Your patients and service users should be able to easily understand what the national data opt-out is and how it may affect the use of their information. 

Your privacy information should explain the national data opt-out in clear, concise and accessible language and direct readers to further information where they wish to learn more. 

Applying opt-outs consistently

You should have a procedure that ensures the national data opt-out is considered wherever it is relevant to uses or disclosures of confidential patient information. 

A practical approach is to incorporate national data opt-out checks into existing governance processes, such as: 

  • information disclosure procedures
  • research or planning activity approvals
  • data protection impact assessments (DPIAs)

Supporting evidence

To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:

  • privacy information
  • data flow register 
  • methodology for processing opt-outs 
  • governance for ensuring the national data opt-out is consistently applied

This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.

Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate. 

Additional guidance

For additional guidance, see:

NHS England | National data opt-out


Last edited: 26 August 2026 12:07 pm