Part of Objective E - Using and sharing information appropriately
Principle: E3 Using and sharing information
E3.a Using and sharing information for direct care
"You lawfully and appropriately use and share information for direct care.”
Overview
This contributing outcome relates to your organisation facilitating the lawful and appropriate using and sharing of information for direct care.
Using and sharing information for direct care
Your organisation has a duty to share information about a patient or service user for direct care purposes, where lawful and unless a specific exception applies. This is set out in the Health and Social Care Act 2012.
Practical ways to gain assurance that clinical staff within your organisation are appropriately using and sharing information for direct care include:
- policies and procedures - clearly signposting policies and procedures for staff members on your organisation’s intranet pages that establish how information should be used and shared
- training - ensuring that training is delivered to staff members covering their day-to-day information sharing responsibilities under UK GDPR, Common Law and the Caldicott Principles (such as the Data Security Awareness training and Information Sharing training provided by NHS England)
- engagement – directly engaging with teams to advise on IG considerations and promote the importance of robust information sharing practices
Staff members’ understanding of direct care information sharing
You should identify which staff roles require an understanding of direct care information sharing and ensure training and awareness activities are proportionate to those roles.
Relevant staff are likely to include clinical staff, administrative staff involved in patient care, and others who have access to confidential patient information as part of their duties. They should understand:
- what direct care means and the activities it covers
- the importance of considering patients' reasonable expectations and recorded objections
- their responsibility to ensure information sharing is relevant and proportionate
- when a request is unusual and should be escalated for advice
- how to contact the information governance team, Caldicott Guardian or other appropriate decision-makers for support
A practical way to achieve this is through a combination of policies, staff guidance, training and internal communications that explain common information sharing scenarios and escalation routes.
Policies and procedures for direct care information sharing
Your organisation should have documented policies, procedures or equivalent guidance covering the direct care information sharing activities it routinely undertakes as part of delivering its services.
Collectively, these should provide clear direction on:
- the importance of using and sharing information where it is needed for direct care purposes
- the controls that apply
- when advice should be sought from the information governance team, Caldicott Guardian or other appropriate decision-makers
-
the importance of identifying appropriate legal bases under both common law and UK GDPR when using and sharing information for direct care
-
the need to be informed by the National Data Guardian's Caldicott Principles
Reasonable expectations and objections
Staff members should use and share information in line with patients’ reasonable expectations. This means that before using or sharing information, staff members should:
- ensure that it is reasonable to believe that the patient concerned understands the reason for and expects their use or sharing of the patient’s information
- check the patient record for any objections, and if relevant, decide whether to uphold them
Both of these concepts are covered in the Data Security Awareness training and Information Sharing training provided by NHS England.
Specific legislation about confidential information
Specific legislation exist which apply some limitations on information being shared for direct care. These include:
- the Health and Social Care Act 2012 which sets out restrictions on sharing where a service is an anonymous access provider, such as a dedicated human immunodeficiency virus (HIV) and sexually transmitted disease (STI) service
- the Gender Recognition Act 2004 which limits the circumstances in which certain information can be disclosed without explicit consent
- the Human Fertilisation and Embryology Act 1990 which prevents information from being disclosed relating to certain treatments defined under the Act
Your organisation must be aware of these legal restrictions on using and sharing information, and apply their requirements where relevant.
Non-routine ad hoc data sharing for direct care purposes
Most information sharing for direct care will occur within your own organisation, or with other health and care providers within your local network.
However, you may receive information requests from health or care organisations for direct care who are not part of your usual sharing networks, for example:
- organisations situated abroad
- private healthcare providers that are not normally involved in the patient's care
- specialist tertiary centres
- emergency or major incident response healthcare providers
- military healthcare providers
These requests should be considered on a case-by-case basis, with controls to ensure that data protection principles and best practices for information sharing are adhered to.
In practice, when staff members receive information sharing requests for direct care which they consider to be unusual, they should know how to seek appropriate advice before information is disclosed. Depending on the circumstances, this may involve consulting a line manager, team leader, senior clinician, information governance (IG) team, Caldicott Guardian or other designated decision-maker, depending on who is available and the urgency of the situation.
You should have an internal process that supports these escalation arrangements, ensures decisions are appropriately documented, and maintains a record of any disclosures made.
Arrangements for information sharing for direct care
If you're routinely sharing data with another controller organisation, it's good practice to have arrangements in place such as:
- data sharing agreements (see NHS England’s Data Sharing and Processing Agreement template for more information)
- policies, processes and procedures (information sharing frameworks, data protection impact assessments (DPIAs))
There are different forms your arrangements for information sharing can take. What's important is that you can demonstrate that you have considered:
- the nature of the information being shared
- measures to ensure the sharing adheres to legal and professional requirements
- roles and responsibilities of those involved in the sharing
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- evidence of policies and procedures for direct care information sharing
- training needs analysis and materials used for staff awareness
- documents related to data sharing arrangements for direct care
This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
Interpreting indicators of good practice
| Indicator(s) of good practice | Term | Interpretation |
|---|---|---|
|
A#1 Relevant staff understand what direct care is, the activities it covers, and when they should use or share information to facilitate it. |
'direct care' | For the purposes of the DSPT assessment, 'direct care' should be interpreted as per the definition given in the National Data Guardian’s 2013 Information Governance Review. |
|
A#3 Information which is used or shared for direct care is relevant and proportionate. |
'relevant and proportionate' |
Assessing the relevance and proportionality of information before using or sharing it forms part of your legal obligations under UK GDPR and professional obligations under the Caldicott Principles. Decisions made in situations where there is a question over relevance or proportionality should be justified and recorded. |
Additional guidance
For additional guidance, see:
NHS England | Use and share information with confidence
NHS England | Information sharing in multidisciplinary teams
NHS England | Sharing information with the voluntary sector
NHS England | HIV and sexually transmitted infections (STIs)
Information Commissioner’s Office | Data sharing: a code of practice
E3.b Using and sharing information for other purposes
"You lawfully and appropriately use and share information for purposes outside of direct care.”
Overview
This contributing outcome relates to your organisation facilitating the lawful and appropriate using and sharing of information for other purposes outside of direct care.
Using information for other purposes outside of direct care
Your organisation may undertake activities involving using or sharing information for purposes other than providing care. For example:
- research
- service evaluation
- quality improvement
- planning and commissioning
- investigations and inquiries
- disclosures to third parties such as law enforcement, public inquiries and researchers
Staff members’ understanding of information sharing for other purposes
Relevant staff should understand which activities within their area of responsibility fall outside of direct care and the additional legal and professional requirements that apply when confidential patient information is used or shared for these purposes.
They should understand:
- when information can be used or disclosed under established procedures
- when decisions should be escalated to the information governance (IG) team, Caldicott Guardian, data protection officer (DPO) or other appropriate decision-makers
- their responsibility to ensure any information used or disclosed is relevant and proportionate to the purpose
Practical ways to gain assurance that relevant teams within your organisation are appropriately using and sharing information for non-direct care purposes include:
- policies and procedures - clearly signposting policies and procedures for staff members on your organisation’s intranet pages that establish how information should be used and shared
- training - ensuring that training is delivered to staff members covering their day-to-day information sharing responsibilities under UK GDPR, Common Law and the Caldicott Principles (such as the Data Security Awareness training and Information Sharing training provided by NHS England)
- engagement – directly engaging with teams to advise on IG considerations and promote the importance of robust information sharing practices
Legal and professional considerations
Your organisation should have documented procedures for assessing requests to use or share information for purposes outside of direct care.
These procedures should ensure that appropriate consideration is given to:
- the common law duty of confidentiality
- UK GDPR requirements for sharing personal data
- the Caldicott principles
- any other legal or professional requirements relevant to the proposed use or disclosure
Transparency and communicating with individuals
Patients and service users should be provided with clear information about how their information may be used or shared for purposes outside of direct care.
Your privacy information should explain:
- the types of secondary uses undertaken by your organisation
- the circumstances in which information may be shared with other organisations
- any choices or rights available to individuals
- where further information can be obtained
Relevant staff should understand when individuals may require additional information about a proposed use or disclosure and know how to direct them to appropriate transparency materials.
Documenting decisions and disclosures
Your organisation should have clear governance arrangements for decisions relating to the use and sharing of information for purposes outside of direct care.
Most routine uses and disclosures should be managed through established policies, procedures and approval processes. However, where a proposed use or disclosure is unusual, complex, high-risk, novel, contentious, or falls outside normal business activities, it may be appropriate for the Caldicott Guardian, information governance (IG) team, data protection officer (DPO), IG steering group or other appropriate governance forum to be involved.
For any disclosure decisions taken, details should be recorded with a clear UK GDPR legal basis and common law basis identified in line with professional guidance.
There is no mandated format for recording disclosures, however your disclosure logs should include:
- nature and quantity of information requested
- details of the requester
- nature and quantity of information given
- names and roles of decision makers
- justifications for any decisions taken
- risk assessments carried out
Arrangements for information sharing for other purposes outside of direct care
If you're routinely sharing data with another controller organisation, it's good practice to have arrangements in place such as:
- data sharing agreements (see NHS England’s Data Sharing and Processing Agreement template for more information)
- agreed policies, processes and procedures, such as information sharing frameworks, and data protection impact assessments (DPIAs)
There are different forms your arrangements for information sharing can take. What's important is that you can demonstrate that you have considered:
- the nature of the information being shared
- measures to ensure the sharing adheres to legal and professional requirements
- roles and responsibilities of those involved in the sharing
Supporting evidence
To support your response, you can upload (or link to) evidence which best demonstrates your achievement of the contributing outcome. Examples include:
- evidence of policies and procedures for non-direct care information sharing
- training needs analysis and materials used for staff awareness
- privacy information or equivalent
- documents related to data sharing arrangements for other purposes outside of direct care
- disclosure log
This is not an exhaustive list. You're welcome to provide other types of evidence if you feel they are relevant to the contributing outcome.
Your supporting statement should cross-reference how each piece of evidence provides justification for your achievement of the contributing outcome, including relevant page numbers where appropriate.
Interpreting indicators of good practice
| Indicator(s) of good practice | Term | Interpretation |
|---|---|---|
|
PA#1 Relevant staff members understand which of your organisation’s information sharing activities fall outside of direct care. |
'relevant staff' |
Requests to share information (whether written or verbal) should be processed by trained or experienced staff. If you work in a large organisation, there may be a team who is responsible for managing requests. In smaller organisations there should be an individual who is trained to manage requests. |
|
PA#1 Relevant staff members understand which of your organisation’s information sharing activities fall outside of direct care. |
'direct care' | For the purposes of the DSPT assessment, 'direct care' should be interpreted as per the definition given in the National Data Guardian’s 2013 Information Governance Review. |
Additional guidance
For additional guidance, see:
NHS England | Use and share information with confidence
NHS England | Sharing information with the voluntary sector
NHS England | Sharing information with the police
NHS England | Access to the health and care records of deceased people
NHS England | Inquiries, reviews, investigations and court orders in health and social care services
Information Commissioner’s Office | Data sharing: a code of practice
Information Commissioner’s Office | Sharing personal data with law enforcement authorities
Last edited: 25 August 2026 3:53 pm