Doctor’s Passport

Find your next topic

Explore the current textbook

Available drafts · Clinical review pending
Membership
Educational draft · awaiting clinical reviewThe full textbook explains uncertainty but does not replace live national or local guidance, specialist advice, or current prescribing information.
Full textbookMLASJTMSRAMRCPMRCGP

Confidentiality and information sharing

Share the right patient information with the right recipient for a justified purpose, distinguishing professional confidentiality, common-law duties and data-protection bases while documenting proportionate decisions and protecting people from harm.

Saved on this device
Open the sections you need. The overview is shown first.
01Principles and purposeThe professional or clinical skill and the decisions it supports.

A sound information-sharing decision begins with the clinical or public purpose, not with a reflexive request for consent. Professional confidentiality, the common-law duty of confidence, data-protection law and specific statutory duties overlap but answer different questions. A disclosure can satisfy UK GDPR yet still breach confidence, or be professionally justified while requiring a distinct lawful basis and safeguards.

The GMC’s UK-wide framework emphasises minimum necessary information, protection, lawful handling, appropriate direct-care sharing and explicit consent for most identifiable secondary uses unless law or public interest justifies disclosure. Statutory health-information routes differ across the nations. Escalate complex requests to a Caldicott Guardian, data protection officer, safeguarding lead or legal adviser without using advice-seeking as a reason for dangerous delay.

Key points

  • Confidentiality is not absolute and information sharing is not automatically a breach. Identify the purpose, recipient, authority, necessity and minimum information needed before disclosing.
  • For direct care, share relevant, accurate and current information within the care team in line with reasonable patient expectations unless the patient objects; explain the consequences of an objection and seek a workable compromise.
  • Do not confuse consent under the common-law duty of confidence with a UK GDPR lawful basis. Health data processing normally needs both an Article 6 basis and an Article 9 condition, which may be provisions other than consent.
  • Use anonymised information when it serves the purpose. If identifiable information is necessary, disclose only what is relevant, use a secure channel and confirm the recipient.
  • Share information when the law requires it. Public-interest disclosure to protect others requires a proportionate balance of risks and confidentiality. Usually respect a capacitous adult’s refusal when only they are endangered; exceptional departures need careful justification and advice. Record the reasons for sharing or withholding information.
  • The duty continues after death. “Next of kin” does not own the record or automatically authorise disclosure; consider legal rights, prior wishes, benefit, distress, third-party information and the purpose of the request.
02Situations and prioritiesThe context, relevant information and actions that matter most.
Expected direct-care sharing

The care team needs relevant information and should explain how it is shared. Respect a specific objection unless disclosure is legally required or independently justified in the public interest. An overall-benefit justification applies to someone who lacks capacity for the disclosure decision; it is not a general power to override an adult’s informed refusal.

Secondary-purpose request

Research, teaching, media, insurance, employment, commissioning or administration may not fall within reasonable direct-care expectations. Prefer anonymised data; otherwise identify consent, statutory authority or a defensible public-interest route and meet data-protection requirements.

Risk of serious harm

A necessary, proportionate disclosure may protect other people from death or serious harm. If only the patient faces the risk, usually respect an adult’s capacitous refusal and continue offering support. Exceptions are very rare and may require legal advice. Incapacity requires the relevant benefit and safeguarding framework.

Unverified or excessive request

Requests by telephone, messaging, relatives, police, employers or external clinicians require identity, role and purpose checks. Authority to request some information does not create entitlement to the whole record.

03Assessment and interpretationHow to gather information, assess the situation and recognise uncertainty.
Reasoning sequence

Consider the information, its meaning and its limitations before deciding what follows.

  1. 01
    Purpose and recipient check
    Why
    Define why information is needed and who will receive it.
    Interpretation and limitations
    Verify identity and role independently, especially for remote requests. A clear purpose determines relevance, legal authority, patient expectations and the secure route.
  2. 02
    Authority and lawful-basis analysis
    Why
    Identify the confidence justification and applicable data-protection conditions.
    Interpretation and limitations
    Separate consent, legal obligation, direct care and public interest. For health data, identify an Article 6 basis and Article 9 condition where UK GDPR applies; consent is not the only or always the best basis.
  3. 03
    Necessity and minimisation check
    Why
    Limit disclosure to information needed to achieve the legitimate purpose.
    Interpretation and limitations
    Consider anonymisation, redaction, summary or restricted time period. Include enough context to avoid misleading the recipient, but do not send the full record by default.
  4. 04
    Risk and documentation check
    Why
    Balance privacy, harm prevention and accountability before acting.
    Interpretation and limitations
    Record the request, factors considered, advice, decision, content shared, recipient and whether the patient was informed. In emergencies, share necessary information promptly and document afterwards.
04Worked approachesCases with ordered reasoning, an action and a check of the outcome.
01Worked casePatient objects to direct-care sharingA patient with capacity refuses permission to share a serious drug reaction with a specialist who would prescribe related treatment; the information is essential to safe referral.
  1. 1Clarify exactly what the patient objects to and why, explain who would receive the information and how it prevents foreseeable treatment harm.
  2. 2Explore a proportionate compromise, such as sharing only the reaction, severity and relevant treatment context through the secure referral route.
  3. 3If the patient maintains the objection, explain that safe referral or treatment may be impossible without the essential information; do not promise unsafe secrecy.
  4. 4Final action: agree the safe route the patient accepts, or decline to arrange care that requires undisclosed essential information while offering alternatives.
  5. 5Verification: document the objection, consequences, compromise considered and plan, and ensure any permitted disclosure reached the intended clinical recipient.
02Public-interest approachCredible threat of serious harmA patient describes a specific plan to cause serious violence and identifies an intended victim, but refuses consent to share information.
  1. 1Assess immediacy, specificity, capability, vulnerability and whether urgent action is needed, involving senior or safeguarding support where practicable.
  2. 2Consider whether warning the patient, obtaining consent or using less identifying information can mitigate risk without increasing danger.
  3. 3Disclose necessary information promptly to an appropriate responsible authority when needed to protect against death or serious harm.
  4. 4Record the risk evidence, balancing, recipient, information disclosed and reason the patient was or was not informed; continue clinical and safety follow-up.
03Request-handling approachPolice request for the complete recordA police officer emails asking for a patient’s entire record to assist an investigation but provides no court order, statutory requirement or patient consent.
  1. 1Verify the officer and request through an approved channel, and ask for the precise purpose, legal authority and information required.
  2. 2Do not assume police status creates blanket entitlement; seek information-governance or legal advice and identify whether disclosure is required, permitted or unjustified.
  3. 3If disclosure is lawful and necessary, provide only relevant information securely and tell the patient when practicable unless that would undermine the purpose.
  4. 4Record the decision and retain the request and response according to organisational policy, including reasons for refusing or narrowing it.
05Feedback, follow-up and evidenceReview outcomes, seek feedback and identify what to improve.
  • Confirm receipt of urgent disclosures and correct misdirected or incomplete information promptly; a technically sent message does not prove safe communication.
  • Review access logs, misdirected correspondence, inappropriate browsing and near misses, escalating suspected breaches through local information-governance and regulatory processes.
  • Tell patients about unexpected disclosures unless impracticable or likely to undermine the purpose, and keep privacy information current for routine processing.
  • Use case review to test whether staff distinguished direct care, safeguarding, legal compulsion and secondary use, and whether disclosed information was truly minimal and sufficient.
06Special situationsVariants, exceptions and circumstances that change the usual approach.

The duty to share matters

Over-cautious withholding can harm patients when a direct-care team lacks relevant, current information. Confidentiality requires controlled, justified sharing as well as protection from improper disclosure.

Consent has several meanings

Consent to treatment, agreement to confidential disclosure and consent as a data-protection lawful basis are distinct. Name which question is being answered and document the applicable authority.

Public interest requires specificity

Identify the threatened harm, why disclosure is necessary, why the recipient can reduce it and what minimum information is sufficient. Vague anxiety does not justify indiscriminate disclosure.

Posthumous privacy persists

Confidentiality continues after death. Consider the deceased’s wishes, third-party information, statutory access rights and the purpose and likely effect of disclosure; a relative’s status alone is not authority.

07Common pitfallsFrequent interpretation and management errors.
  1. 01

    Saying “GDPR prevents sharing” without analysing direct-care need, legal authority, serious-harm risk and the actual minimum information required.

  2. 02

    Using explicit consent as the UK GDPR basis for routine healthcare processing when another basis more accurately reflects the relationship and purpose.

  3. 03

    Sending a complete record because part is relevant, or using an unverified email address, personal device or informal group chat for convenience.

  4. 04

    Recording only that information was shared, without recipient, purpose, authority, content, advice or whether the patient was told.

Practice

Two practice questions

Question 1 of 20 correct
Ethics, law and professional practiceOriginal SBA

Direct-care objection

A patient refuses permission to disclose a previous life-threatening drug reaction to a specialist who would prescribe a related medicine. The information is essential for safe referral. What should the GP do first?

Sources and review status5 sources · checked 7 Sept 2026 · clinical review pending
Sources

Sources and review status

National guidance is shown before implementation-dependent detail. Apply principles in context and verify current guidance when a decision affects care. Source check completed 7 Sept 2026; clinical approval remains outstanding.

Authoring stateComplete draftClinical stateAwaiting reviewJurisdictionUnited Kingdom