01Principles and purposeThe professional or clinical skill and the decisions it supports.
A sound information-sharing decision begins with the clinical or public purpose, not with a reflexive request for consent. Professional confidentiality, the common-law duty of confidence, data-protection law and specific statutory duties overlap but answer different questions. A disclosure can satisfy UK GDPR yet still breach confidence, or be professionally justified while requiring a distinct lawful basis and safeguards.
The GMC’s UK-wide framework emphasises minimum necessary information, protection, lawful handling, appropriate direct-care sharing and explicit consent for most identifiable secondary uses unless law or public interest justifies disclosure. Statutory health-information routes differ across the nations. Escalate complex requests to a Caldicott Guardian, data protection officer, safeguarding lead or legal adviser without using advice-seeking as a reason for dangerous delay.
Key points
- Confidentiality is not absolute and information sharing is not automatically a breach. Identify the purpose, recipient, authority, necessity and minimum information needed before disclosing.
- For direct care, share relevant, accurate and current information within the care team in line with reasonable patient expectations unless the patient objects; explain the consequences of an objection and seek a workable compromise.
- Do not confuse consent under the common-law duty of confidence with a UK GDPR lawful basis. Health data processing normally needs both an Article 6 basis and an Article 9 condition, which may be provisions other than consent.
- Use anonymised information when it serves the purpose. If identifiable information is necessary, disclose only what is relevant, use a secure channel and confirm the recipient.
- Share information when the law requires it. Public-interest disclosure to protect others requires a proportionate balance of risks and confidentiality. Usually respect a capacitous adult’s refusal when only they are endangered; exceptional departures need careful justification and advice. Record the reasons for sharing or withholding information.
- The duty continues after death. “Next of kin” does not own the record or automatically authorise disclosure; consider legal rights, prior wishes, benefit, distress, third-party information and the purpose of the request.
02Situations and prioritiesThe context, relevant information and actions that matter most.
The care team needs relevant information and should explain how it is shared. Respect a specific objection unless disclosure is legally required or independently justified in the public interest. An overall-benefit justification applies to someone who lacks capacity for the disclosure decision; it is not a general power to override an adult’s informed refusal.
Research, teaching, media, insurance, employment, commissioning or administration may not fall within reasonable direct-care expectations. Prefer anonymised data; otherwise identify consent, statutory authority or a defensible public-interest route and meet data-protection requirements.
A necessary, proportionate disclosure may protect other people from death or serious harm. If only the patient faces the risk, usually respect an adult’s capacitous refusal and continue offering support. Exceptions are very rare and may require legal advice. Incapacity requires the relevant benefit and safeguarding framework.
Requests by telephone, messaging, relatives, police, employers or external clinicians require identity, role and purpose checks. Authority to request some information does not create entitlement to the whole record.
03Assessment and interpretationHow to gather information, assess the situation and recognise uncertainty.
Consider the information, its meaning and its limitations before deciding what follows.
- 01
Purpose and recipient check - Why
- Define why information is needed and who will receive it.
- Interpretation and limitations
- Verify identity and role independently, especially for remote requests. A clear purpose determines relevance, legal authority, patient expectations and the secure route.
- 02
Authority and lawful-basis analysis - Why
- Identify the confidence justification and applicable data-protection conditions.
- Interpretation and limitations
- Separate consent, legal obligation, direct care and public interest. For health data, identify an Article 6 basis and Article 9 condition where UK GDPR applies; consent is not the only or always the best basis.
- 03
Necessity and minimisation check - Why
- Limit disclosure to information needed to achieve the legitimate purpose.
- Interpretation and limitations
- Consider anonymisation, redaction, summary or restricted time period. Include enough context to avoid misleading the recipient, but do not send the full record by default.
- 04
Risk and documentation check - Why
- Balance privacy, harm prevention and accountability before acting.
- Interpretation and limitations
- Record the request, factors considered, advice, decision, content shared, recipient and whether the patient was informed. In emergencies, share necessary information promptly and document afterwards.
04Worked approachesCases with ordered reasoning, an action and a check of the outcome.
01Worked casePatient objects to direct-care sharingA patient with capacity refuses permission to share a serious drug reaction with a specialist who would prescribe related treatment; the information is essential to safe referral.+
- 1Clarify exactly what the patient objects to and why, explain who would receive the information and how it prevents foreseeable treatment harm.
- 2Explore a proportionate compromise, such as sharing only the reaction, severity and relevant treatment context through the secure referral route.
- 3If the patient maintains the objection, explain that safe referral or treatment may be impossible without the essential information; do not promise unsafe secrecy.
- 4Final action: agree the safe route the patient accepts, or decline to arrange care that requires undisclosed essential information while offering alternatives.
- 5Verification: document the objection, consequences, compromise considered and plan, and ensure any permitted disclosure reached the intended clinical recipient.
02Public-interest approachCredible threat of serious harmA patient describes a specific plan to cause serious violence and identifies an intended victim, but refuses consent to share information.+
- 1Assess immediacy, specificity, capability, vulnerability and whether urgent action is needed, involving senior or safeguarding support where practicable.
- 2Consider whether warning the patient, obtaining consent or using less identifying information can mitigate risk without increasing danger.
- 3Disclose necessary information promptly to an appropriate responsible authority when needed to protect against death or serious harm.
- 4Record the risk evidence, balancing, recipient, information disclosed and reason the patient was or was not informed; continue clinical and safety follow-up.
03Request-handling approachPolice request for the complete recordA police officer emails asking for a patient’s entire record to assist an investigation but provides no court order, statutory requirement or patient consent.+
- 1Verify the officer and request through an approved channel, and ask for the precise purpose, legal authority and information required.
- 2Do not assume police status creates blanket entitlement; seek information-governance or legal advice and identify whether disclosure is required, permitted or unjustified.
- 3If disclosure is lawful and necessary, provide only relevant information securely and tell the patient when practicable unless that would undermine the purpose.
- 4Record the decision and retain the request and response according to organisational policy, including reasons for refusing or narrowing it.
05Feedback, follow-up and evidenceReview outcomes, seek feedback and identify what to improve.
- Confirm receipt of urgent disclosures and correct misdirected or incomplete information promptly; a technically sent message does not prove safe communication.
- Review access logs, misdirected correspondence, inappropriate browsing and near misses, escalating suspected breaches through local information-governance and regulatory processes.
- Tell patients about unexpected disclosures unless impracticable or likely to undermine the purpose, and keep privacy information current for routine processing.
- Use case review to test whether staff distinguished direct care, safeguarding, legal compulsion and secondary use, and whether disclosed information was truly minimal and sufficient.
06Special situationsVariants, exceptions and circumstances that change the usual approach.
The duty to share matters
Over-cautious withholding can harm patients when a direct-care team lacks relevant, current information. Confidentiality requires controlled, justified sharing as well as protection from improper disclosure.
Consent has several meanings
Consent to treatment, agreement to confidential disclosure and consent as a data-protection lawful basis are distinct. Name which question is being answered and document the applicable authority.
Public interest requires specificity
Identify the threatened harm, why disclosure is necessary, why the recipient can reduce it and what minimum information is sufficient. Vague anxiety does not justify indiscriminate disclosure.
Posthumous privacy persists
Confidentiality continues after death. Consider the deceased’s wishes, third-party information, statutory access rights and the purpose and likely effect of disclosure; a relative’s status alone is not authority.
07Common pitfallsFrequent interpretation and management errors.
- 01
Saying “GDPR prevents sharing” without analysing direct-care need, legal authority, serious-harm risk and the actual minimum information required.
- 02
Using explicit consent as the UK GDPR basis for routine healthcare processing when another basis more accurately reflects the relationship and purpose.
- 03
Sending a complete record because part is relevant, or using an unverified email address, personal device or informal group chat for convenience.
- 04
Recording only that information was shared, without recipient, purpose, authority, content, advice or whether the patient was told.