Skip to main content

BETA This is a new service - your feedback (opens in a new tab) will help us to improve it.

Get an overview of your obligations with the data checklist for developers.

This is required guidance

It is legally required and it is an essential activity.

This Guide covers:

  • England

From:

Developers - Common law duty of confidentiality

Reviewed: 22 January 2023

Reviewed by: Health and Care IG Panel

Common law is a form of law based on previous court cases decided by judges.

The common law duty of confidentiality means that when someone shares confidential information in confidence, you cannot disclose it without some form of legal authority or justification (a ‘legal or lawful basis’ in common law, not to be confused with a legal/lawful basis under UK GDPR).

In practice, this means you’ll need to get explicit consent from a patient before sharing confidential information collected about them when they were receiving care, unless there is another legal basis (also known as ‘setting aside’ the common law duty of confidentiality).

Important note reminder: this form of consent is distinct from UK GDPR consent. If the person has died without giving consent, you cannot receive the information unless another legal basis applies. It is irrelevant how old the person is, or the state of their mental health; the common law duty of confidence still applies.

Before receiving confidential patient or service-user information for your research, therefore, you will need to check that you meet 1 of the following legal bases:

  • Consent, which may be implicit or explicit as follows:
    • Implied consent when no positive action is required (only relevant if you are a member of the direct care team, such that people would have a reasonable expectation of their confidential information being accessed by you)
    • Explicit consent (received from the patient to agree to the information being shared for research purposes)
  • A legal obligation (set out in legislation or otherwise required by law, such as ordered by a judge) requiring the information to be shared
  • Overwhelming public interest (this is exceptional and public interest can rarely provide a legal basis for sharing large volumes of information)
  • A statutory authority or gateway that sets aside the common law duty of confidentiality: for example, support under The Health Service (Control of Patient Information) Regulations 2002 (known as ‘section 251 support’). Applications to process confidential patient information for medical purposes under its regulation 5 will be considered by CAG. CAG reviews applications to set aside the common law duty of confidentiality for research purposes under section 251 of the NHS Act 2006 in circumstances when obtaining consent to share confidential patient information is not practicable. CAG then advises the HRA, which in turn determines whether an application to process confidential information without consent should be approved

For more detailed information on each of these, please read guidance from the NHS Transformation Directorate on consent and confidential patient information.

Important note reminder. The above legal bases relate to the common law duty of confidentiality only. These legal bases are different from the legal bases under UK GDPR. You should refer back to Step 4: Have a lawful basis for processing health and care data to determine which legal basis you should use to process data for research purposes under UK GDPR. You must also still comply with all other relevant legal obligations including data protection legislation and obtaining relevant research approvals before you start your research.

Get an overview of your obligations with the data checklist for developers.

This is required guidance

It is legally required and it is an essential activity.

This Guide covers:

  • England

From:

Get more support

To discover how the HRA can assist you and for contact details, visit our 'Get Support' page.

Is this article useful?

How can we improve this piece?

Error:Select how we can improve this piece
Cancel

Thank you for your feedback!

To share additional insights about this page, please use the following link (opens in a new tab) to submit your observations.

Print this guidance (opens a PDF in a new tab)

Regulations are regularly updated. For the latest information, check the website as printed documents may be outdated.