Blog Image

What Are the Caldicott Principles? The 8 Principles Explained

Home » Uncategorized » What Are the Caldicott Principles? The 8 Principles Explained

The Caldicott principles are eight important principles that help health and social care organisations protect confidential information while ensuring that information can still be used and shared when there is a legitimate reason to do so. They influence everyday decisions involving medical records, care information, referrals, information sharing, access permissions and communication with patients and service users.

Quick Overview
The Caldicott Principles provide a practical framework for protecting confidential health and social care information while supporting appropriate information sharing. This guide explains the 8 Caldicott Principles, their purpose, practical application, Caldicott Guardians and their relationship with UK data protection law.

This guide covers:
✅ What the Caldicott Principles are and why they are important
✅ The Caldicott principles definition, purpose and history
✅ The 8 Caldicott Principles and how they guide everyday information handling
✅ What confidential and patient-identifiable information is covered
✅ Who the principles apply to, including health and social care professionals and organisations
✅ The role and responsibilities of a Caldicott Guardian
✅ How the principles support appropriate information sharing while protecting confidentiality
✅ How the Caldicott Principles work alongside the UK GDPR and Data Protection Act 2018

Understanding the Caldicott principles is particularly important for anyone who works with sensitive health or care information. Confidentiality does not mean that information should never be shared. Equally, being involved in someone’s care does not automatically justify unrestricted access to everything recorded about them.

The Caldicott principles help professionals find the right balance between protecting confidentiality and sharing information appropriately. They provide a practical framework for deciding why information is needed, whether it is necessary, how much should be shared, who should have access and how patients and service users should be informed.

This guide explains what are the 8 Caldicott principles, why they were developed, who they apply to, how Caldicott Guardians support organisations and how the principles work alongside modern UK data-protection law.

Understanding the Caldicott Principles

A useful Caldicott principles definition is that the Caldicott principles are a set of good-practice principles for deciding when confidential health and social care information should be used, accessed or shared.

The purpose of Caldicott principles is broader than simply preventing disclosure. They encourage organisations to ask a series of practical questions: Why do we need this information? Do we genuinely need information that identifies the person? How much information is necessary? Who needs access? Is the use lawful? Should information be shared for the person’s care? Has the individual been properly informed about how their information may be used?

Together, these questions create a practical framework for responsible information handling. In this way, what do the eight Caldicott principles achieve? They help organisations and professionals balance the need to protect confidentiality with the need to use and share information appropriately for safe and effective care.

This is why Caldicott principles confidentiality should not be interpreted as a rule of total secrecy. In some situations, protecting information is essential. In others, appropriately sharing relevant information may be necessary to provide safe and effective care.

Similarly, Caldicott principles information governance is not limited to computer security. It concerns why information is used, who can see it, what is shared, how decisions are justified and whether those handling the information understand their responsibilities.

What Is Patient-Identifiable and Confidential Information?

The original Caldicott work frequently used the concept of patient-identifiable information. The current Caldicott principles refer more broadly to confidential information.

Confidential health and care information may include:

  • a patient’s or service user’s name and address;
  • NHS or other identifying numbers;
  • symptoms and diagnoses;
  • medication and treatment information;
  • test results;
  • information about disabilities or care needs;
  • mental health information;
  • details contained within social care assessments;
  • photographs or recordings connected with care; and
  • other information which, alone or when combined with other information, could identify the individual.

Identification does not always require a person’s name to appear.

For example, a document describing an unusual condition, the person’s age, a small geographical area and the hospital providing treatment might make the individual identifiable, even if their name has been removed.

This is why organisations should distinguish carefully between identifiable, pseudonymised and genuinely anonymised information.

Pseudonymisation replaces or separates direct identifiers, but the individual may still be identifiable if additional information is available. Proper anonymisation goes further, so that the person is no longer identifiable by reasonable means. This distinction matters because genuinely anonymised information is treated differently from identifiable personal data.

Confidentiality also depends on context. Information provided to a doctor, nurse, social worker or care organisation is often given in circumstances where the person reasonably expects privacy. It should therefore not be treated casually merely because an employee can technically access it.

The History and Development of the Caldicott Principles

The Caldicott principles history began in the 1990s, when the increasing use of information technology and the greater movement of patient information across the NHS created concerns about how identifiable information was being handled.

A review was undertaken under the chairmanship of Dame Fiona Caldicott. The resulting 1997 report examined the use and transfer of patient-identifiable information and produced six original principles.

So, why were the Caldicott principles introduced?

The central concern was that identifiable information should not be used or transferred simply because it was available. Organisations needed to justify its use, limit unnecessary identification, minimise the information involved and control access.

The original framework was therefore designed to create a more disciplined approach to confidentiality within the NHS.

The principles did not remain unchanged.

In 2013, another major review of information governance considered how health and social care professionals were approaching confidentiality and information sharing. One concern was that fear of breaching confidentiality could itself prevent appropriate sharing required for good care.

A seventh principle was consequently added, recognising that the duty to share information for individual care can be just as important as the duty to protect confidentiality.

The framework changed again in December 2020. The wording of the existing principles was revised and Principle 8 was introduced. It requires organisations to inform patients and service users about how their confidential information is used.

The objective is often described as avoiding “surprises”. People should normally understand what organisations are doing with confidential information about them and what choices may be available.

If someone asks how many Caldicott principles are there today, the answer is therefore eight. The Caldicott principles have developed over time to reflect changes in health and social care, technology and information-sharing practices while maintaining their central focus on responsible use and protection of confidential information.

The 8 Caldicott Principles Explained

To understand what do the eight Caldicott principles achieve, it helps to view them as a sequence of practical checks.

First, establish the purpose. Then ask whether identifiable confidential information is necessary. If it is, minimise what is used and restrict access. Make sure everyone understands their responsibilities and that the activity is lawful. At the same time, do not prevent necessary information sharing for individual care, and keep patients and service users appropriately informed.

The Caldicott principles therefore provide a practical framework for balancing the protection of confidential information with appropriate information sharing. They form an important part of Caldicott principles information governance and help organisations make responsible decisions about how confidential information is handled.

Principle 1: Justify the Purpose(s) for Using Confidential Information

The first principle requires every proposed use or transfer of confidential information to have a clearly defined and justifiable purpose.

Organisations should not collect, access or circulate information merely because it may become useful at some point. Instead, they should be able to explain what the information is being used for and why that purpose justifies the proposed activity.

For example, a hospital may need to share information with another provider because a patient is being transferred for specialist treatment. The purpose is clear and directly connected with the patient’s care.

A different situation might involve using patient information for research, service evaluation or planning. These purposes may also be legitimate, but the fact that information would be useful does not automatically justify using identifiable confidential information.

Principle 1 also encourages organisations to review ongoing uses of confidential information. An information-sharing arrangement created several years ago should not simply continue indefinitely without scrutiny. Services change, technology develops and information that was once considered necessary may no longer be required.

Good practice therefore involves documenting important information flows and reviewing whether their purposes remain valid and justified.

Principle 2: Use Confidential Information Only When Necessary

Once an organisation has established a legitimate purpose, it should ask a second question: does it actually need confidential information to achieve that purpose?

Sometimes the answer will be yes. A doctor treating an individual will often need identifiable medical information. A pharmacist dispensing medication will need sufficient information to ensure that the medication is supplied safely to the correct person.

However, many other activities may be possible without using identifiable information.

Suppose managers want to know how many people received a particular service during a particular month. They may need statistics, but they may not need individual names or complete patient records.

The principle encourages organisations to consider less intrusive alternatives. Could anonymised information achieve the same objective? Could the information be aggregated? Could identifiers be removed before analysis?

If the purpose can reasonably be fulfilled without confidential identifiable information, that is generally the preferable approach.

Principle 3: Use the Minimum Necessary Confidential Information

Principle 2 asks whether confidential information is required at all. Principle 3 asks how much information is required.

These are related but separate questions.

Where identifiable confidential information is genuinely necessary, only the minimum amount needed for the particular task should be used.

Imagine that an occupational therapist needs particular information about a person’s mobility restrictions before visiting them at home. Access to relevant information about mobility and care needs may be justified. Access to unrelated medical history from many years ago may not be necessary.

The same principle can apply when information is shared externally. If another organisation needs confirmation of a particular fact, supplying an entire clinical record may be disproportionate.

The focus should therefore be on the individual items of information being used or shared. Each significant item should have a clear reason for being included.

This minimisation also reduces risk. The less unnecessary information that is copied, transferred or accessed, the less information could be exposed if something goes wrong.

Principle 4: Access Confidential Information on a Strict Need-to-Know Basis

Confidential information should not be available to everyone simply because they work for the same organisation.

Access should correspond to genuine responsibilities and legitimate tasks.

A receptionist, pharmacist, consultant, physiotherapist, social worker, records administrator and IT specialist may all work within or for health and care services, but their information needs are different.

Principle 4 therefore supports access controls based on roles and legitimate tasks.

For electronic systems, practical measures may include role-based permissions, authentication requirements and audit logs. Paper information may require secure storage and controlled distribution.

The need-to-know principle also applies to human behaviour. A staff member must not access the record of a relative, neighbour, celebrity or colleague out of curiosity. Being technically able to open a record does not create a professional need to view it.

The principle can also require information flows to be separated. If the same dataset is being used for several functions, different recipients may need access to different parts rather than everyone receiving the entire dataset.

Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities

Confidentiality cannot be protected through policies alone. People need to understand what is expected of them.

This responsibility applies far beyond doctors and senior managers. Depending on the organisation, confidential information may be handled by nurses, care workers, social workers, administrative staff, receptionists, contractors, temporary staff, volunteers, records teams and others.

Relevant awareness may include:

  • protecting passwords and authentication details;
  • checking recipients before sending information;
  • avoiding inappropriate conversations in public areas;
  • storing physical records securely;
  • recognising phishing and other security risks;
  • following procedures when working remotely;
  • reporting suspected information incidents;
  • understanding when information sharing is permitted or required; and
  • seeking advice when a decision is uncertain.

Training can help establish this knowledge, but completing training is not the same as demonstrating that every real-world situation has been handled correctly.

Organisations also need appropriate policies, supervision, secure systems and an information-governance culture in which staff feel able to ask questions and raise concerns.

Principle 6: Comply with the Law

The Caldicott principles operate alongside the law rather than replacing it. Every use of confidential information must be lawful.

Depending on the circumstances, relevant rules may include UK data-protection legislation, the common law duty of confidentiality, legislation specifically governing health or social care information, statutory disclosure requirements and professional obligations.

For personal data, organisations may need to consider the UK GDPR and the Data Protection Act 2018, as amended by subsequent legislation, including the Data (Use and Access) Act 2025.

Where health information is being processed, it will commonly constitute special-category personal data. Organisations therefore need an appropriate Article 6 lawful basis and a relevant Article 9 condition. In certain circumstances, additional provisions of the Data Protection Act 2018 may also apply.

However, data protection and confidentiality are related rather than identical concepts. An activity being permitted under data-protection legislation does not automatically answer every question about the common law duty of confidentiality.

Organisations therefore need to consider all relevant legal and professional requirements. Principle 6 is crucial because the other seven principles should never be interpreted as permission to ignore applicable law.

Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Patient Confidentiality

Principle 7 addressed an important misunderstanding that had developed around confidentiality.

Good Caldicott principles confidentiality practice does not mean refusing to share information whenever there is uncertainty. Health and social care increasingly involves teams of professionals, and information may need to move between a GP, hospital department, community nurse, pharmacist, social worker or care provider so that an individual receives safe and coordinated care.

If relevant information is unnecessarily withheld, the consequences may include duplicated treatment, missed risks, medication errors or poorly coordinated support.

Principle 7 therefore gives professionals a framework for sharing confidential information appropriately where this is necessary for individual care.

However, this does not cancel Principles 1 to 6. Sharing should still have a proper purpose, be necessary and proportionate, be restricted to appropriate recipients and comply with the law.

The principle is not “always share”. Instead, it means that unnecessary fear of confidentiality should not prevent appropriate information sharing for individual care.

Principle 8: Inform Patients and Service Users How Their Confidential Information Is Used

The eighth Caldicott principle places greater emphasis on transparency.

People should have clear and accessible information about how organisations use their confidential information, why information may be shared and what choices they may have.

This information should be accessible and relevant rather than hidden within complex legal wording.

Appropriate methods might include privacy information, patient leaflets, website notices, explanations during care or more direct engagement where a use is unusual or particularly significant.

The level of communication should reflect the circumstances. Routine information use supporting ordinary care may require a different approach from a new, unexpected or complex use involving external organisations.

Principle 8 does not mean that explicit consent must be obtained for every use of confidential information. Consent is only one possible basis within the wider legal and confidentiality framework.

Instead, the principle promotes transparency. People should not unnecessarily discover after the event that their confidential information has been used in a way they could not reasonably have anticipated.

If you are asking how many Caldicott principles are there, there are currently eight Caldicott principles.

The Caldicott principles have evolved in response to changes in healthcare, technology and information-sharing practices. Their central purpose remains the same: to help organisations protect confidential information while ensuring that it can be used and shared appropriately when there is a genuine and legitimate need.

Who Do the Caldicott Principles Apply To?

The Caldicott Principles apply to organisations and professionals who handle confidential health and social care information, helping them use and share information responsibly, securely and appropriately. 

Caldicott Principles in Health and Social Care

The Caldicott principles health and social care framework is designed primarily for organisations and people who handle confidential information collected in connection with health and social care services.

This can include NHS bodies, healthcare professionals, adult social care organisations, commissioned providers and other organisations that handle relevant confidential information.

The National Data Guardian states that the principles are intended to apply to information collected for the provision of health and social care services where patients or service users can be identified and would reasonably expect the information to remain private.

In some circumstances, the Caldicott principles may also be relevant when staff information is processed.

References to Caldicott principles NHS practice are common because the framework originated within the NHS. However, the principles are now relevant more broadly across health and social care.

There is, however, an important distinction across the UK. The National Data Guardian’s statutory guidance on Caldicott Guardians specifically applies in England. Scotland, Wales and Northern Ireland have their own health systems and information-governance arrangements. The Caldicott principles may be recognised and used more widely, but organisations should check the specific legislation, guidance and governance requirements that apply in their own jurisdiction rather than assuming that all UK arrangements are identical.

Do the Caldicott Principles Apply to the Deceased?

A frequent question is: do Caldicott principles apply to the deceased?

Confidentiality does not simply disappear when someone dies. Health and care records relating to deceased individuals can remain subject to confidentiality obligations, and the Caldicott principles can remain relevant when decisions are made about their use or disclosure.

The Caldicott principles deceased position should be distinguished from UK GDPR. UK data-protection legislation generally protects information relating to living individuals. As a result, information relating solely to a deceased person does not constitute their personal data for UK GDPR purposes in the same way as information about a living patient.

Nevertheless, the common law duty of confidentiality can continue after death.

There may also be specific legislation governing access to health records. In England and Wales, for example, the Access to Health Records Act 1990 provides certain rights concerning the health records of deceased people to specified individuals, subject to applicable limitations.

This does not mean that every family member automatically has an unrestricted right to obtain a deceased person’s complete medical record. The circumstances of the request, the requester’s legal position, any known wishes of the deceased and other relevant confidentiality considerations may need to be examined.

Information about a deceased person may also contain information about living individuals, creating additional privacy and confidentiality considerations.

What Is a Caldicott Guardian?

A Caldicott Guardian is a senior person who supports an organisation in protecting confidential health and care information and ensuring that it is used and shared appropriately.

The Guardian provides particular expertise where legal, ethical and practical questions about confidentiality and information sharing intersect. This is especially valuable when a decision is unusual, sensitive or difficult.

A straightforward information flow may already be covered by established organisational procedures. However, a new research project, unusual disclosure request, complex multi-agency arrangement or controversial use of information may require more careful consideration. The National Data Guardian recommends involving a Caldicott Guardian when a novel or difficult judgement is required.

The role can also be relevant when considering information about deceased individuals. Caldicott principles deceased information remains an important consideration because confidentiality obligations can continue after a person’s death, even though UK GDPR generally applies to information about living individuals.

What Does a Caldicott Guardian Do?

The exact responsibilities depend on the organisation, but the role commonly involves advising on confidentiality, information sharing and the appropriate use of health and care information.

A Caldicott Guardian may contribute to:

  • difficult disclosure decisions;
  • new information-sharing arrangements;
  • confidentiality policies;
  • organisational information-governance discussions;
  • reviewing information flows;
  • helping staff understand and apply the Caldicott principles;
  • advising senior leadership about confidentiality issues;
  • promoting appropriate rather than excessive restrictions on information sharing; and
  • ensuring that ethical considerations remain visible alongside legal compliance.

A Guardian should have sufficient authority to challenge inappropriate practices.

For example, if a proposed project requests a large amount of identifiable information, the Guardian might question whether all of it is necessary. The Guardian may also consider whether the purpose could be achieved using less information or information that does not identify individuals.

At the same time, a Guardian should not become an obstacle to appropriate care. The role includes supporting lawful and ethical information sharing when it is genuinely needed.

Caldicott Guardian and Data Protection Responsibilities

A Caldicott Guardian should also be distinguished from a Data Protection Officer (DPO).

The relationship between the Caldicott principles and GDPR is important because both frameworks can affect decisions about the use and sharing of health and care information. However, they are not the same.

A Data Protection Officer has specific responsibilities within the data-protection framework where the UK GDPR requires an organisation to appoint one. A Caldicott Guardian focuses particularly on confidential health and care information and the ethical and information-governance considerations surrounding its use and sharing.

An organisation may therefore have both roles, and they may work closely together. However, appointing a Caldicott Guardian does not transfer data-protection responsibilities away from other staff or remove the organisation’s legal obligations.

Who Needs a Caldicott Guardian?

In England, the National Data Guardian has issued statutory guidance on the appointment, role and responsibilities of Caldicott Guardians.

The guidance applies to public bodies in the health service, adult social care and adult carer-support sectors in England that handle confidential information about patients or service users. It also extends to organisations contracted by public bodies to deliver relevant health or adult social care services where they handle that confidential information.

Organisations within the scope of the guidance must give due regard to the statutory guidance.

This is more precise than saying that “every healthcare business in Britain must appoint a Caldicott Guardian”. Requirements depend on the organisation, its functions and the jurisdiction in which it operates.

Organisations outside the direct scope may still decide that establishing a Caldicott function or appointing a suitable Guardian would be good practice.

Ultimately, the Caldicott Guardian’s role is to help an organisation apply the Caldicott principles in practical situations, particularly where confidentiality, appropriate information sharing, ethical considerations and legal requirements need to be considered together.

How Are the Caldicott Principles Applied in Practice?

The Caldicott principles become easier to understand when they are applied to realistic, everyday decisions involving confidential health and social care information.

Examples of Applying the Caldicott Principles

Consider a patient being discharged from hospital who requires community nursing support.

The hospital needs to transfer appropriate information to the community team so that continuing care can be provided safely.

  • Principle 1 asks why the information is being shared: the purpose is to support continuing care.
  • Principle 2 asks whether confidential information is necessary. Because the community team needs to know which individual is receiving care, some identifiable information will clearly be required.
  • Principle 3 limits the information shared to what the receiving team genuinely needs.
  • Principle 4 means the information should be accessible only to people with a legitimate need to know.
  • Principle 5 requires staff in both organisations to understand their confidentiality responsibilities.
  • Principle 6 requires the sharing arrangement to comply with the law.
  • Principle 7 reminds professionals that confidentiality should not be used as a reason to withhold information that is genuinely needed for the patient’s care.
  • Principle 8 supports informing patients about how their confidential information is used and shared across services.

Now consider a second example. Managers want to examine whether waiting times for a service are improving.

They may need information about appointment dates and service performance, but they may not require complete, identifiable medical records. Principles 2 and 3 would encourage them to consider whether aggregate, anonymised or otherwise minimised information could achieve the same purpose.

A third example could involve an employee accidentally emailing care records to the wrong recipient.

The problem does not simply concern computer security. Principle 5 is relevant because everyone handling confidential information needs to understand their responsibilities. Principle 4 may also raise questions about how access and distribution were controlled. Principle 6 requires consideration of applicable legal obligations and the organisation’s incident-reporting procedures.

These examples demonstrate why the Caldicott principles work together rather than independently. Each principle addresses a different aspect of responsible information handling, from establishing a purpose and limiting access to complying with the law and supporting appropriate information sharing.

When Can Confidential Information Be Shared?

Confidential information can sometimes be shared without obtaining explicit consent on every occasion. The appropriate approach depends on why the information is being shared and the legal and confidentiality framework surrounding the particular situation.

Information sharing may be appropriate for individual care, safeguarding, where legislation requires or permits disclosure, certain public-health purposes, public-interest reasons or other properly justified activities.

The correct question is therefore not simply, “Do we have consent?”

Instead, staff should consider:

  1. What is the purpose of the disclosure?
  2. Is confidential, identifiable information genuinely necessary?
  3. What is the minimum information required?
  4. Does the recipient have a legitimate need to know?
  5. What legal and confidentiality basis supports the sharing?
  6. Is the information being transferred securely?
  7. Has the person been appropriately informed?
  8. Is specialist information-governance or Caldicott Guardian advice needed?

Consent remains important in many situations, but assuming that consent is always necessary can be just as misleading as assuming that it is never required.

Caldicott Principles and Data Protection Law

The Caldicott Principles work alongside data protection law to help organisations protect confidential information while ensuring it is used and shared lawfully, securely and appropriately. 

How Do the Caldicott Principles Relate to UK GDPR?

The relationship between the Caldicott principles and GDPR is sometimes misunderstood. They are not competing versions of the same rules, nor do they serve exactly the same purpose.

The UK GDPR is part of the legal framework governing the processing of personal data. The Caldicott principles are good-practice information-governance principles that focus particularly on the responsible use and sharing of confidential health and social care information.

There are, however, several important similarities.

Principle 3, which requires organisations to use the minimum necessary confidential information, closely aligns with the UK GDPR principle of data minimisation.

Principle 8, which emphasises keeping patients and service users appropriately informed, also complements the data-protection requirement for transparency.

Principle 4, which promotes access on a strict need-to-know basis, supports appropriate security and access controls.

Nevertheless, complying with one framework does not automatically guarantee compliance with the other.

For example, an organisation processing health information will generally need to identify an appropriate Article 6 lawful basis under the UK GDPR. Because health information is special-category personal data, an applicable Article 9 condition will also normally be required.

Depending on the condition relied upon and the circumstances, the Data Protection Act 2018 may impose additional requirements. The organisation must also consider any applicable confidentiality obligations separately.

This is why a responsible Caldicott principles data protection approach involves considering both legal compliance and the ethical and practical questions addressed by the Caldicott principles.

What Does the Data Protection Act 2018 Require?

The Caldicott principles and Data Protection Act framework should not be viewed as static or interchangeable.

The Data Protection Act 2018 supplements the UK GDPR and contains additional provisions concerning the processing of personal data, including certain conditions and safeguards relating to special-category information.

Health information requires particular care because inappropriate use or disclosure can cause significant harm, embarrassment or loss of trust. Organisations handling such information therefore need to establish an appropriate legal basis for processing, apply suitable safeguards, keep information secure and respect applicable individual rights.

The legal position has also evolved since the Data Protection Act 2018 came into force. The Data (Use and Access) Act 2025 amended parts of UK data-protection legislation. By 19 June 2026, the Information Commissioner’s Office (ICO) confirmed that all of the Act’s data-protection provisions were in force.

This means organisations and learners should be cautious about relying on older materials that discuss the UK GDPR and Data Protection Act 2018 as though the legal framework has remained unchanged since 2018.

The core distinction remains important:

The Caldicott principles help health and social care organisations decide how confidential information should be used and shared responsibly. Data-protection legislation establishes legal requirements for the processing of personal data.

Both frameworks may need to be considered alongside the common law duty of confidentiality, professional obligations and other sector-specific requirements.

Understanding the relationship between the Caldicott principles, data protection and the Caldicott principles and data protection act framework can help health and social care organisations make more informed decisions about confidentiality, lawful information use and appropriate information sharing.

Frequently Asked Questions About the Caldicott Principles

Why Are the Caldicott Principles Important?

The Caldicott principles provide a practical framework for making decisions about highly sensitive health and social care information.

Rather than assuming that information should either be freely shared or completely withheld, the principles require organisations to justify the purpose of using information, establish whether it is necessary, minimise the information used, control access, comply with the law and support appropriate information sharing.

They can therefore help protect privacy without unnecessarily preventing safe and effective care.

Are the Caldicott Principles Legally Binding?

The eight principles are primarily good-practice principles rather than eight separate statutory rules that create their own offences.

However, this does not mean that they should be treated as optional in everyday practice. Principle 6 requires compliance with the law, and many activities covered by the principles are also subject to statutory or common law obligations.

In England, the National Data Guardian has also issued statutory guidance on Caldicott Guardians. Organisations within its scope are required to give that guidance due regard.

Who Is Responsible for Following the Caldicott Principles?

Responsibility extends beyond the Caldicott Guardian.

Principle 5 specifically emphasises that everyone with access to confidential information should understand their responsibilities. This may include clinicians, social workers, care workers, administrators, managers, reception staff and other authorised personnel.

Organisations themselves must also establish appropriate governance arrangements, policies, access controls and training to support responsible information handling.

What Is the Difference Between the Caldicott Principles and GDPR?

The UK GDPR is data-protection legislation that applies broadly to the processing of personal data.

The Caldicott principles are a health and social care information-governance framework focused particularly on confidential information.

There is substantial overlap in areas such as data minimisation, security and transparency, but the frameworks are not interchangeable. An organisation handling identifiable health information may need to comply with the UK GDPR, the Data Protection Act 2018, confidentiality obligations and the Caldicott principles at the same time.

Is Consent Always Required Before Patient Information Is Shared?

No.

There are circumstances in which confidential information may appropriately be shared without obtaining explicit consent for every individual disclosure.

The appropriate approach depends on the purpose of the sharing, the nature of the information and the relevant legal and confidentiality requirements. For example, necessary information sharing within a care team may operate differently from using information for an unrelated purpose.

Staff should therefore not assume either that consent is always required or that it is never required.

Can Staff Look at a Patient Record If They Do Not Treat the Patient?

Simply having technical access to a record is not sufficient.

Principle 4 requires access to confidential information on a strict need-to-know basis. A staff member should therefore have a legitimate work-related reason for accessing the information.

Opening a record because the individual is a friend, relative, colleague, neighbour or public figure would not normally provide a legitimate justification.

Do the Caldicott Principles Prevent Information Sharing?

No. This is one of the most important misconceptions about the Caldicott principles.

Principle 7 specifically states that the duty to share information for individual care is as important as the duty to protect confidentiality.

The principles are intended to support appropriate information sharing while preventing unjustified, excessive or unnecessary disclosure.

Are There Six, Seven or Eight Caldicott Principles?

There are currently eight Caldicott principles.

The original framework introduced six principles in 1997. A seventh was added following the 2013 review, and the eighth principle was introduced in 2020.

Older course materials, policies or websites may therefore refer to six or seven principles. Such materials should be checked against the current framework.

Does UK GDPR Apply to a Patient After Death?

UK GDPR generally applies to information concerning living individuals. Therefore, information relating solely to a deceased person is not protected by UK GDPR in exactly the same way as information about a living individual.

However, confidentiality obligations can continue after death.

Health records relating to deceased people should therefore not be assumed to be freely accessible. Other legislation and confidentiality requirements may also govern access to those records.

When Should a Caldicott Guardian Be Consulted?

A Caldicott Guardian can be particularly useful when a decision is novel, difficult or ethically sensitive.

Examples may include an unusual disclosure request, a new information-sharing arrangement, a research proposal involving confidential information or uncertainty about how to balance confidentiality against the need to share information for care.

Routine decisions that are already covered by clear organisational policies will not necessarily require individual Caldicott Guardian involvement.

Key Takeaways

The Caldicott principles provide an important framework for handling confidential health and social care information responsibly.

There are now eight principles. They require organisations and staff to:

  • justify why confidential information is being used;
  • avoid identifiable information where it is unnecessary;
  • use the minimum amount of information genuinely required;
  • limit access to people with a legitimate need to know;
  • ensure that everyone handling confidential information understands their responsibilities;
  • comply with applicable law;
  • recognise that appropriate information sharing for individual care can be as important as protecting confidentiality; and
  • inform patients and service users about how their confidential information is being used.

Understanding what are the 8 Caldicott principles therefore involves more than memorising eight statements. The real purpose is to apply them when making practical decisions about confidential information.

A professional should be able to ask why the information is needed, whether identifying the individual is necessary, how much information should be disclosed, who should receive it and what legal or confidentiality requirements apply.

The framework also highlights an important balance. Poor information protection can damage privacy and trust, but unnecessarily refusing to share information can also interfere with effective care. Good information governance therefore requires both appropriate protection and responsible information sharing.