A Complete Guide to the Eight Caldicott Principles 

Rounded teal padlock illustration with 'Caldicott Principles' headline on cream background.

Every day, vast amounts of sensitive data from blood test results to mental health records, flow through the NHS and social care services. The processing of this data is governed by a complex legal framework, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Common Law Duty of Confidentiality. 

But how do we ensure sensitive information is processed lawfully without compromising the privacy of the individuals involved? The answer lies in the Caldicott Principles which serve as the bridge between legal obligations and daily practice.  

This guide will walk you through everything you need to know about these principles, why they exist, and how they protect sensitive data while enabling proper care.  

Whilst it is vital for the proper care of individuals that those concerned with that care have ready access to the information that they need, it is also important that patients and their carers can trust that personal information will be kept confidential and that their privacy is respected.

Why were the Caldicott Principles introduced? 

Surprisingly it was only less than 30 years ago, personal information of individuals relating to their health, medical conditions and treatment received was not considered confidential patient data. In 1997, Dame Fiona Caldicott chaired a committee that addressed the concern about how patient information was being handled in the NHS. The committee produced ‘The Caldicott Committee’s Report on the Review of Patient-Identifiable Information’ and reviewed  the use and transfer of identifiable patient information within health services. Her report introduced the first six principles to guide health and social care organisations when processing data. Over time, as technology and patient needs evolved, two more were added (in 2013 and in 2021). 

The Caldicott Principles provide a clear framework for upholding the Common Law Duty of Confidentiality according to which when someone shares personal information in confidence it must not be disclosed without some form of legal authority or justification. In practice this often means that the information cannot be disclosed without that person’s explicit consent unless there is another valid legal basis. It is the foundation of trust between a service user and a provider. 

What is patient-identifiable information? 

Before exploring the principles, it is important to define what they are protecting: patient-identifiable information. In simple terms, this is any data that could allow a person to be recognised or “singled out,” either directly or indirectly. 

It is a common mistake to think that if you remove a person’s name, the data is suddenly anonymous. In reality, a combination of factors can make a person identifiable, such as: 

  • Full names and home addresses 
  • Dates of birth and NHS numbers 
  • Visual or audio recordings (i.e. photos or videos) 
  • Any other identifying information, for instance specific test results or health conditions which could lead to the identification of the individual 

It is important to note that the Caldicott Principles also apply to information about deceased people, as the Common Law Duty of Confidentiality extends beyond death.  

Caldicott Guardians 

You may be wondering who is responsible for the enforcement and oversight on the eight principles. The answer is to be found in the role played by the Caldicott Guardians, senior individuals in health and social care organisations. According to the Royal College of Psychiatrists, there are over 22,000 Caldicott Guardians. 

Caldicott Guardians act as “the conscience of the organisation”, responsible for protecting the confidentiality of patient and service-user information and enabling appropriate and safe information sharing to improve care. 

While NHS organisations have been required to appoint a Caldicott guardian since 1998, the 2021 National Data Guardian Guidance significantly extended this duty.  

You must check if your organisation falls into the following categories: 

  • Public Bodies: any public body in England exercising functions related to the health service, adult social care, or adult carer support that processes confidential information. 
  • Publicly Funded Providers: any other organisation providing health or adult social care/carer support that is publicly funded, even if the organisation itself is private or a charity (i.e. not a public body) 

Importantly, these organisations are also expected to register the details of their Caldicott Guardians on the Caldicott Guardian Register to ensure transparency and accountability. 

Caldicott Guardians are called to provide leadership and informed guidance on complex matters involving confidentiality and information sharing. Crucially, their approval must be sought for processing patient data for secondary purposes (i.e. purpose other than the delivery of direct care) For instance, when it comes to external research projects to which the organisation is a party. 

The Eight Caldicott Principles explained 

The principles are intended to apply to all data collected for the provision of health and social care services where patients can be identified and where they would expect this to be kept private (i.e. confidential). They are aimed at helping healthcare workers understand exactly when, how and why they can share patient information.  

Let’s break them down with some simple examples to illustrate them. 

Principle 1: Justify the purpose(s) for using confidential information 

“Every proposed use or transfer of confidential information should be clearly defined, scrutinised and documented, with continuing uses regularly reviewed by an appropriate guardian.” 

 For instance, before you look at a file or send an email containing patient identifiable information, you must have a clear, valid and documented reason. 

  • Example: In a specialist referral (e.g. a GP referring a patient to an oncologist), the purpose is always clearly defined: the data is shared specifically to ensure the patient receives expert treatment for a specific suspected condition. 

Principle 2: Use confidential information only when it is necessary 

“Confidential information should not be included unless it is necessary for the specified purpose(s) for which the information is used or accessed. The need to identify individuals should be considered at each stage of satisfying the purpose(s) and alternatives used where possible.” 

In general, you should ask yourself: “Can I do this task without using the patient’s identifiable information?” For instance, if you are performing statistical analysis or conducting general training, you often don’t need to know the identity of the patient. 

  • Example: in the context of a senior doctor training a junior, it is not relevant nor essential to share identifiable information of patients to achieve the clinical objective. The senior doctor should use anonymised or pseudonymised data. They can present the clinical facts, such as the symptoms and test results, while referring to the individual simply as “the patient”. By removing the patient identifiable data, the doctor ensures his student gains the required knowledge without ever compromising the patient’s privacy.

Principle 3: Use the minimum necessary confidential information  

“Where use of confidential information is considered to be necessary, each item of information must be justified so that only the minimum amount of confidential information is included as necessary for a given function.” 

In other words, even if you have a valid and lawful reason to share data, you should only share the specific data required for the task at hand. 

  • Example: if a patient goes to their GP for a chronic heart condition and the GP decides to refer the patient for further evaluation to a cardiologist, it is not necessary for data relating to the patient’s broken foot to be shared, as it is not relevant to their cardiac issue. In other words, only the relevant information needed for the specialist to provide appropriate care should be shared. 

Principle 4: Access to confidential information should be on a strict need-to-know basis 

“Only those who need access to confidential information should have access to it, and then only to the items that they need to see. This may mean introducing access controls or splitting information flows where one flow is used for several purposes.” 

  • Example: a physiotherapist should be able to see the records of the patients they are currently treating, but they should not have access to the records of patients in a completely different hospital unit such as the oncology who they have never met and are not under their care. 

Principle 5: Everyone with access to confidential information should be aware of their responsibilities  

“Action should be taken to ensure that all those handling confidential information understand their responsibilities and obligations to respect the confidentiality of patient and service users.” 

This principle puts the responsibility on the organisation to train its staff. Anyone handling data must understand that they are legally and ethically bound to keep that information private and confidential. 

  • Example: A doctor shall know they must never discuss a patient’s diagnosis in the hospital public spaces where others not involved in the patient’s care might overhear. 

Principle 6: Comply with the law 

“Every use of confidential information must be lawful. All those handling confidential information are responsible for ensuring that their use of and access to that information complies with legal requirements set out in statute and under the common law.” 

  • Example: when a hospital is affected by a data breach (i.e. data is unlawfully accessed by third parties), patients affected shall be informed about the incident, its implications and the measures taken to mitigate it as outlined in the UK GDPR. Specifically, the statute provides that organisations must report personal data breaches to the relevant supervisory authority (i.e. the Information Commissioner Office) within 72 hours. Furthermore, if the breach is likely to affect rights and freedoms of the patients, the law mandates that those individuals be informed in a timely manner. 

Principle 7: The duty to share information for individual care is as important as the duty to protect patient confidentiality 

“Health and social care professionals should have the confidence to share confidential information in the best interests of patients and service users within the framework set out by these principles. They should be supported by the policies of their employers, regulators and professional bodies.” 

If sharing information is vital to saving someone’s life or providing essential care, you should feel empowered to do so. Protection of confidentiality and privacy should not become a barrier to safe treatment. 

  • Example: a GP may deem it appropriate to share a patient’s relevant mental health history with an emergency consultant to ensure safe, immediate treatment in the interest of the patient. 

Principle 8: Inform patients and service users about how their confidential information is used 

“A range of steps should be taken to ensure no surprises for patients and service users, so they can have clear expectations about how and why their confidential information is used, and what choices they have about this. These steps will vary depending on the use: as a minimum, this should include providing accessible, relevant and appropriate information – in some cases, greater engagement will be required.” 

  • Example: a mental health charity has a website where people can sign up for a support group. The sign-up page contains a link to the privacy notice that explains in clear and accessible how names are shared with the group’s organiser. This allows individuals to make an informed decision on their personal data. 

Conclusion 

The Eight Caldicott Principles provide a clear and practical framework for handling sensitive information in health and social care. They help you strike a balance between protecting a patient’s confidential data and providing effective delivery of care. 

Whether you are a clinician, an administrator, or a Caldicott Guardian, the goal remains the same: handle data with integrity, keep it secure, and share it only when it truly benefits the patient and it is not in contrast with legal obligations and requirements. 

At IGS, we help you seamlessly integrate the Caldicott Principles and the Common Law Duty of Confidentiality into your everyday care practices. 

If you would like support reviewing your confidentiality practices, identifying potential information-sharing risks, or upskilling your team with practical training, please contact us at info@informationgovernanceservices.com or 0208 106 7936

Share:

More Posts

Send Us A Message