Upskilling Academy
Trusted by 3 million learners 24/7 online training Money back guarantee Fully accredited courses

The Caldicott Principles are eight principles used in health and social care to help organisations and workers use confidential information appropriately. They require organisations to justify why information is needed, use only what is necessary, restrict access, comply with the law, share relevant information when required for care and explain clearly how people’s information is used.

They are particularly important within the NHS and adult social care because professionals routinely handle highly sensitive information about health, treatment, disability, family circumstances and care needs.

The principles do not replace the UK GDPR, Data Protection Act 2018 or common law confidentiality. Instead, they provide an ethical and practical framework for applying those obligations to real health and care decisions.

Understanding the Caldicott Principles

A simple Caldicott principles definition is:

The Caldicott Principles are eight good-practice principles designed to ensure confidential health and social care information is protected, used only when justified and shared appropriately when necessary for care.

The National Data Guardian says they apply to confidential information used within health and social care organisations and when that information is shared between organisations or individuals.

The purpose of Caldicott principles is therefore not merely to prevent disclosure.

They are intended to create a balance between two important responsibilities:

  • protecting people’s confidential information; and
  • ensuring relevant information is available when appropriate sharing is necessary for safe and effective care.

That balance is particularly clear in Principle 7.

What Is Patient-Identifiable and Confidential Information?

Older Caldicott material often referred to patient-identifiable information or personal confidential data.

Current National Data Guardian wording uses the broader expression confidential information.

This can include information such as:

  • a person’s name and address;
  • NHS or other health identifiers;
  • symptoms;
  • diagnoses;
  • medicines;
  • treatment history;
  • test results;
  • care needs;
  • mental-health information; and
  • social-care information.

Information does not necessarily need to contain someone’s name to be identifiable.

If a person can reasonably be identified from the information itself or by combining it with other available information, UK data-protection law may still treat it as personal data.

Health information about an identifiable living person is generally special-category personal data, which receives additional legal protection under the UK GDPR.

The Caldicott Principles are concerned particularly with information people would reasonably expect health or social care services to keep private.

The History and Development of the Caldicott Principles

Where Did the Caldicott Principles Come From?

The Caldicott principles history begins with concerns about how patient information was being used and transferred within the NHS.

A review chaired by psychiatrist Dame Fiona Caldicott examined patient-identifiable information and reported in December 1997.

The original review established six principles for determining when identifiable patient information should be used and how it should be protected. It also recommended that senior individuals within health organisations should take responsibility for protecting confidentiality—the origin of the Caldicott Guardian role.

Why Were the Caldicott Principles Introduced?

The answer to why were the Caldicott principles introduced is primarily information governance.

Health services need information to:

  • provide treatment;
  • coordinate care;
  • manage services;
  • investigate problems;
  • conduct legitimate research; and
  • protect public health.

But unnecessary access or disclosure can seriously affect privacy and public trust.

The principles were therefore designed to ensure organisations could demonstrate why identifiable confidential information was needed and limit its use accordingly.

How Many Caldicott Principles Are There?

There are currently eight Caldicott Principles.

The timeline is:

YearDevelopment
1997Original six principles introduced
2013Seventh principle added, emphasising that appropriate sharing can be as important as confidentiality
2020Principles revised and eighth principle added on transparency and informing patients/service users

The eighth principle was introduced partly to strengthen the expectation that people should understand how and why their information is being used.

The 8 Caldicott Principles Explained

The current 8 Caldicott principles are set out by the National Data Guardian.

Principle 1: Justify the Purpose(s) for Using Confidential Information

An organisation should be able to explain why confidential information is being accessed, used or shared.

A proposed use should have a clear purpose.

For example, a hospital wanting to transfer information to another clinical team should understand:

  • what information is needed;
  • why the receiving team needs it;
  • what outcome the sharing supports; and
  • whether that use remains justified over time.

Routine information flows should not continue indefinitely simply because “we have always done it this way”.

The National Data Guardian says each proposed use or transfer should be clearly defined, scrutinised, documented and reviewed where appropriate.

Principle 2: Use Confidential Information Only When Necessary

Before using identifiable information, staff should ask whether the purpose could be achieved without using confidential information at all.

For example, an organisation producing general service statistics might not need identifiable patient records if genuinely anonymised figures are sufficient.

This principle encourages organisations to consider less intrusive alternatives.

The central question is:

Do we actually need confidential information to achieve this purpose?

If the answer is no, it should not be used.

Principle 3: Use the Minimum Necessary Confidential Information

Sometimes confidential information genuinely is necessary.

Even then, an organisation should use only the minimum amount needed.

For example, if a professional only needs to know whether someone has a particular allergy, there may be no justification for giving them access to the person’s entire medical history.

This principle closely resembles the UK GDPR concept of data minimisation: organisations should avoid collecting or using information simply because it might be useful someday.

The National Data Guardian requires each item of confidential information used to be justifiable.

Principle 4: Access Confidential Information on a Strict Need-to-Know Basis

Not everybody working within an organisation needs access to every record.

Access should be restricted according to what someone needs for their role.

For example:

A receptionist may need access to appointment information.

A clinician may need access to clinical notes.

A finance employee may need billing information.

That does not automatically mean each person should be able to see every part of the patient’s record.

Practical controls may include:

  • role-based system permissions;
  • restricted folders;
  • secure login credentials;
  • audit trails; and
  • separation of information flows.

The principle is straightforward:

Access should follow genuine need, not curiosity, seniority or convenience.

Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities

Confidentiality is not only the responsibility of doctors, nurses or information-governance teams.

Anyone who handles confidential information needs to understand what is expected of them.

That can include:

  • clinical staff;
  • care workers;
  • administrators;
  • managers;
  • contractors;
  • volunteers; and
  • temporary staff.

Organisations therefore need suitable policies, induction, training and supervision.

For example, an employee should know that discussing identifiable patient details in a public corridor, accessing records without a work-related reason or sending confidential information insecurely may breach organisational policy and potentially legal duties.

NHS England’s current confidentiality policy places responsibility on everyone handling confidential information to understand and protect it.

Principle 6: Comply with the Law

The Caldicott principles confidentiality framework does not replace legal requirements.

Every use of confidential information must also be lawful.

Relevant legal and regulatory considerations can include:

  • UK GDPR;
  • Data Protection Act 2018;
  • Data (Use and Access) Act 2025 amendments;
  • common law duty of confidentiality;
  • Health and Social Care legislation;
  • Human Rights Act considerations;
  • professional regulatory rules; and
  • specific statutory duties or powers to disclose information.

For health information about living individuals, an organisation generally needs a lawful basis under Article 6 of the UK GDPR and, because health information is special-category data, a relevant Article 9 condition as well.

The Data Protection Act 2018 supplies additional UK-law conditions for some forms of special-category processing.

Principle 6 therefore acts as a reminder that good intentions do not make unlawful information use acceptable.

Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Patient Confidentiality

This principle was added after the 2013 Caldicott review.

It addresses an important problem: excessive caution about confidentiality can itself cause harm.

Imagine an emergency department receives a patient who is taking medication that creates a serious interaction risk.

If another care provider has relevant information and appropriate sharing is lawful and necessary for the person’s treatment, refusing to share simply because “information is confidential” could jeopardise care.

Principle 7 therefore emphasises that health and social care professionals should feel able to share relevant information appropriately when this is in the interests of individual care.

It does not mean confidentiality becomes optional.

Sharing still needs to satisfy the other principles and applicable law.

Principle 8: Inform Patients and Service Users How Their Confidential Information Is Used

The eighth principle was introduced in 2020.

It is intended to promote transparency and reduce unexpected uses of confidential information.

Patients and service users should receive accessible and relevant information explaining matters such as:

  • how their information is used;
  • why it is needed;
  • who it may be shared with; and
  • what choices they may have.

The National Data Guardian describes the objective as ensuring there are “no surprises” for patients and service users.

This principle connects particularly strongly with transparency requirements under data-protection law.

Who Do the Caldicott Principles Apply To?

The National Data Guardian says the principles are primarily intended to guide health and social care organisations and their staff when handling confidential patient or service-user information.

They can apply to information used:

  • for individual care;
  • between members of a care team;
  • between organisations;
  • for service management;
  • for planning;
  • for legitimate research; or
  • for other lawful health and social care purposes.

The official National Data Guardian publication formally applies to England. Caldicott Guardians or equivalent information-governance arrangements also operate across Scotland, Wales and Northern Ireland, although the organisational and legal arrangements differ.

Caldicott Principles in Health and Social Care

The Caldicott principles health and social care framework is relevant wherever services handle information that individuals would reasonably expect to remain confidential.

That includes the NHS but is not limited to hospitals or doctors.

Potential settings include:

  • GP services;
  • hospitals;
  • mental-health services;
  • adult social care;
  • community services;
  • local authorities;
  • care providers; and
  • organisations contracted to provide relevant services.

NHS England’s current policy explicitly incorporates the eight principles when handling confidential patient data.

Do the Caldicott Principles Apply to the Deceased?

The answer requires distinguishing data protection from confidentiality.

Under the UK GDPR, information about a deceased person is not personal data because the legislation protects information relating to living individuals.

However, NHS England confirms that the common law duty of confidentiality continues after a patient’s death.

Therefore, confidential records do not become freely available simply because someone has died.

In practice, Caldicott-style considerations around necessity, minimum disclosure, lawful authority and appropriate access remain highly relevant when organisations decide whether deceased-patient information should be used or disclosed.

Separate legislation may also create rights or duties relating to records after death, depending on the circumstances.

What Information Is Covered by the Caldicott Principles?

Examples include information about:

  • symptoms;
  • diagnoses;
  • treatment;
  • prescriptions;
  • disability;
  • mental health;
  • social-care needs;
  • addresses;
  • identifiers; and
  • other information that identifies a patient or service user and would reasonably be expected to remain private.

The principles can sometimes also be relevant to confidential staff information.

Completely anonymised information falls outside much of this confidentiality concern because individuals cannot be identified, although organisations must ensure information is genuinely anonymised rather than merely having names removed.

What Is a Caldicott Guardian?

A Caldicott Guardian is a senior person who helps an organisation make appropriate decisions about confidential health and care information.

The National Data Guardian describes Caldicott Guardians as senior people who protect confidentiality by considering the ethical and legal aspects of information sharing.

The Guardian is sometimes described as the organisation’s conscience for confidentiality and information sharing.

This is different from a Data Protection Officer.

A DPO focuses on compliance with data-protection law.

A Caldicott Guardian provides senior ethical and confidentiality leadership, particularly where complex health and care information-sharing decisions arise.

The two functions often work closely together.

What Does a Caldicott Guardian Do?

Responsibilities can include:

  • advising on difficult confidentiality decisions;
  • supporting appropriate information sharing;
  • promoting the eight principles;
  • advising on disclosures;
  • contributing to investigations of data incidents;
  • helping consider complaints;
  • reviewing relevant policies;
  • providing senior leadership on confidentiality; and
  • helping balance privacy with safe information sharing.

NHS England describes its Caldicott Guardian as providing leadership and informed advice particularly where legal or ethical issues are complex or ambiguous.

Who Needs a Caldicott Guardian?

In England, National Data Guardian guidance applies to public bodies within health, adult social care and adult carer support that handle confidential patient or service-user information.

It also applies to organisations contracted by public bodies to provide relevant health or adult social care services while handling that information.

The statutory NDG guidance must be given due regard by organisations within scope.

It widened the position beyond the earlier model under which NHS organisations and local authorities were the main bodies expected to have Guardians.

Smaller organisations may in appropriate circumstances use shared arrangements rather than necessarily appointing a separate full-time Guardian. NHS England, for example, notes that GP practices may be able to share a Caldicott Guardian where appointing one internally is not proportionate.

How Are the Caldicott Principles Applied in Practice?

The principles become most useful when applied to actual information-sharing decisions.

Examples of Applying the Caldicott Principles

Example 1: Sharing information with another clinician

A GP refers a patient to a specialist.

Relevant clinical information is shared because it is necessary for treatment.

The GP does not include unrelated historical information merely because it is available.

This reflects Principles 1, 2, 3 and 7.

Example 2: Staff access to records

A care worker needs access to a resident’s current care plan but does not need unrestricted access to unrelated organisational files.

Role-based permissions limit access.

This reflects Principle 4.

Example 3: Research project

A health organisation considers whether identifiable data is genuinely required.

If anonymised information can achieve the research purpose, identifiable confidential information should not be used unnecessarily.

This reflects Principles 2 and 3.

Example 4: Privacy information

A service publishes accessible information explaining how patient records are used, shared and protected.

This reflects Principle 8.

When Can Confidential Information Be Shared?

Confidential information can sometimes be shared:

With appropriate consent. For direct individual care, implied consent may apply in suitable circumstances where information is being shared within the care team and the person has not objected.

Where the law requires disclosure. A statutory requirement or court order may compel sharing.

Where legislation provides authority. Certain statutory mechanisms can permit processing or disclosure.

Where an overriding public-interest justification exists. This is normally a careful case-by-case assessment.

NHS England identifies consent, legal requirements, statutory powers and overriding public interest among the circumstances capable of permitting confidential-information disclosure.

The Caldicott Principles help determine how much should be shared and whether access is appropriate, but the legal basis must still be identified separately.

Caldicott Principles and Data Protection Law

The relationship between the Caldicott principles and GDPR is complementary.

They are not competing systems.

How Do the Caldicott Principles Relate to UK GDPR?

The UK GDPR contains legally enforceable rules governing personal-data processing.

The Caldicott principles information governance framework provides additional health and social care guidance about appropriate use of confidential information.

Several ideas overlap.

For example:

Caldicott conceptRelated UK GDPR concept
Justify the purposePurpose limitation and lawfulness
Use information only when necessaryNecessity and proportionality
Use the minimum informationData minimisation
Need-to-know accessSecurity and access control
Explain information useTransparency
Comply with lawLawfulness and accountability

The similarities do not make the Caldicott Principles a replacement for data-protection compliance.

An organisation can satisfy a Caldicott principle in spirit but still breach the UK GDPR if it lacks the required lawful basis.

Equally, something technically permitted by data-protection law may still require consideration of the separate common law duty of confidentiality.

NHS England explicitly describes information governance as covering confidentiality, data protection and records management rather than treating them as one identical concept.

What Does the Data Protection Act 2018 Require?

The Caldicott principles and Data Protection Act operate alongside one another.

The Data Protection Act 2018 supplements the UK GDPR.

For health information, this is particularly important because health data is generally special-category data.

An organisation normally needs:

an Article 6 lawful basis for processing personal data; and

an Article 9 condition allowing processing of special-category data.

The UK GDPR contains an Article 9 condition relating specifically to processing necessary for health or social care, subject to its requirements.

Section 10 and Schedule 1 of the Data Protection Act 2018 provide additional UK-law conditions relevant to several Article 9 categories, including health and social care.

The Data (Use and Access) Act 2025 has since amended parts of UK data-protection legislation. All its data-protection provisions were in force by 19 June 2026, but it did not replace either the UK GDPR or the Data Protection Act 2018.

For health and care workers, the practical lesson is straightforward:

Caldicott is one layer of the information-governance framework—not the whole legal framework.

Frequently Asked Questions About the Caldicott Principles

Why Are the Caldicott Principles Important?

The principles help health and care organisations protect confidentiality without preventing appropriate information sharing. They encourage organisations to justify information use, restrict access, minimise unnecessary disclosure and be transparent with patients and service users.

This supports both trust and safe care.

Are the Caldicott Principles Legally Binding?

The eight principles themselves are best described as good-practice information-governance principles, not a standalone Act of Parliament creating a separate offence for breaching “Principle 3” or “Principle 7”.

However, many of the responsibilities they describe overlap with legally enforceable duties under data-protection law, confidentiality law and sector-specific legislation.

There is an additional distinction for Caldicott Guardians: National Data Guardian guidance on their appointment was issued under statutory powers, and organisations to which that guidance applies must give it due regard.

So a failure involving confidential information can have legal or regulatory consequences even though the Caldicott Principles themselves are not a standalone statutory code.

Who Is Responsible for Following the Caldicott Principles?

Responsibility does not rest only with the Caldicott Guardian.

People throughout health and social care who access or use confidential information need to understand their responsibilities.

This can include clinicians, care workers, managers, administrative staff, contractors and other authorised personnel.

The Caldicott Guardian provides leadership and advice, but individual workers remain responsible for handling information appropriately.

What Is the Difference Between the Caldicott Principles and GDPR?

The Caldicott Principles are health and social care information-governance principles concerned with appropriate use and sharing of confidential information.

The UK GDPR is data-protection law governing the processing of personal data across many sectors, not just health and care.

The UK GDPR creates formal legal obligations and rights. Caldicott provides a practical and ethical framework for applying confidentiality and information-sharing principles within health and social care.

What Do the Eight Caldicott Principles Achieve?

The answer to what do the eight Caldicott principles achieve is that they create a structured approach for deciding whether confidential information should be used or shared.

Together, they encourage organisations to:

  • define a legitimate purpose;
  • question whether identifiable information is required;
  • minimise information used;
  • restrict access;
  • train staff;
  • comply with applicable law;
  • avoid harmful under-sharing; and
  • remain transparent with patients and service users.

Do Caldicott Principles Apply to the Deceased?

Confidentiality remains relevant after death.

The UK GDPR does not protect data about deceased individuals, but NHS England confirms that the common law duty of confidentiality continues beyond death.

Health records concerning deceased people therefore should not simply be treated as public information.

Key Takeaways

There are currently eight Caldicott Principles.

They were introduced originally in 1997 to improve the way patient-identifiable information was used within healthcare. The seventh principle, added in 2013, recognises that appropriate sharing can be just as important as protecting confidentiality. The eighth, added in 2020, emphasises transparency with patients and service users.

The principles require organisations to justify information use, avoid unnecessary identifiable data, use the minimum necessary information, restrict access, educate staff, comply with the law, share appropriately for individual care and explain how information is used.

For anyone studying Caldicott principles NHS, confidentiality or information governance, the most important point is that Caldicott does not operate alone.

It works alongside the common law duty of confidentiality, UK GDPR, Data Protection Act 2018 and other relevant health and social care rules.

Used properly, the principles help achieve both sides of good information governance: protect information when it should remain confidential and share it safely when appropriate care requires it.

Subscribe for Course Discounts, Free Resources & Expert Insights

No spam, ever. Just useful updates, exclusive offers, and practical tips.