Dishcover Academy

The Caldicott principles are eight good-practice principles that help health and social care organisations protect confidential information while allowing it to be used and shared appropriately. They provide a practical way to decide why sensitive information is needed, how much should be used, who should have access and when sharing may be necessary.

Quick Overview
The Caldicott principles help health and social care organisations protect confidential information, use only what is necessary, and share information appropriately and lawfully when it is needed for care.

This guide covers:
✅ What the Caldicott Principles are and why they are important
✅ The Caldicott principles definition, purpose and history
✅ The 8 Caldicott Principles and how they guide everyday information handling
✅ What confidential and patient-identifiable information is covered
✅ Who the principles apply to, including health and social care professionals and organisations
✅ The role and responsibilities of a Caldicott Guardian
✅ How the principles support appropriate information sharing while protecting confidentiality
✅ How the Caldicott principles and GDPR work alongside the UK GDPR and Data Protection Act 2018

Understanding what are the 8 Caldicott principles is particularly valuable for people who handle patient or service-user information. The principles recognise that confidentiality matters, but they also make clear that unnecessary secrecy can interfere with safe and effective care.

Understanding the Caldicott Principles

A simple Caldicott principles definition is that they are eight principles for managing confidential information responsibly within health and social care.

The purpose of Caldicott principles is to balance privacy with appropriate information use. Patients and service users should be able to trust organisations with sensitive details, while professionals need access to relevant information to perform their roles. 

This is why Caldicott principles confidentiality is not the same as never sharing information. Appropriate confidentiality means protecting information from unjustified access while allowing proportionate sharing where there is a valid reason. 

Similarly, Caldicott principles information governance covers more than cybersecurity. It concerns why information is collected, who can access it, how it is shared, whether its use is lawful and whether people understand their responsibilities. 

What Is Patient-Identifiable and Confidential Information?

Confidential health and care information can include information that identifies someone directly or enables them to be identified when combined with other information.

Examples include:

  • names, addresses and NHS numbers;
  • diagnoses and medical histories;
  • prescriptions and treatment details;
  • test results;
  • mental health information;
  • care assessments and support needs;
  • identifiable photographs or recordings; and
  • correspondence concerning an individual’s care.

Removing somebody’s name does not necessarily make information anonymous. A combination of age, location, medical condition and treatment details may still identify the person.

Pseudonymised information also remains different from truly anonymised information. With pseudonymisation, identifiers are replaced or separated, but the individual can potentially be identified using additional information. Properly anonymised information no longer identifies an individual by reasonable means.

These distinctions are important when organisations decide whether identifiable confidential information genuinely needs to be used.

The History and Development of the Caldicott Principles

The Caldicott principles history began in the 1990s, when the growing use of electronic records and information sharing across the NHS raised concerns about the handling of patient-identifiable information.

Dame Fiona Caldicott chaired a review of these practices, and six principles were introduced following the review in 1997. 

So, why were the Caldicott principles introduced? The aim was to ensure organisations did not use or transfer sensitive patient information merely because it was available. There needed to be a genuine purpose, necessity and proper control over access. 

As information-sharing practices continued to develop, it became clear that confidentiality needed to be balanced with the practical need to share relevant information appropriately. The framework changed in 2013 after another review led by Dame Fiona Caldicott. Evidence suggested that some professionals were interpreting confidentiality too rigidly and becoming reluctant to share information even where doing so could support better care. 

Principle 7 was therefore added to emphasise that the duty to share information for individual care can be as important as the duty to protect confidentiality. 

The principles were revised again in December 2020, when Principle 8 was introduced. It focuses on informing patients and service users about how their confidential information is used. 

If you are asking how many Caldicott principles are there, the current answer is eight.

The 8 Caldicott Principles Explained

With this historical development in mind, it is easier to understand what the eight Caldicott principles achieve. Together, they provide a structured approach for deciding whether confidential information should be used or shared, why it is needed, who should have access to it and what safeguards should apply.

Principle 1: Justify the Purpose(s) for Using Confidential Information

Every proposed use or transfer of confidential information should have a clearly defined purpose.

An organisation should be able to explain why the information is needed and what it intends to achieve 

For example, sharing relevant information with a specialist treating a patient may be justified because the specialist needs it to provide care. A completely different use of the same information would need its own justification. 

Continuing uses should also be reviewed periodically. Information-sharing arrangements should not continue automatically merely because they have existed for several years. 

Principle 2: Use Confidential Information Only When It Is Necessary

Once a legitimate purpose has been identified, the next step is to consider whether confidential information is genuinely required to achieve that purpose.

If the same objective can be achieved using anonymised, aggregated or otherwise less identifiable information, using identifiable confidential information may not be necessary. This helps organisations avoid unnecessary intrusion into people’s privacy.

For example, a service manager reviewing overall patterns of service use may only need statistical information rather than individual patient names or detailed records.

Principle 2 therefore builds directly on Principle 1. After establishing why information is needed, organisations should consider whether confidential information is actually required at all.

Principle 3: Use the Minimum Necessary

If confidential information is required, only the minimum information necessary for the specific purpose should be used.

This means that having a legitimate reason to access information does not automatically justify accessing an entire record. Organisations and professionals should consider what information is genuinely relevant to the task.

For example, a professional involved in a particular aspect of care may only need specific information relevant to that responsibility rather than unrelated details from a person’s complete record.

Principle 3 therefore develops the reasoning from the first two principles: first establish the purpose, then determine whether confidential information is necessary, and finally limit the information used to what is required.

Principle 4: Access Confidential Information on a Strict Need-to-Know Basis

Confidential information should only be available to people who genuinely need it for their work.

Different staff members have different responsibilities, so they should not automatically receive identical access to patient or service-user records.

Organisations can support this through role-based permissions, secure authentication, audit logs and other access controls.

The principle also applies to individual conduct. An employee should not access the record of a friend, family member, colleague or well-known person simply because they are curious.

Having technical access does not create a legitimate need to know.

Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities

Confidentiality is not solely the responsibility of doctors, senior managers or information-governance teams.

Everyone with authorised access to confidential information should understand their obligations. This can include nurses, care workers, social workers, reception staff, administrators, contractors and managers.

Good practice may involve checking recipients before sending information, protecting passwords, keeping paper documents secure, avoiding conversations where confidential details could be overheard and reporting suspected security incidents.

Training can help people understand these responsibilities, but effective information governance also depends on suitable policies, secure systems, supervision and workplace culture.

Principle 6: Comply with the Law

Every use of confidential information must be lawful.

Depending on the circumstances, relevant requirements may include UK GDPR, the Data Protection Act 2018 as amended, the common law duty of confidentiality and legislation governing specific health or social care activities.

Health information is generally special-category personal data. This means organisations usually need an appropriate lawful basis under Article 6 of UK GDPR and a relevant Article 9 condition, together with any applicable Data Protection Act requirements.

The Caldicott principles do not replace these laws. Instead, they help organisations apply good information-governance practice within the wider legal framework.

Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Confidentiality

The addition of Principle 7 in 2013 highlighted an important balance within information governance.

Protecting confidentiality remains essential, but professionals should not automatically withhold relevant information when sharing it is necessary for an individual’s care and is appropriate to do so.

For example, effective care may depend on relevant information being available to professionals who need it to understand a person’s circumstances, treatment or care needs.

Principle 7 therefore complements the earlier principles. Confidentiality should be protected, but it should not be interpreted in a way that creates unnecessary barriers to appropriate information sharing for individual care.

Principle 8: Inform the Expectations of Patients and Service Users About How Their Confidential Information Is Used

The eighth principle, introduced in 2020, places greater emphasis on transparency.

Patients and service users should be informed about how their confidential information is used, including the purposes for which information may be collected, accessed or shared.

Clear and accessible information can help people understand why their information is needed and how organisations seek to protect it. Transparency can also support trust between individuals and health and social care organisations.

Who Do the Caldicott Principles Apply To?

The Caldicott Principles apply to organisations and professionals who handle confidential health and social care information, helping them protect privacy and share information responsibly. 

Caldicott Principles in Health and Social Care

The Caldicott principles health and social care framework primarily concerns confidential information collected in providing health and social care services where an identifiable patient or service user would expect privacy.

The principles may therefore be relevant to NHS organisations, healthcare professionals, social care bodies, commissioned providers and other organisations handling such information.

References to Caldicott principles NHS practice are common because the framework originated within the NHS. However, its relevance now extends across health and social care more broadly.

The exact governance framework is not necessarily identical across England, Scotland, Wales and Northern Ireland. Organisations should therefore check requirements relevant to their particular jurisdiction.

Do the Caldicott Principles Apply to the Deceased?

A frequent question is: do Caldicott principles apply to the deceased?

A person’s medical information does not automatically become public when they die. Confidentiality can continue after death, meaning health and care records should still be handled carefully.

The Caldicott principles deceased position should be distinguished from UK GDPR. UK GDPR protects personal information relating to living individuals, so it does not apply to a deceased person’s data in exactly the same way.

However, the common law duty of confidentiality can continue after death.

There are also specific rules concerning access. In England and Wales, for example, the Access to Health Records Act 1990 provides particular people with rights to request access to certain records of deceased individuals, subject to conditions and limitations.

Family members should therefore not assume that they automatically have unrestricted access to an entire medical record.

What Information Is Covered by the Caldicott Principles?

The principles are not limited to information held in electronic patient records.

Confidential information can appear in:

  • electronic systems;
  • paper medical or care records;
  • referral documents;
  • emails and messages;
  • care plans;
  • photographs and recordings; and
  • verbal conversations.

What matters is the nature of the information, whether an individual can be identified and whether that person would reasonably expect the information to remain private.

What Is a Caldicott Guardian?

A Caldicott Guardian is a senior person who helps an organisation protect confidential health and care information and ensure it is used appropriately.

Guardians are particularly valuable when difficult ethical, confidentiality or information-sharing decisions arise.

What Does a Caldicott Guardian Do?

A Caldicott Guardian may help an organisation consider:

  • difficult disclosure requests;
  • new information-sharing arrangements;
  • confidentiality policies;
  • novel uses of confidential information;
  • application of the eight principles; and
  • ethical issues surrounding access and sharing.

The Guardian should have enough seniority and influence to challenge an inappropriate proposal when necessary.

However, responsibility for confidentiality does not transfer entirely to the Guardian. Principle 5 makes clear that everyone handling confidential information has responsibilities.

A Caldicott Guardian is also not automatically the same as a Data Protection Officer. The two roles can work closely together, but their functions are different.

Who Needs a Caldicott Guardian?

In England, National Data Guardian statutory guidance applies to specified public bodies in health services, adult social care and adult carer-support services that handle confidential information about patients or service users.

It also applies to organisations contracted by those public bodies to deliver relevant health or adult social care services while handling such information.

It would therefore be misleading to say that every business connected with health or care anywhere in the UK is subject to exactly the same requirement.

Organisations need to determine what applies to their activities and jurisdiction.

How Are the Caldicott Principles Applied in Practice?

The Caldicott Principles are applied in practice by helping health and social care professionals make responsible decisions about using, accessing and sharing confidential information. 

Examples of Applying the Caldicott Principles

Imagine a patient is discharged from hospital and requires support from a community nursing team.

There is a clear reason for sharing relevant information: continuity of care.

Some identifiable information is necessary because the community team must know which patient it is supporting. However, that does not mean the complete hospital record needs to be transferred.

Relevant information should be selected, shared securely and made available only to appropriate professionals.

Now consider a different situation. A health service wants to calculate the average waiting time for appointments.

The organisation may require appointment dates and statistical information but not patient identities or complete clinical histories. Anonymous information may therefore be sufficient.

These examples demonstrate how the principles encourage proportional decision-making.

When Can Confidential Information Be Shared?

There is no universal rule that confidential information can only be shared when explicit consent has been obtained.

Depending on the circumstances, sharing may be appropriate for individual care, safeguarding, statutory requirements or other properly justified purposes.

Before sharing information, staff should consider:

  1. What is the purpose?
  2. Does the individual need to be identified?
  3. What is the minimum information required?
  4. Does the recipient genuinely need the information?
  5. Is the disclosure lawful and consistent with confidentiality obligations?
  6. Is the method of sharing secure?
  7. Has the person been appropriately informed?

Where the decision is unusual or difficult, staff should follow organisational procedures and seek advice from an appropriate information-governance professional or Caldicott Guardian.

Caldicott Principles and Data Protection Law

The Caldicott Principles work alongside data protection law to help health and social care organisations protect confidential information and ensure it is used and shared lawfully and appropriately. 

How Do the Caldicott Principles Relate to UK GDPR?

The relationship between Caldicott principles and GDPR is complementary rather than interchangeable.

UK GDPR forms part of the legal framework governing personal information. The Caldicott principles are good-practice principles focused specifically on confidential health and social care information.

There are important areas of overlap.

Principle 3’s emphasis on using the minimum necessary information closely resembles the data-minimisation principle. Principle 8’s focus on explaining information use complements transparency requirements.

However, complying with Caldicott does not automatically establish compliance with UK GDPR.

A responsible Caldicott principles data protection approach therefore considers both frameworks.

What Does the Data Protection Act 2018 Require?

The relationship between Caldicott principles and Data Protection Act requirements is particularly important when processing health information.

Health data is normally special-category personal data. An organisation generally needs a lawful basis under Article 6 of UK GDPR as well as an applicable Article 9 condition. Some Article 9 conditions also require additional conditions or safeguards under Schedule 1 of the Data Protection Act 2018.

The legal framework has also changed since the Data Protection Act was introduced.

The Data (Use and Access) Act 2025 amended UK data-protection law, and all of its data-protection provisions were in force by June 2026.

Organisations should therefore consult current legislation and ICO guidance rather than relying entirely on older materials describing the original 2018 framework.

Frequently Asked Questions About the Caldicott Principles

Why Are the Caldicott Principles Important?

They help organisations protect highly sensitive information while avoiding unnecessary obstacles to appropriate information sharing. They provide staff with a practical framework for considering purpose, necessity, access and proportionality.

Are the Caldicott Principles Legally Binding?

The eight principles are good-practice principles rather than eight separate statutory provisions. However, they operate alongside legal requirements, and specified organisations in England must give due regard to statutory National Data Guardian guidance concerning Caldicott Guardians.

Who Is Responsible for Following the Caldicott Principles?

Everyone handling relevant confidential information has responsibilities. This includes health and social care professionals, administrative staff, managers and other authorised people.

What Is the Difference Between the Caldicott Principles and GDPR?

UK GDPR is data-protection legislation covering personal-data processing generally. The Caldicott principles focus particularly on the responsible use and sharing of confidential health and social care information. An organisation may need to comply with both.

Are There Still Seven Caldicott Principles?

No. There are eight. Six originated in 1997, the seventh was introduced following the 2013 review, and Principle 8 was added in 2020.

Does Confidentiality Mean Patient Information Cannot Be Shared?

No. Principle 7 specifically recognises that sharing relevant information for individual care can be as important as protecting confidentiality.

Is Consent Always Required Before Information Is Shared?

No. Consent is not the only possible basis for legitimate information use or sharing. The correct approach depends on the purpose, applicable law and confidentiality obligations.

Is Pseudonymised Information the Same as Anonymous Information?

No. Pseudonymised information can still be personal data because an individual can potentially be identified using additional information. Truly anonymised information does not identify an individual by reasonable means.

Key Takeaways

The Caldicott principles provide a practical framework for protecting confidential information while enabling appropriate information sharing in health and social care.

There are eight principles. They require organisations and staff to justify why confidential information is needed, avoid using it where unnecessary, use only the minimum amount required, restrict access to people with a genuine need to know, understand their responsibilities, comply with the law, recognise the importance of appropriate sharing for individual care and inform patients and service users about how information is used.

Understanding what are the 8 Caldicott principles therefore requires more than memorising eight headings. Their real value comes from applying them when deciding whether to access, use or disclose sensitive information.

The Caldicott framework must also be considered alongside current legal requirements. Caldicott principles data protection responsibilities interact with UK GDPR, the Data Protection Act 2018 as amended and the common law duty of confidentiality, but these should not be treated as identical frameworks.

Dishcover Academy’s current public course catalogue focuses primarily on culinary education rather than health and social care. Anyone seeking formal training for a healthcare, social care or information-governance role should therefore check the precise course content, assessment arrangements and professional or regulatory recognition of any training they consider. General online learning or a completion certificate should not automatically be treated as a regulated qualification or evidence of workplace competence.

Ultimately, the Caldicott principles promote a balanced approach: protect confidential information carefully, use only what is genuinely needed, share appropriately where good care requires it and make sure people understand how information about them is being handled.

Leave a Reply

Your email address will not be published. Required fields are marked *