Concepts
Ethics, law & frameworks/Confidentiality & disclosure · Information governancelow yield

Caldicott & data protection (GDPR)

What it means

The Caldicott principles govern the use of confidential information (justify the purpose; use the minimum necessary; access on a need-to-know basis; everyone aware of responsibilities; comply with the law; the duty to share can be as important as the duty to protect). UK GDPR/Data Protection Act 2018 give the legal framework — lawful basis, data minimisation, patient rights of access.

Worked example

Accessing a patient's record out of curiosity (not for their care) breaches need-to-know and data-protection law — even with no onward disclosure.

In the exam

A clinician looks up the record of a celebrity admitted to another ward, out of curiosity, with no role in their care.

What settles it

Need-to-know access is required even WITHIN an organisation — being employed there doesn't entitle you to any record.

Classically confused with

Duty of confidentiality

Source: Caldicott principles; UK GDPR / DPA 2018