The Caldicott principles provide a practical framework for protecting confidential information while ensuring it can be used and shared appropriately across health and social care. They are particularly important because effective care depends not only on keeping information private, but also on ensuring that relevant information reaches the right people when it is genuinely needed.
Quick Overview
The Caldicott principles provide a practical framework for protecting confidential health and social care information while allowing it to be used and shared appropriately. They help organisations and staff make informed decisions about necessity, proportionality, access, confidentiality and transparency.
This guide covers:
✅ What the Caldicott Principles are and why they are important
✅ The Caldicott principles definition, purpose and history
✅ The 8 Caldicott Principles and how they guide everyday information handling
✅ What confidential and patient-identifiable information is covered
✅ Who the principles apply to, including health and social care professionals and organisations
✅ The role and responsibilities of a Caldicott Guardian
✅ How the principles support appropriate information sharing while protecting confidentiality
✅ How the Caldicott principles and GDPR work alongside the UK GDPR and Data Protection Act 2018
There are currently eight Caldicott principles. Together, the Caldicott principles address why confidential information is being used, whether identifiable information is necessary, how much information should be disclosed, who should have access to it, and how patients and service users should be informed. This guide explains the principles, their history, their relationship with data protection law, and how they operate in practice.
Understanding the Caldicott Principles
A useful Caldicott principles definition is that they are ethical and information governance principles designed to ensure that confidential health and social care information is used lawfully, appropriately and only to the extent necessary.
The purpose of Caldicott principles is therefore not simply to prevent information from being shared. Instead, the Caldicott principles seek to create an appropriate balance between protecting confidentiality and enabling responsible information sharing that supports individual care and other legitimate health and social care purposes.

If the question is “what do the eight Caldicott principles achieve?”, the answer is that they provide organisations and workers with a structured way of deciding when confidential information should be used, who needs access to it, how much information is required and how patients and service users should be informed about its use.
What Is Patient-Identifiable and Confidential Information?
Confidential health and social care information can include considerably more than a person’s medical diagnosis. It may include information about:
- symptoms, diagnoses and treatment;
- medicines or care plans;
- mental or physical health;
- social care needs;
- names, addresses and contact information; and
- other information that identifies a patient or service user and that they would reasonably expect to remain private.
Information does not necessarily have to contain someone’s name to identify them. A combination of details may be sufficient to make an individual identifiable.
This is why the Caldicott principles require organisations to consider information as a whole when making confidentiality and information-sharing decisions, rather than focusing solely on obvious identifiers.
The History and Development of the Caldicott Principles
The history of the Caldicott principles begins with a review of patient-identifiable information in the NHS, chaired by Dame Fiona Caldicott. The resulting 1997 report introduced six principles and recommended that NHS organisations appoint senior people to oversee the protection and appropriate use of confidential information.
So, why were the Caldicott principles introduced? The original review responded to concerns about how patient-identifiable information was being handled and transferred as information systems within the NHS developed.
The framework was reviewed in 2013. This review added a seventh principle, emphasising that sharing information appropriately can be just as important as protecting confidentiality. This addressed the risk that excessive caution about information sharing could itself interfere with safe and effective care.
A further review resulted in an eighth principle in 2020, focusing on transparency and ensuring that patients and service users understand how their confidential information is used.
This also answers the common question, how many Caldicott principles are there? There are eight Caldicott principles today: six originating from 1997, a seventh added following the 2013 review and an eighth introduced in 2020.
The 8 Caldicott Principles Explained
The Caldicott principles provide a practical framework for protecting confidential information while ensuring that it can be used and shared appropriately. Understanding the Caldicott principles confidentiality requirements is an important part of effective information governance across health and social care.
The principles have developed over time in response to changes in how confidential information is collected, stored, accessed and shared. To understand their current role, it is useful to consider the Caldicott principles history, including why they were introduced and how the framework has evolved.
Principle 1: Justify the Purpose(s) for Using Confidential Information
Every proposed use or transfer of confidential information should have a clear and legitimate purpose.
An organisation should be able to explain why the information is required, what its use is intended to achieve and whether continued use remains justified. Information should not simply continue to be used because it has become part of routine practice.
For example, if a health or social care service proposes to share identifiable patient information for a new project, the purpose should be clearly defined and appropriately scrutinised before the information is used.
This principle is an important part of Caldicott principles information governance, as it encourages organisations to consider the purpose of information use before access or sharing takes place.
Principle 2: Use Confidential Information Only When Necessary
Even where the purpose is legitimate, organisations should consider whether confidential information is actually necessary.
Could the task be completed using anonymised information instead? Could an individual be referred to using a non-identifying code or another appropriate method?
This principle encourages staff to question unnecessary use of confidential information rather than assuming that access to more information is always preferable. It reinforces the wider approach of the Caldicott principles: information should only be used when there is a genuine need for it.
Principle 3: Use the Minimum Necessary Confidential Information
Where confidential information genuinely needs to be used, only the minimum amount necessary for the particular purpose should be included.
This means considering individual data items rather than treating an entire health or care record as a single package of information.
For example, a professional who needs confirmation of a particular condition may not require access to the person’s complete medical history. Limiting the information shared can reduce unnecessary exposure while still allowing the intended purpose to be achieved.
Principle 4: Access Confidential Information on a Strict Need-to-Know Basis
Confidential information should only be available to people who need access to perform their role or fulfil the relevant purpose.
Working for a healthcare or social care organisation does not automatically justify access to every patient or service-user record. Access should be based on a genuine need and appropriate professional responsibilities.
Organisations therefore need effective access controls, role-based permissions and working practices that prevent employees from viewing information simply because a technical system allows them to do so.
This principle demonstrates how Caldicott principles confidentiality requirements work alongside practical information-security and access-management controls.
Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities
Information governance depends heavily on individual behaviour and organisational culture.
Anyone permitted to access confidential information should understand their responsibilities, including when information can be accessed, discussed, recorded, transmitted or shared.
Training is important, but organisations also need effective policies, supervision and clear routes for raising questions or concerns. Workers should know what to do if they are uncertain about a disclosure or believe confidential information has been mishandled.
Clear accountability is an essential part of Caldicott principles information governance, helping ensure that confidentiality responsibilities are understood and applied in day-to-day practice.
Principle 6: Comply with the Law
The Caldicott framework operates alongside the law rather than replacing it.
Depending on the circumstances, relevant legal obligations may arise from the UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality and specific health or social care legislation.
Organisations therefore cannot justify a disclosure solely by saying that it appears consistent with the Caldicott principles. There must also be an appropriate legal basis for processing or sharing personal data, together with consideration of any applicable confidentiality requirements.
This principle is particularly important because the Caldicott framework is part of a wider information-governance landscape. Organisations should consider the relevant legal and regulatory requirements before using or sharing confidential information.
Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Patient Confidentiality
Principle 7 corrects a potentially dangerous misconception: confidentiality does not always mean refusing to share information.
Relevant information may need to be shared between professionals to provide safe, coordinated and effective care. In some circumstances, failing to share important information could place the individual or somebody else at risk.
The key is appropriate and proportionate sharing. Staff should neither disclose information casually nor withhold necessary information simply because they are concerned about breaching confidentiality.
This principle is an important development in the Caldicott principles history because it recognises that protecting confidentiality and sharing information for safe individual care are not necessarily competing objectives.
Principle 8: Inform Patients and Service Users How Their Confidential Information Is Used
Patients and service users should receive appropriate information about how and why their confidential information is used.
The National Data Guardian has emphasised the importance of transparency and avoiding unexpected uses of information. Privacy information should therefore be accessible, relevant and appropriate to the circumstances.

This principle supports transparency and trust. Privacy information should not merely exist somewhere in an organisation’s documentation; people should have a realistic opportunity to understand significant uses of their information and any relevant choices available to them.
A common question is “how many Caldicott principles are there?” There are currently eight Caldicott principles.
The framework originated in the 1997 Caldicott Report, which established six principles. A seventh principle was introduced following the 2013 review, emphasising that the duty to share information for individual care is as important as the duty to protect confidentiality. An eighth principle was subsequently introduced to strengthen transparency around how confidential information is used.
Understanding why were the Caldicott principles introduced requires looking at the development of information systems and the growing need to ensure that patient-identifiable information was handled appropriately. The framework has since evolved to reflect the importance of both protecting confidential information and sharing it responsibly when this supports safe and effective care.
Who Do the Caldicott Principles Apply To?
The Caldicott principles apply to organisations and individuals who handle confidential information in health and social care, including NHS bodies and other relevant care providers.
Caldicott Principles in Health and Social Care
The Caldicott principles health and social care framework is relevant to organisations and staff who handle confidential information about patients and service users.
This includes many NHS bodies, healthcare providers, adult social care organisations and other organisations involved in delivering relevant health and care services.
When people search for Caldicott principles NHS guidance, it is important to remember that the Caldicott principles now extend beyond their original NHS context. Health and social care increasingly involve information being shared between different organisations, so appropriate information governance needs to follow the information wherever it is used or shared.
The exact organisational duties can nevertheless vary between England, Scotland, Wales and Northern Ireland. In particular, the National Data Guardian’s statutory guidance introduced in 2021 requiring certain organisations to appoint Caldicott Guardians applies to England.
Do the Caldicott Principles Apply to the Deceased?
The question “do Caldicott principles apply to the deceased?” requires an important distinction between data protection and confidentiality.
UK data-protection legislation generally protects personal data relating to living identifiable individuals. Information relating solely to someone who has died therefore falls outside the UK GDPR definition of personal data.
However, this does not mean that confidential medical or social care information automatically becomes public after death. Duties of confidentiality and other legal or professional restrictions may still apply.
For this reason, Caldicott principles should still be considered when handling information relating to deceased individuals. Any disclosure should be approached carefully, particularly when deciding whether it is justified and whether the record also contains information about living relatives or other identifiable people.
This means that the question of Caldicott principles and the deceased cannot be answered simply by saying that data-protection law no longer applies. Organisations should consider confidentiality, applicable legislation, professional obligations and the circumstances surrounding the proposed use or disclosure.
What Information Is Covered by the Caldicott Principles?
The Caldicott principles are intended to cover confidential information gathered in connection with health and social care where an individual can be identified and would reasonably expect the information to remain private.
This can include clinical records, social care records, referrals, assessments and communications between professionals. It may also include photographs, recordings and digital information where an individual is identifiable.
Truly anonymised information falls into a different category because the individual is no longer identifiable. Pseudonymised information, however, may still constitute personal data where re-identification remains reasonably possible.
A common question is “what are the 8 Caldicott principles?” The 8 Caldicott principles provide a structured approach to the appropriate use and sharing of confidential information. They cover matters such as justifying the purpose for using information, using information only when necessary, limiting the amount of information used, restricting access, ensuring that people understand their responsibilities, complying with the law, sharing information appropriately for individual care, and being transparent with patients and service users.
What Is a Caldicott Guardian?
A Caldicott Guardian is a senior person who helps an organisation protect the confidentiality of people’s health and care information while ensuring that it is used and shared appropriately.
The role involves ethical, legal and information-governance considerations. A Guardian may be particularly important when a proposed use or disclosure of confidential information is unusual, sensitive or difficult to assess.
The role can also involve considering how the Caldicott principles, Caldicott principles data protection requirements and other relevant legal duties apply to the circumstances. This may include situations involving deceased individuals, where the distinction between confidentiality and data-protection law is particularly important.
What Does a Caldicott Guardian Do?
The precise responsibilities depend on the organisation, but a Caldicott Guardian can help to:
- advise on difficult information-sharing decisions;
- promote appropriate confidentiality practices;
- support the application of the Caldicott principles;
- consider the ethical and legal aspects of using and sharing information;
- contribute to information-governance policies and practices;
- help organisations understand the relationship between the Caldicott principles and GDPR;
- consider confidentiality issues involving information about deceased individuals; and
- encourage an appropriate balance between protecting confidentiality and sharing information when there is a legitimate need to do so.
A Caldicott Guardian is not a substitute for everyone else’s responsibilities. Staff members remain responsible for following applicable policies, professional obligations and the law. The Guardian’s role is to provide senior oversight, advice and support rather than to remove individual accountability.
Who Needs a Caldicott Guardian?
In England, the National Data Guardian’s statutory guidance states that relevant public bodies in the health service, adult social care or adult carer-support sector that process confidential patient or service-user information should appoint a Caldicott Guardian.
The guidance also covers certain organisations that provide publicly funded health or adult social care services under arrangements with those public bodies. Some organisations may share access to a Caldicott Guardian where appointing a dedicated internal person would not be proportionate or practical.
How Are the Caldicott Principles Applied in Practice?
The Caldicott principles are most useful when incorporated into everyday decision-making rather than treated as abstract rules.
A practical approach is to identify the purpose, consider whether identifiable confidential information is genuinely necessary, use the minimum information required, limit access to those who need it, and confirm that the proposed use or disclosure complies with relevant law and organisational policy.
Applying the Caldicott principles in this way helps organisations make proportionate decisions about how confidential information is collected, accessed, used, stored and shared.
Examples of Applying the Caldicott Principles
Imagine a hospital clinician needs to send information to a community care team before a patient is discharged.
The purpose is clear: supporting continuing care. The clinician should then consider which information the community team genuinely requires. Relevant information about medication, mobility and care needs may need to be shared, while unrelated historical information may not be necessary.
Similarly, a manager analysing service performance might be able to work with appropriately anonymised information rather than identifiable patient records.
These examples demonstrate why Caldicott principles information governance is not simply about keeping information secret. It is about making proportionate and justifiable decisions about confidential information throughout its lifecycle.
When Can Confidential Information Be Shared?
There is no single rule stating that confidential information can only be shared with consent. The appropriate approach will depend on the circumstances, the purpose of the disclosure, applicable law and any relevant professional or organisational requirements.
Information may, for example, be shared appropriately to support individual care or where another lawful justification applies. The decision should be based on the specific circumstances rather than on a blanket assumption that information must always be withheld or always be shared.
Staff should follow organisational procedures and seek appropriate advice where the position is uncertain. Particularly difficult, sensitive or novel decisions may warrant involvement from a Caldicott Guardian, data-protection specialist or another appropriate senior professional.
Caldicott Principles and Data Protection Law
Understanding Caldicott principles data protection requirements means recognising that several legal, ethical and information-governance frameworks work together.
The Caldicott principles provide an ethical and governance framework for deciding how confidential health and social care information should be handled. Data-protection legislation, including the UK GDPR and the Data Protection Act 2018, creates legal requirements concerning the processing of personal data.
These frameworks complement one another. One does not cancel out or replace the other. Organisations must therefore consider the relevant Caldicott, confidentiality and data-protection requirements when using or sharing information.
How Do the Caldicott Principles Relate to UK GDPR?
The relationship between the Caldicott principles and GDPR is complementary.
The UK GDPR includes principles such as lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; security; and accountability. Several of these concepts correspond closely with the Caldicott principles, including justifying the purpose for using information, using the minimum necessary information and restricting unnecessary access.
Health information commonly receives additional protection because it is special-category personal data under the UK GDPR. Organisations generally need both an appropriate Article 6 lawful basis and an applicable Article 9 condition when processing such information.
The Caldicott principles do not themselves provide these legal bases. Instead, they provide an additional framework for considering whether confidential information should be used or shared appropriately.
What Does the Data Protection Act 2018 Require?
The relationship between the Caldicott principles and Data Protection Act 2018 is also complementary. The Data Protection Act 2018 supplements the UK GDPR and contains important provisions governing the processing of personal information, including provisions relevant to health and social care.
The legal framework has also developed since 2018. The Data (Use and Access) Act 2025 amended aspects of the UK GDPR and the Data Protection Act 2018 rather than replacing them. Organisations should therefore ensure that they consider the current legal requirements when handling personal and confidential information.
For organisations handling health and care information, the practical lesson remains clear: a proposed use or disclosure must satisfy applicable law as well as appropriate confidentiality and information-governance standards.
The Caldicott principles deceased context requires particular care because data protection and confidentiality do not operate in exactly the same way after a person’s death.
As a result, organisations should not assume that information can be freely disclosed simply because the individual has died. The circumstances, purpose of the disclosure, confidentiality obligations and any applicable legal requirements should all be considered before information is accessed or shared.
Frequently Asked Questions About the Caldicott Principles

Why Are the Caldicott Principles Important?
The Caldicott principles provide a practical way to protect confidentiality without preventing legitimate information sharing. They support patient trust, appropriate information governance and safe, coordinated care.
Are the Caldicott Principles Legally Binding?
The Caldicott principles are not a standalone Act of Parliament creating a complete legal code for confidentiality. However, they operate alongside relevant legal and professional obligations. Separately, the National Data Guardian’s statutory guidance on appointing Caldicott Guardians must be given due regard by organisations within its scope in England.
Who Is Responsible for Following the Caldicott Principles?
Responsibility for following the Caldicott principles is not limited to Caldicott Guardians. Organisations and individuals who handle relevant confidential information need to understand and apply appropriate confidentiality and information-governance requirements within their roles.
What Is the Difference Between the Caldicott Principles and GDPR?
The Caldicott principles form an information-governance framework focused particularly on the appropriate use and sharing of confidential health and social care information. The UK GDPR is part of the statutory data-protection framework that regulates the processing of personal data across many sectors.
The two frameworks work alongside each other. The Caldicott principles do not replace the legal requirements of the UK GDPR or other applicable legislation.
What Are the 8 Caldicott Principles?
The 8 Caldicott principles require organisations to justify the purpose of using confidential information, use it only where necessary, minimise the information used, restrict access to those who need it, ensure people understand their responsibilities, comply with the law, recognise the importance of appropriate information sharing for individual care, and inform people about how their information is used.
How Many Caldicott Principles Are There?
There are currently eight Caldicott principles. Six originated from the 1997 Caldicott review, a seventh followed the 2013 review, and an eighth was introduced in 2020.
Can Confidential Information Be Shared Without Consent?
Sometimes. Consent is not the only possible basis for using or sharing confidential information. The appropriate approach depends on the purpose, circumstances, confidentiality obligations and applicable legislation.
Staff should follow their organisation’s procedures and obtain specialist advice where necessary. The Caldicott principles emphasise that information should neither be shared unnecessarily nor withheld when appropriate sharing is required to support individual care.
Does GDPR Apply to the Medical Records of Someone Who Has Died?
The UK GDPR applies to information about identifiable living individuals, so information relating solely to a deceased person is not personal data under the UK GDPR. However, other confidentiality obligations and legal protections may continue to restrict disclosure.
This means that the Caldicott principles should still be considered when handling information relating to a deceased individual, particularly where the information may also relate to living people or where other confidentiality requirements apply.
Key Takeaways
The Caldicott principles are best understood as a framework for responsible information use rather than a blanket rule against sharing.
Their central messages are straightforward:
- establish a legitimate and clearly defined purpose;
- avoid using confidential information unless it is necessary;
- use only the minimum amount of information required;
- restrict access to people with a genuine need to know;
- ensure staff understand their responsibilities;
- comply with applicable law;
- share relevant information when individual care requires it; and
- be transparent with patients and service users.
For learners developing their knowledge of health and social care through resources such as High Paying Skills, understanding these distinctions is particularly important. Learning the names of the Caldicott principles is useful, but applying them requires judgement about necessity, proportionality, confidentiality, transparency and the legal basis for handling information.
Conclusion
So, what are the 8 Caldicott principles in practical terms? They are a decision-making framework designed to ensure that confidential information is protected while still being available when legitimate health and social care purposes require it.
Modern information governance is not achieved by either sharing everything or refusing to share anything. The Caldicott principles require organisations and workers to justify the purpose, minimise information, control access, comply with the law and communicate transparently with the people whose information they hold.
The Caldicott principles also need to be understood alongside current UK data-protection legislation rather than treated as a substitute for it. Applying both the confidentiality framework and the relevant legal requirements appropriately helps organisations use sensitive health and social care information responsibly while supporting safe and effective care.


