img
Offer Ends Soon
00:00:00
Get Courses for
£9.99
Use Coupon Code

Home/ Blog / What Are the Caldicott Principles? The 8 Principles Explained

What Are the Caldicott Principles? The 8 Principles Explained

image

The Caldicott Principles provide a practical framework for using confidential information responsibly in health and social care. They help health and care professionals make informed decisions about when identifiable information should be used, how much information should be shared, who genuinely needs access to it, and when sharing information is necessary to support a person’s care. 

Quick Overview
The Caldicott Principles are essential for protecting confidential health and social care information while ensuring that information is shared appropriately when needed for safe and effective care. This guide covers the 8 Caldicott Principles, their purpose, practical application, confidentiality, data protection and the role of Caldicott Guardians.

This guide covers:
✅ What the Caldicott Principles are and why they are important in health and social care
✅ The Caldicott principles definition, history and purpose
✅ What confidential and patient-identifiable information is covered by the principles
✅ The 8 Caldicott Principles and how they are applied in practice
✅ How the principles relate to the UK GDPR, Data Protection Act 2018 and confidentiality law
✅ When confidential information can be shared, including for individual care
✅ The role and responsibilities of a Caldicott Guardian
✅ How organisations can balance protecting confidentiality with appropriate information sharing

Today there are now 8 Caldicott Principles, which emphasise the importance of balancing confidentiality with appropriate information sharing rather than treating privacy as an automatic reason to withhold information. 

Understanding the Caldicott Principles

A useful Caldicott principles definition is: eight good-practice principles designed to ensure that confidential health and social care information is protected and used appropriately.

The purpose of Caldicott principles is not simply to prevent information from being shared. Instead, they provide a practical decision-making framework for determining when confidential information is genuinely required, how much should be shared, who should have access to it and how it should be handled. This is why the principles address necessity, minimisation, access, staff responsibility, lawfulness, appropriate sharing and transparency.

In practical terms, the relationship between the Caldicott principles, confidentiality and good information governance is about achieving the right balance. Keeping information secure is essential, but refusing to share relevant information with another professional can also cause harm when that information is needed to provide safe and effective care.

What Is Patient-Identifiable and Confidential Information?

The Caldicott principles are intended to apply to confidential information collected in connection with health and social care where a patient or service user can be identified and would reasonably expect the information to remain private.

Examples may include a person's:

  • Name, address or other identifying details
  • Symptoms and medical history
  • Diagnosis
  • Treatment and medication
  • Mental or physical health information
  • Social care needs and support arrangements

Information does not necessarily become non-identifiable simply because a person's name has been removed. If an individual could reasonably be identified from other details, the information may still require protection. Under data-protection law, pseudonymised information can also remain personal data where re-identification is possible.

The Caldicott framework may sometimes also be relevant to staff information where similar confidentiality considerations arise.

The History and Development of the Caldicott Principles

The history of the Caldicott principles began in the 1990s, when increasing computerisation and the movement of patient information across the NHS raised concerns about whether identifiable information was always being used appropriately.

Where Did the Caldicott Principles Come From?

In 1997, a committee chaired by Dame Fiona Caldicott completed a review of patient-identifiable information in the NHS. The review produced six principles for deciding when identifiable information should be used and recommended that organisations appoint a senior person to oversee patient confidentiality. These senior figures became known as Caldicott Guardians.

The framework subsequently developed as follows:

YearDevelopment
1997Original six Caldicott Principles introduced
2013Seventh principle added, emphasising appropriate information sharing
2020Principles revised and an eighth principle added, strengthening transparency

The 2013 addition was significant because it addressed a problem at the opposite end of confidentiality: professionals could sometimes become too reluctant to share information. The seventh principle therefore made clear that sharing information for individual care can be just as important as protecting confidentiality.

The eighth principle, introduced in 2020, strengthened transparency. It promotes a ‘no surprises’ approach, helping patients and service users understand how their confidential information is likely to be used.

Why Were the Caldicott Principles Introduced?

So, why were the Caldicott principles introduced? Their original purpose was to respond to concerns about the increasing use and movement of identifiable patient information within the NHS.

Health information is exceptionally sensitive, but healthcare also depends on information being shared between appropriate people. A GP, hospital consultant, pharmacist, nurse and social care professional may all need different information about the same person.

The principles were designed to ensure that these information flows could be justified rather than assumed. They help professionals consider whether information is necessary, who genuinely needs access to it and whether it can be shared lawfully and responsibly.

How Many Caldicott Principles Are There?

Anyone asking how many Caldicott principles are there should use the current figure of eight.

There were originally six principles in 1997, seven from 2013 and eight from December 2020 onwards.

What Do the Eight Caldicott Principles Achieve?

So, what do the eight Caldicott principles achieve collectively? They provide a structured way for health and social care professionals to consider questions such as:

  • Is identifiable information actually required?
  • Is this the minimum information needed?
  • Does this person genuinely need access?
  • Is the proposed use or sharing lawful?
  • Does the patient or service user understand how their information is being used?
  • Could failing to share relevant information itself put the person's care or safety at risk?

Together, the Caldicott principles support responsible information governance by helping organisations protect confidentiality while enabling appropriate information sharing when it is necessary for safe, effective and person-centred care.

The 8 Caldicott Principles Explained

The 8 Caldicott Principles provide a practical framework for protecting confidential information while ensuring it is used and shared appropriately in health and social care.

Principle 1: Justify the Purpose(s) for Using Confidential Information

Before confidential information is used or transferred, the purpose should be clear and justifiable.

Organisations should define and document the purpose rather than collect or share information simply because it might prove useful in the future. Ongoing uses should also be reviewed to ensure that they remain justified.

For example, if identifiable patient information is proposed for a new service evaluation, the organisation should establish why identifiable information is necessary and how the information will actually be used.

Principle 1 establishes accountability at the beginning of the decision-making process and helps ensure that the use of confidential information has a clear and legitimate purpose.

Principle 2: Use Confidential Information Only When Necessary

Once the purpose has been established, the next question is whether confidential information is needed at all.

If a task can be completed effectively using anonymised information, identifiable information should not normally be introduced unnecessarily.

For example, suppose a manager needs statistics showing how many patients attended a service each month. Names and addresses would usually add nothing to that purpose, so aggregate information may be sufficient.

This principle encourages professionals to distinguish between information that may be useful and information that is genuinely necessary for the specific purpose.

Principle 3: Use the Minimum Necessary Confidential Information

Sometimes identifiable information is genuinely required. Principle 3 then asks how much information is necessary.

Only the minimum confidential information needed for the particular purpose should be used or shared.

For example, another professional may need to know a patient's relevant diagnosis, current medication and allergy information without needing access to their entire medical history.

This principle closely complements the data-minimisation approach found in data-protection law and supports the proportionate use of confidential information.

Principle 4: Access Confidential Information on a Strict Need-to-Know Basis

Not everyone working in a healthcare organisation needs access to every patient record.

Access should be limited to people who genuinely require the information for their role and, where practicable, to the specific information they need.

Organisations can support this through role-based permissions, appropriate system access and clear procedures for managing confidential information.

The principle also applies outside electronic systems. Confidential information should not be discussed in places where people without a legitimate need to know could overhear it.

Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities

Technical security cannot adequately protect confidential information if staff do not understand their responsibilities.

Everyone handling confidential information should know how to store, access, discuss, transmit and dispose of it appropriately. This extends beyond doctors and nurses to administrators, support staff, contractors and others who may encounter confidential records.

Training is therefore an important part of Caldicott principles information governance. However, completing a training course alone does not demonstrate that someone will always handle information correctly. Organisations also need clear policies, effective supervision, appropriate access controls and secure systems.

Together, these measures help turn the Caldicott principles from a set of statements into practical safeguards for the responsible handling of confidential information.

Principle 6: Comply with the Law

Every use of confidential information must be lawful. This is a fundamental part of applying the Caldicott principles in health and social care and should be considered alongside the specific legal requirements that apply to the situation.

Depending on the circumstances, relevant requirements may arise from the UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality and legislation governing particular health or social care activities.

The relationship between the Caldicott principles and GDPR is important. The Caldicott Principles do not replace legal requirements or provide a substitute for legal analysis. A proposed disclosure does not become lawful simply because someone believes that it is consistent with a Caldicott principle.

Organisations must identify and follow the legal framework applicable to the specific use, disclosure or sharing of confidential information.

Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Patient Confidentiality

Principle 7 addresses the misconception that confidentiality always means withholding information. In both the Caldicott principles NHS context and wider health and social care, safe and effective care often depends on appropriate information sharing.

For example, a clinician treating a patient may need access to their medication history, allergies, previous investigations or other relevant information. Social care professionals may also need specific information to provide safe and effective support.

Professionals should therefore have the confidence to share relevant information for individual care when this is appropriate, necessary and lawful.

However, Principle 7 does not give permission to share information indiscriminately. Principles 1 to 6 still apply. The information must have a legitimate purpose, be necessary for the person's care, be limited to what is required and be shared only with appropriate people.

Principle 8: Inform Patients and Service Users How Their Confidential Information Is Used

The eighth principle aims to prevent unexpected uses of confidential information. Patients and service users should receive clear, accessible and relevant information explaining how and why their confidential information is used and what choices may be available to them.

This goes beyond placing a lengthy privacy notice somewhere on a website. Information should be understandable, accessible and appropriate to the intended audience.

In some situations, a standard privacy notice may be sufficient. More unusual or potentially unexpected uses may require clearer communication, additional explanation or appropriate engagement.

Do Caldicott Principles Apply to the Deceased?

Questions such as do Caldicott principles apply to the deceased require careful consideration because confidentiality does not simply become irrelevant when a person dies.

The Caldicott principles deceased context should be considered alongside the common law duty of confidentiality, relevant legislation and professional guidance. Organisations should assess whether information about a deceased person is confidential, the purpose for which it is being requested and whether there is a lawful and appropriate basis for disclosure.

The Caldicott framework therefore continues to provide a useful governance approach to handling information responsibly, while the specific legal and professional requirements should be considered for each situation.

Who Do the Caldicott Principles Apply To?

The Caldicott Principles apply to organisations and professionals who handle confidential information in health and social care, helping them use and share information responsibly and lawfully. 

Caldicott Principles in Health and Social Care

The Caldicott principles health and social care framework is primarily intended to guide organisations and people who handle confidential patient and service-user information.
The framework began within the NHS but now has much wider relevance across health and social care. The NHS origins are why references to the Caldicott principles NHS framework remain common, but the principles are no longer relevant only to NHS employees.


They can apply to professionals and organisations including hospitals, GP services, community healthcare providers, social care providers, local authorities, mental health services and organisations contracted to provide relevant health or social care services.
The precise legal and organisational obligations relating to Caldicott Guardians vary depending on the UK jurisdiction and type of organisation. For example, the National Data Guardian's statutory guidance on Caldicott Guardian appointments specifically applies in England.

Do the Caldicott Principles Apply to the Deceased?

Yes. Confidentiality does not automatically disappear when a patient or service user dies.

The answer to do Caldicott principles apply to the deceased is therefore different from the position under the UK GDPR. The UK GDPR protects personal data relating to identifiable living individuals. Information relating solely to a deceased person is not personal data for UK GDPR purposes.


However, Caldicott principles deceased records may still require careful handling because other legal and professional protections can remain relevant. The common law duty of confidentiality may continue after death, and organisations should not assume that a deceased person's record can simply be disclosed to anyone who requests it.
Certain people may have statutory rights to access deceased patients' medical records in particular circumstances under the Access to Health Records Act 1990. Requests should therefore be assessed under the correct legal route rather than automatically treated as ordinary subject access requests under the UK GDPR.

What Information Is Covered by the Caldicott Principles?

The Caldicott principles apply to confidential information collected for health and social care where individuals can be identified and would reasonably expect their information to remain private.

This can include:

  • Written and electronic records
  • Photographs
  • Emails and other correspondence
  • Test results
  • Care plans
  • Medical and social care information
  • Verbal information shared about a patient or service user

The method of communication does not change the underlying confidentiality obligation. Discussing a diagnosis in a corridor can create a confidentiality risk just as sending a patient's record to the wrong email recipient can.

What Is a Caldicott Guardian?

A Caldicott Guardian is a senior person who helps an organisation protect the confidentiality of health and care information and ensure that information is used appropriately.

The role combines legal, ethical and practical considerations. A Guardian may become involved when a proposed disclosure or use of information presents a difficult judgement and the correct course of action is not immediately clear.

The role is closely linked to the Caldicott Principles. The Caldicott Principles are a set of principles that provide a framework for using and sharing confidential health and care information appropriately. The purpose of the Caldicott Principles is to help organisations balance the need to protect people's confidentiality with the need to use and share information when this is necessary for safe and effective care.

What Does a Caldicott Guardian Do?

Typical responsibilities can include advising on difficult information-sharing decisions, promoting the Caldicott Principles, supporting appropriate information governance, and helping the organisation balance confidentiality with the need to share information for care.

A Guardian may also help staff understand the Caldicott Principles and apply them appropriately when using or sharing confidential information.

The Guardian is not simply the person who says “no” to information sharing. Caldicott Principle 7 means that the role should also support appropriate information sharing when withholding information could undermine safe and effective care.

A Guardian may work alongside information governance teams, Data Protection Officers, data protection specialists, clinicians, safeguarding professionals and senior management.

The role is also distinct from that of a Data Protection Officer (DPO). There may be some overlap, but the functions are not interchangeable. A DPO focuses particularly on compliance with data protection law, while a Caldicott Guardian brings a health and social care confidentiality and ethical perspective to the use and sharing of information.

Who Needs a Caldicott Guardian?

All NHS organisations and local authorities providing social services have long been expected to have a Caldicott Guardian.

National Data Guardian guidance in England has extended expectations to a broader range of public health and adult social care bodies that handle confidential information, as well as organisations contracted by those bodies to deliver relevant services.

The guidance allows for proportionate arrangements. For example, an organisation may be able to access a shared Caldicott Guardian function rather than appointing a dedicated, full-time individual.

For difficult information-sharing decisions, staff should know how to contact the person performing the Caldicott Guardian function and seek their advice when necessary.

How Are the Caldicott Principles Applied in Practice?

The Caldicott Principles are applied in practice by helping organisations make informed decisions about how confidential health and care information is collected, used and shared.

Examples of Applying the Caldicott Principles

The Caldicott principles provide a practical framework for protecting confidential information while ensuring that it is used and shared appropriately. The Caldicott principles definition can be summarised as a set of guidelines that help organisations and professionals make responsible decisions about the use and sharing of confidential information. The purpose of the Caldicott principles is to ensure that confidential information is handled lawfully, securely and appropriately, while still allowing information to be shared when it is necessary for patient care and other justified purposes.

Consider a hospital preparing a report on waiting times. If patient identities are not necessary, Principle 2 supports using information without identifiable details.

A community nurse sending information to a social worker may need to share details that are relevant to a patient’s immediate care. Principle 7 supports appropriate information sharing, while Principles 3 and 4 require the nurse to limit the information shared to what the social worker needs.

If a service introduces a new digital system containing confidential records, Principle 1 requires the intended uses of the information to be clearly justified. Principle 4 supports appropriate access controls, while Principle 8 requires suitable transparency for patients.

A receptionist who can access patient records also falls within the framework. Principle 5 means that confidentiality responsibilities apply to everyone who has access to confidential information, not only registered healthcare professionals.

These examples demonstrate that Caldicott principles data protection is not simply an IT issue. Decisions made during conversations, telephone calls, handovers, meetings and routine clinical work can all involve confidential information.

When Can Confidential Information Be Shared?

Confidential information can sometimes be shared for direct care, with the person’s consent or under another lawful authority or justification.

There are also situations where disclosure may be required or justified without consent, for example, where legislation requires information to be provided or where sufficiently serious public-interest considerations apply.

The correct approach depends on the circumstances. Professionals should therefore avoid two opposite assumptions:

“Confidential means I can never share it.”

and

“I work in healthcare, so I can share it with anyone else working in healthcare.”

Both assumptions are incorrect.

Instead, professionals should consider why the information is needed, whether its use is necessary, what minimum information should be shared, who needs to receive it, and what legal and confidentiality requirements apply. In this way, the Caldicott principles help professionals balance the need to protect confidentiality with the need to share information appropriately for patient care and other legitimate purposes.

Caldicott Principles and Data Protection Law

The Caldicott principles definition can be understood as a set of principles that guide health and social care organisations in the responsible use and sharing of confidential information.

How Do the Caldicott Principles Relate to UK GDPR?

The Caldicott principles and GDPR work alongside each other, but they are not the same framework.

The Caldicott principles definition can be understood as a set of principles that guide health and social care organisations in the responsible use and sharing of confidential information. The purpose of Caldicott principles is to help organisations protect confidentiality while ensuring that information can be used and shared appropriately when there is a legitimate need to do so.

The UK GDPR forms part of the legal framework governing the processing of personal data. Health information about an identifiable living person is generally considered special category personal data, which receives additional protection.

An organisation processing health data normally needs an appropriate lawful basis under Article 6 of the UK GDPR and an applicable special-category condition under Article 9. The appropriate basis depends on why the information is being processed and the circumstances involved.

The Caldicott Principles do not create either of these legal bases. Instead, they help health and social care organisations make responsible decisions about the use and sharing of confidential information within the wider legal and regulatory framework.

There are clear parallels between the two frameworks. Principle 3's focus on using the minimum necessary information closely reflects the data minimisation principle. Principle 8 supports transparency, while Principle 4 complements requirements relating to security and access controls.

However, compliance with one framework does not automatically mean that an organisation is compliant with the other. Organisations must consider all relevant legal and information-governance requirements.

There is also a separate common law duty of confidentiality. This distinction is important because consent can have different significance under confidentiality law and under the UK GDPR. Health and social care organisations should therefore avoid assuming that consent is always the appropriate UK GDPR lawful basis simply because confidential information is involved.

What Does the Data Protection Act 2018 Require?

The Caldicott principles and Data Protection Act 2018 operate alongside the UK GDPR. The Data Protection Act 2018 supplements the UK GDPR, provides additional rules and conditions, and contains specific provisions relevant to areas including health and social care.

The Caldicott principles and data protection act framework should therefore be understood as complementary rather than interchangeable. The Caldicott Principles provide health-and-care-specific ethical and information-governance guidance, while data-protection legislation establishes legal obligations that organisations must follow.

The current legal framework also includes amendments made by the Data (Use and Access) Act 2025. By June 2026, all of its data-protection provisions were in force. The Act amended parts of the UK GDPR and the Data Protection Act 2018 but did not replace or abolish either framework.

For organisations handling health information, good Caldicott principles data protection practice therefore involves several layers. These include compliance with the UK GDPR, the Data Protection Act 2018 as amended, applicable confidentiality law, sector-specific requirements and the appropriate application of the Caldicott Principles.

Together, these frameworks help organisations use information responsibly, protect people's confidentiality and ensure that information is shared when there is a lawful, necessary and appropriate reason to do so.

Frequently Asked Questions About the Caldicott Principles

Why Are the Caldicott Principles Important?

The Caldicott principles help health and social care organisations protect confidential information without preventing information sharing that is genuinely necessary for safe and effective care. Their value lies in providing a practical framework for considering purpose, necessity, minimisation, access, responsibility, lawfulness, information sharing and transparency.

The Caldicott principles definition can be summarised as a set of principles that guide organisations and individuals in the responsible use and sharing of confidential information. The purpose of Caldicott principles is to help ensure that confidential information is protected while allowing it to be used and shared appropriately when there is a legitimate need.

Are the Caldicott Principles Legally Binding?

The Caldicott Principles themselves are generally described as good-practice guidance rather than a standalone Act of Parliament. However, Principle 6 requires compliance with the law, and decisions involving confidential information may also be governed by statutory duties, the UK GDPR, the Data Protection Act 2018 and the common law duty of confidentiality.

Separate statutory National Data Guardian guidance on Caldicott Guardians also requires organisations within its scope in England to have due regard to that guidance.

Who Is Responsible for Following the Caldicott Principles?

Responsibility is not limited to Caldicott Guardians. Everyone who handles relevant confidential information should understand and follow their responsibilities.

This may include clinicians, care workers, administrative staff, managers, contractors and other workers who have access to confidential information.

What Is the Difference Between the Caldicott Principles and GDPR?

The UK GDPR is data-protection law, whereas the Caldicott Principles are health-and-social-care-specific good-practice principles for handling confidential information.

The two frameworks overlap in areas such as data minimisation, appropriate access and transparency. However, following the Caldicott Principles does not, by itself, establish compliance with the UK GDPR.

What Are the 8 Caldicott Principles?

For anyone asking what are the 8 Caldicott principles, they are:

  1. Justify the purpose for using confidential information.
  2. Use confidential information only when necessary.
  3. Use the minimum necessary confidential information.
  4. Restrict access to confidential information on a strict need-to-know basis.
  5. Make sure everyone with access understands their responsibilities.
  6. Comply with the law.
  7. Recognise that the duty to share information for individual care is as important as the duty to protect confidentiality.
  8. Inform patients and service users about how their confidential information is used.

Can Patient Information Be Shared Without Consent?

Sometimes. The answer depends on the purpose of the disclosure, the applicable law, common law confidentiality and the circumstances of the particular case.

Information may sometimes be shared under statutory authority or another recognised justification. Information sharing for direct care should also be considered within the relevant confidentiality framework.

Staff should follow their organisation's policies and seek specialist or Caldicott Guardian advice where a decision is difficult or unclear.

Is a Caldicott Guardian the Same as a Data Protection Officer?

No. Both roles can contribute to responsible information handling, but their functions are different.

A Data Protection Officer (DPO) has responsibilities arising from data-protection law, while a Caldicott Guardian focuses particularly on confidentiality and the ethical use and sharing of health and care information.

Do the Principles Apply Only to Electronic Records?

No. The principles can apply to confidential information regardless of its format. Paper files, photographs, emails, telephone conversations, meetings and verbal handovers can all involve confidential information.

Does Completing Caldicott Training Make Someone Competent to Make Every Disclosure Decision?

No. Training can develop knowledge and understanding of the Caldicott Principles, but difficult cases may require knowledge of data-protection law, common law confidentiality, organisational policies and the specific facts of the situation.

Competehigh provides health and social care learning that may support broader knowledge development. Any training should be appropriate to the learner's role and supported by workplace policies, supervision and access to specialist advice where necessary. A course certificate should not be treated as practising authority or as proof that every information-governance judgement will be correct.

Key Takeaways

The Caldicott principles began as six NHS confidentiality guidelines in 1997, expanded to seven in 2013 and became the current set of eight in 2020. Their central aim is to ensure that confidential health and social care information is used responsibly without creating unnecessary barriers to appropriate information sharing.

The principles require organisations and staff to justify why confidential information is needed, avoid using identifiable information where possible, use only the minimum necessary information, restrict access, understand their responsibilities and comply with the law. They also recognise that sharing information can be essential for individual care and that patients and service users should understand how their information is being used.

The purpose of Caldicott principles is therefore not simply to prevent information sharing. Instead, they provide a practical framework for balancing confidentiality with the need to use and share information appropriately for safe and effective care.

The principles sit alongside, rather than replace, the UK GDPR, Data Protection Act 2018, common law confidentiality and other relevant legal requirements. This distinction is particularly important when considering information about deceased people, because UK data-protection law generally concerns living individuals, while confidentiality obligations may continue after death.

Ultimately, the eight Caldicott Principles provide a practical way to balance two objectives that health and social care organisations must achieve at the same time: protecting confidential information and making appropriate information available when it is genuinely needed for safe and effective care.