The Caldicott principles provide a practical framework for protecting confidential information while ensuring that it can be used and shared appropriately within health and social care. They are particularly important because effective care often depends on information being shared between professionals, teams and organisations. At the same time, patients and service users have a legitimate expectation that sensitive information about them will be kept private and handled responsibly.
Quick Overview
The Caldicott Principles provide a practical framework for protecting confidential health and social care information while supporting appropriate information sharing. This guide explains the 8 Caldicott Principles, their purpose, history, practical application and relationship with data protection law.
This guide covers:
✅ What the Caldicott Principles are and why they are important
✅ The Caldicott principles definition, purpose and history
✅ The 8 Caldicott Principles and how they guide information handling
✅ Who the principles apply to, including health and social care organisations and professionals
✅ The role and responsibilities of a Caldicott Guardian
✅ How the principles apply to confidential and patient-identifiable information, including information about deceased people
✅ How the Caldicott Principles work alongside the UK GDPR and Data Protection Act 2018
✅ When confidential information can be shared and how the principles support safe, lawful and responsible information sharing
There are currently 8 Caldicott principles. Together, they help organisations and professionals determine why confidential information is needed, how much information should be used, who should have access to it, when sharing is appropriate and how patients and service users should be informed about the use of their information.
The Caldicott principles form an important part of information governance in health and social care. They support responsible decision-making and help organisations balance the need to protect confidentiality with the need to share information when it is necessary for safe and effective care.
This guide explains what are the 8 Caldicott principles, where the Caldicott principles came from, who they apply to, the role of a Caldicott Guardian and how the principles interact with UK data-protection law.
A practical Caldicott principles definition is that the Caldicott principles are eight information-governance principles designed to ensure that confidential health and social care information is protected, used lawfully and shared appropriately.

The purpose of Caldicott principles is not simply to prevent information from being disclosed. Modern health and social care depends on appropriate information sharing. A GP, hospital consultant, pharmacist, social worker or care provider may all need relevant information to provide safe, effective and coordinated care.
The principles therefore seek to achieve a careful balance. Information should not be accessed or disclosed without proper justification, but excessive secrecy should not prevent necessary information sharing for an individual's care.
This balance is central to Caldicott principles confidentiality. Protecting confidential information and sharing it appropriately are both important responsibilities.
The eight Caldicott principles provide a practical framework for making responsible decisions about confidential information. They help organisations and professionals consider why information is needed, whether its use is necessary, how much information should be shared, who should have access and whether the law permits or requires the information to be used or disclosed.
In practical terms, what do the eight Caldicott principles achieve? They help organisations protect people's confidentiality while ensuring that important information can be shared when it is genuinely needed for safe and effective care. They also promote accountability, appropriate access, compliance with the law and transparency about how confidential information is used.
Confidential health and care information can include information that directly identifies an individual or enables them to be identified when combined with other information.
Examples may include:
The National Data Guardian generally uses the term confidential information in the current principles. Earlier guidance commonly referred to terms such as “patient-identifiable information” or “personal confidential data”.
Not every piece of information carries the same level of risk. Properly anonymised information, where an individual can no longer reasonably be identified, is treated differently from identifiable confidential information. However, simply removing a person's name does not necessarily make information anonymous if other details could still identify them.
Within Caldicott principles information governance, the key question is therefore not only whether a person's name appears on a record, but whether the information relates to an identifiable person who would reasonably expect it to remain private.
The Caldicott principles history begins in 1997. Concerns had developed about the increasing use of patient information across the NHS, particularly as advances in information technology made it easier to store, copy and transfer records.
A review of patient-identifiable information was chaired by Dame Fiona Caldicott. The resulting report recommended six principles for controlling the use and transfer of confidential patient information and also led to the development of the Caldicott Guardian role.
So, why were the Caldicott principles introduced? The original aim was to ensure that patient-identifiable information was used only for justified purposes, that unnecessary identification was avoided and that only the minimum information required was disclosed.
The framework later evolved.
In 2013, a further review considered the balance between protecting information and sharing it for good care. A seventh principle was added, making clear that the duty to share information for individual care can be as important as the duty to maintain confidentiality.
In December 2020, the National Data Guardian revised the wording of the principles and introduced Principle 8. This principle focuses on transparency, helping patients and service users understand how and why their confidential information is being used and reducing the risk of unexpected uses of their information.
If you are wondering how many Caldicott principles are there, the current answer is eight. Together, the Caldicott principles provide an important framework for balancing confidentiality, responsible information use and appropriate information sharing across health and social care.
The simplest answer to what do the eight Caldicott principles achieve is that they provide a structured way of deciding whether confidential information should be used or shared and, if so, how this should be done responsibly.
The 8 Caldicott principles form an important part of Caldicott principles information governance. They help organisations balance the need to protect confidentiality with the need to use and share information appropriately for safe and effective health and social care.
Understanding what are the 8 Caldicott principles can help staff make better decisions about confidential information in everyday practice. The principles also reflect the development of information governance over time and form an important part of the Caldicott principles history.
Before confidential information is used or transferred, there should be a clear and justifiable reason for doing so.
An organisation should be able to explain:
This prevents information from being collected or shared simply because it is convenient or potentially useful.
For example, if a healthcare organisation proposes to send identifiable patient information to another organisation for a new project, it should first establish the precise purpose and determine whether the use of confidential information is justified.
Long-standing information flows should also be reviewed rather than assumed to remain appropriate indefinitely.
Even when the overall purpose is legitimate, the next question is whether confidential information is actually necessary.
If the objective can reasonably be achieved without identifying individuals, identifiable information should normally not be used.
For example, a service may want to analyse the number of patients receiving a particular type of treatment. If aggregate or appropriately anonymised information can provide the required answer, there may be no reason to disclose individual patient identities.
Principle 2 therefore asks organisations to challenge the assumption that identifiable information must always be used.
Where confidential information is genuinely required, organisations should use only the minimum amount needed for the particular purpose.
This principle applies to both the content of the information and the number of people's records involved.
Suppose a professional needs to confirm whether a patient takes a particular medicine. Giving that professional access to the patient's entire medical history may be unnecessary if a much smaller part of the record can answer the relevant question.
This approach closely resembles the data-minimisation concept found in data-protection law. It helps reduce privacy risks while allowing necessary work to continue.
Not everyone working within a healthcare or social care organisation needs access to every record.
Access should therefore be based on a person's role and the information required to carry out that role.
Practical measures can include:
For example, an employee should not access the medical record of a neighbour, relative, colleague or public figure merely out of curiosity. Having technical access to a system does not, by itself, create a legitimate need to view confidential information.
Information governance is not only the responsibility of senior managers, data-protection teams or clinicians.

Anyone who handles confidential information should understand their responsibilities. This may include clinical staff, care workers, administrators, reception staff, contractors, temporary workers, volunteers and others with authorised access.
Organisations should support this through appropriate policies, induction, training, supervision and clear reporting procedures.
Staff should understand issues such as secure communication, verifying recipients, appropriate conversations, password protection, handling physical records, remote working and reporting suspected data incidents.
A strong confidentiality culture depends on people understanding not only what the rules say, but also how those rules apply during everyday work.
Every use of confidential information must comply with the law.
The Caldicott principles do not replace legislation. Organisations may need to consider several overlapping legal and professional obligations, including data-protection law, the common law duty of confidentiality, statutory disclosure requirements and professional standards.
In the UK data-protection context, organisations must consider the UK GDPR and the Data Protection Act 2018, as currently amended, including amendments made by the Data (Use and Access) Act 2025.
Health information is generally considered special-category personal data, which means that additional safeguards and processing conditions apply.
Principle 6 therefore prevents an organisation from treating compliance with the other Caldicott principles as sufficient if the proposed activity would otherwise be unlawful.
Principle 7 addresses a significant misconception about Caldicott principles confidentiality: confidentiality does not mean that health and care professionals should never share information.
Sometimes, failing to share relevant information can itself place a patient or service user at risk.
For example, appropriate information may need to be shared between a GP, hospital team, pharmacist and community care provider so that treatment can be coordinated safely.
The principle does not authorise unrestricted information sharing. Principles 1 to 6 still apply. Information should be relevant, proportionate and shared with appropriate people through suitable channels.
Professionals should therefore not withhold information needed for individual care simply because they are concerned that any disclosure might breach confidentiality.
The eighth principle promotes transparency and the idea of providing “no surprises” for patients and service users.
Patients and service users should have accessible and relevant information explaining how their confidential information is used, why it may be shared and what choices they may have.
Depending on the circumstances, organisations may provide this information through privacy notices, patient information, discussions with professionals or more detailed engagement.
This does not mean that every use of information requires individual consent. Data-protection and confidentiality rules provide different legal routes for processing and sharing information.
Instead, Principle 8 means that people should not unnecessarily be kept in the dark about significant uses of information concerning them.
The Caldicott Principles apply to organisations and professionals who handle confidential health and social care information, helping them use and share information responsibly, securely and appropriately.
The Caldicott principles health and social care framework is primarily concerned with confidential information collected and used when providing health and social care services.
The Caldicott principles may affect a wide range of people and organisations, including NHS bodies, health professionals, social care providers, local authorities, commissioned services and other organisations that handle confidential health or care information.
The principles are particularly associated with England through the National Data Guardian, but they are also used within health systems elsewhere in the UK. NHS Scotland and NHS Wales, for example, have incorporated Caldicott principles into their information-governance arrangements.
References to Caldicott principles NHS practice should therefore not be taken to mean that every organisational requirement is identical across England, Scotland, Wales and Northern Ireland. Local legislation, policies and governance arrangements should also be considered.
The principles support Caldicott principles confidentiality by helping organisations and professionals decide how confidential information should be protected, used and shared. They are intended to support appropriate information sharing rather than prevent information from being used when it is genuinely required for safe and effective care.
A common question is: do Caldicott principles apply to the deceased?
Yes. Confidential information about people who have died can continue to require protection, and the Caldicott principles may remain relevant when decisions are made about using or disclosing that information.
This is an important distinction from general data-protection legislation. UK GDPR protections concerning personal data generally relate to living individuals, but confidentiality obligations can continue after death.
The issue sometimes described as Caldicott principles deceased information therefore involves more than ordinary data protection. In England and Wales, for example, the Access to Health Records Act 1990 provides certain people with limited rights to seek access to the health records of a deceased person. Different arrangements apply in Northern Ireland.
A person's death should therefore not be treated as meaning that their medical information automatically becomes public. Appropriate confidentiality considerations can continue to apply after death.
The Caldicott principles apply broadly to confidential information collected or used for health and social care where an individual can be identified and would reasonably expect the information to remain private.
This may include:
Information can exist in many different forms. Electronic records, paper documents, photographs, recordings, emails, messages and verbal communications can all raise confidentiality issues.
Understanding why were the Caldicott principles introduced helps explain their continuing importance. The principles were developed to address concerns about the use and sharing of patient-identifiable information and to provide a practical framework for protecting confidentiality while allowing information to be used appropriately for health and social care.
Their purpose is not simply to prevent disclosure. Instead, the Caldicott principles help organisations balance the responsibility to protect confidential information with the need to share relevant information when it is necessary for individual care or another justified purpose.
If you are asking how many Caldicott principles are there, there are currently eight Caldicott principles.
The eight principles provide a structured approach to deciding why confidential information is needed, whether its use is necessary, how much information should be used, who should have access, what legal requirements apply, when information should be shared and how patients and service users should be informed.
Together, they form an important part of information governance across health and social care and support responsible handling of confidential information throughout its lifecycle.
A Caldicott Guardian is a senior person who helps an organisation make appropriate decisions about the use and sharing of confidential health and care information.
The role combines ethical, confidentiality and information-governance considerations. A Caldicott Guardian may be involved when a proposed use or disclosure of information is unusual, sensitive or difficult, particularly when an organisation needs to balance confidentiality with legitimate information-sharing needs.
The Caldicott principles provide an important framework for this role. They help the Guardian and the organisation consider whether confidential information is necessary, whether the proposed use is justified, who should have access and whether information should be shared.
A Caldicott Guardian is not simply another name for a Data Protection Officer (DPO). The two roles may work closely together, but their responsibilities and areas of focus are different.
Depending on the organisation, a Caldicott Guardian may:
The Guardian should be appropriately senior and able to influence organisational decisions.
However, appointing a Caldicott Guardian does not transfer responsibility for confidentiality away from other staff. Principle 5 makes clear that everyone with access to confidential information has responsibilities for handling it appropriately.
The role of the Caldicott Guardian is particularly relevant to Caldicott principles health and social care arrangements, where confidential information is regularly collected, accessed and shared to support patient and service-user care.
Guardians can help organisations apply the principles in practical situations, such as information sharing between healthcare professionals, social care teams and other organisations involved in a person's care.

The Caldicott principles NHS framework is particularly important because NHS organisations routinely handle large amounts of sensitive health information. A Caldicott Guardian can help ensure that confidential information is used appropriately while avoiding unnecessary barriers to information sharing for safe and effective care.
The role should complement, rather than replace, other information-governance responsibilities, including data-protection, confidentiality and security arrangements.
In England, National Data Guardian statutory guidance on Caldicott Guardians applies to specified organisations that handle confidential patient or service-user information.
This includes public bodies within health services, adult social care or adult carer-support sectors in England, as well as organisations contracted by public bodies to provide relevant health or adult social care services where they handle confidential information.
Organisations within the scope of the guidance are expected to make suitable Caldicott Guardian arrangements and give due regard to the National Data Guardian's statutory guidance.
Other organisations may also choose to appoint a Caldicott Guardian where the same statutory requirement does not apply.
Because arrangements can differ across the UK, organisations should check the requirements that apply to their particular jurisdiction and sector rather than assuming that English statutory guidance applies unchanged everywhere.
A related question is do Caldicott principles apply to the deceased? Yes. Confidential information about a person who has died can continue to require appropriate protection, and Caldicott Guardians may need to consider the Caldicott principles deceased information when advising on its use or disclosure.
Although UK data-protection law generally applies to living individuals, confidentiality obligations can continue after death. A person's death does not automatically make their health or care information public.
A Caldicott Guardian may therefore need to consider confidentiality, applicable law, the circumstances of the disclosure and any relevant rights of access when dealing with information about deceased individuals.
The Caldicott principles are most useful when they guide everyday decisions rather than remaining abstract rules. They provide a practical framework for deciding how confidential information should be used, accessed and shared in health and social care.
Consider a hospital team preparing information for a multidisciplinary meeting.
Another example could involve a research, audit or service-improvement project. The fact that health information would be useful does not automatically justify unrestricted access to identifiable records. The organisation should establish the purpose, consider whether anonymised or less identifiable information would achieve the same objective, minimise the information used and identify the relevant legal and confidentiality basis.
The Caldicott principles and GDPR work alongside each other, but they are not the same framework. The UK GDPR establishes legal requirements for the processing of personal data, while the Caldicott principles provide specific information-governance guidance for handling confidential information in health and social care.
There are important areas of overlap. For example, the Caldicott principles encourage the use of only the minimum necessary information, while the UK GDPR includes the principle of data minimisation. Both frameworks also support appropriate access, security and transparency.
However, following the Caldicott principles does not automatically mean that an organisation has complied with the UK GDPR. Organisations must consider the specific legal requirements that apply to the proposed use or sharing of information.
Caldicott principles data protection practice involves considering confidentiality, information governance and data-protection requirements together. Health and social care organisations should consider whether information is necessary, whether individuals can be identified, who needs access, how information will be protected and what legal requirements apply.
Data-protection law is only one part of the wider framework. Organisations may also need to consider the common law duty of confidentiality, professional obligations, safeguarding requirements and other relevant legislation.
The Caldicott principles and Data Protection Act 2018 should also be understood as complementary rather than interchangeable. The Data Protection Act 2018 works alongside the UK GDPR and provides additional rules and conditions relating to the processing of personal data.
The Caldicott principles do not replace the Data Protection Act 2018 or other legal requirements. Instead, they provide a practical framework for making responsible decisions about confidential information within the wider legal and information-governance environment.
There is no single rule stating that confidential information may only be shared with explicit consent.
Depending on the circumstances, appropriate information sharing may take place in connection with individual care, with the person's agreement, where legislation requires or permits disclosure, for safeguarding purposes or where another lawful justification applies.
However, the exact basis for sharing should be identified rather than assumed. Staff should consider both the relevant data-protection requirements and the duty of confidentiality.
A member of staff deciding whether information should be shared should consider:
This approach supports responsible information sharing without treating confidentiality as an absolute barrier. The Caldicott principles help organisations balance the protection of confidential information with the need to make relevant information available when it is genuinely required for safe and effective care.
The Caldicott Principles work alongside data protection law to help organisations protect confidential information while ensuring it is used and shared lawfully and appropriately.
The relationship between the Caldicott principles and GDPR is complementary rather than interchangeable.
The Caldicott principles provide an ethical and practical information-governance framework for handling confidential health and care information. The UK GDPR, meanwhile, forms part of the statutory legal framework governing the processing of personal data.
There are several areas of overlap between the two frameworks. For example, Principle 3's requirement to use the minimum necessary confidential information closely supports the concept of data minimisation. Principle 8's emphasis on informing patients and service users also complements transparency requirements.
However, following the Caldicott principles does not automatically establish compliance with the UK GDPR. Organisations must separately consider the specific requirements of data-protection law.
For health data, an organisation will normally need an appropriate lawful basis under Article 6 of the UK GDPR. Because health information is generally considered special-category data, an appropriate condition under Article 9 will also usually be required, together with any additional requirements arising under the Data Protection Act 2018.
This is why Caldicott principles data protection procedures should form part of a wider information-governance and compliance system rather than operate in isolation.
It is also important not to assume that consent is always the appropriate data-protection lawful basis for healthcare. Organisations should identify the actual legal basis relevant to the particular processing activity rather than seeking consent simply as a precaution.
The relationship between the Caldicott principles and Data Protection Act 2018 is particularly important when sensitive health information is being processed.
The Data Protection Act 2018 supplements the UK GDPR and contains additional conditions and safeguards relevant to certain types of processing, including some processing involving special-category data.
The legal framework has also developed since 2018. The Data (Use and Access) Act 2025 amended parts of UK data-protection law, and its data-protection provisions were fully in force by June 2026.
Organisations should therefore work from the current UK GDPR, Data Protection Act 2018 and relevant guidance from the Information Commissioner's Office (ICO), rather than relying on training materials written before these amendments.
The Caldicott principles help organisations apply responsible information governance in practical situations. They encourage organisations to establish a clear purpose, use confidential information only when necessary, limit the amount of information used, restrict access, ensure staff understand their responsibilities, comply with the law, share information appropriately for individual care and maintain transparency.
The broad practical lesson is straightforward: the Caldicott principles help organisations decide what responsible use and sharing of confidential information should look like, while data-protection legislation establishes important legal requirements governing the processing of personal data.
Together, these frameworks help health and social care organisations protect confidentiality while ensuring that information can be used and shared appropriately when there is a legitimate need to do so.
The Caldicott principles help health and social care organisations protect confidentiality without unnecessarily preventing appropriate information sharing. They provide staff with a practical framework for deciding whether information is genuinely needed, how much should be disclosed and who should receive it.
The Caldicott principles are not a separate Act of Parliament creating eight standalone statutory offences or duties. However, they operate alongside legal requirements, and Principle 6 expressly requires compliance with the law.
In England, the National Data Guardian has also issued statutory guidance concerning the appointment and role of Caldicott Guardians. Organisations within the scope of that guidance are required to give it due regard.
Responsibility does not rest solely with a Caldicott Guardian. Anyone handling confidential health or social care information should understand and follow their responsibilities.
Organisations should also have appropriate policies, access controls, training and information-governance arrangements in place to support the responsible handling of confidential information.
The Caldicott principles and GDPR work alongside each other, but they are not the same framework.
The Caldicott principles are an information-governance framework focused particularly on confidential health and social care information. The UK GDPR is data-protection legislation that governs the processing of personal data more generally.
An organisation may need to comply with both frameworks, as well as the Data Protection Act 2018, confidentiality law and other sector-specific requirements.
Following the Caldicott principles does not, by itself, establish compliance with the UK GDPR. Organisations must consider the specific legal requirements that apply to each information-processing activity.
No. Principle 7 specifically recognises that the duty to share information for individual care can be as important as the duty to protect confidentiality.
The principles encourage appropriate information sharing rather than either unrestricted disclosure or unnecessary secrecy. Staff should share relevant information when there is a legitimate need to do so, while following the appropriate legal, confidentiality and organisational requirements.
There are eight Caldicott principles in 2026. Six were introduced following the original 1997 review, a seventh was added in 2013, and the eighth was introduced in 2020.
The 8 Caldicott principles provide a practical framework for making decisions about the use, access and sharing of confidential health and social care information.
“Minimum necessary” means using or disclosing only the amount of confidential information genuinely required for the identified purpose.
For example, if a professional needs one relevant part of a patient's record, they should not automatically receive access to the individual's entire medical history.
This approach helps reduce unnecessary exposure of confidential information while ensuring that essential information remains available to support appropriate care.
Not necessarily. Routine information sharing should normally be covered by established organisational policies and procedures.
However, the National Data Guardian recommends involving a Caldicott Guardian when a novel or difficult judgement is required. Staff should also seek appropriate advice whenever they are uncertain about confidentiality, legality or organisational policy.

The Caldicott principles are designed to protect confidential health and social care information while ensuring that necessary information can still be used and shared responsibly.
The eight principles require organisations and staff to justify why confidential information is being used, consider whether identifying information is necessary, use only the minimum required, restrict access to people who genuinely need it, ensure staff understand their responsibilities, comply with the law, recognise the importance of appropriate information sharing for individual care and keep patients and service users appropriately informed.
The principles are therefore about more than secrecy. Effective information governance depends on finding the right balance between privacy, transparency, lawful processing and safe information sharing.
The Caldicott principles and data protection responsibilities overlap, but they are not the same thing. The UK GDPR, the Data Protection Act 2018 as amended, confidentiality obligations and relevant sector-specific rules must all be considered where applicable.
Understanding the Caldicott principles gives health and social care workers a practical foundation for approaching confidential information responsibly: protect what should remain private, share what genuinely needs to be shared, use no more information than necessary and ensure people understand how information about them is being used.
For learners developing broader knowledge of confidentiality and information handling in care settings, Training Station provides online health and social care learning covering areas such as privacy, confidentiality and handling information. Training can support awareness, but completing a course does not replace workplace procedures, professional obligations, current legal guidance or the need to seek specialist advice when difficult information-sharing decisions arise.