Skip to main content

Tyne Academy

What Are the Caldicott Principles? The 8 Principles Explained

Caldicott Principles

The Caldicott principles are eight good-practice principles that help health and social care organisations protect confidential information while ensuring it can be used and shared appropriately. They guide decisions about why information is needed, how much should be used, who should have access to it and when sharing may be necessary to support safe and effective care.

Quick Overview
The Caldicott Principles are eight good-practice principles that help health and social care professionals protect confidential information while ensuring it is shared appropriately when needed. They focus on justifying information use, minimising data, limiting access, following the law, supporting safe information sharing and keeping people informed.

This guide covers:
✅ What the Caldicott Principles are and why they are important
✅ The Caldicott principles definition, purpose and history
✅ The 8 Caldicott Principles and how they guide everyday information handling
✅ What confidential and patient-identifiable information is covered
✅ Who the principles apply to, including health and social care professionals and organisations
✅ The role and responsibilities of a Caldicott Guardian
✅ How the principles support appropriate information sharing while protecting confidentiality
✅ How the Caldicott Principles work alongside the UK GDPR and Data Protection Act 2018

Understanding the 8 Caldicott principles is useful for anyone who works with patient or service-user information. Rather than treating confidentiality as a simple instruction never to disclose information, the Caldicott principles promote a balanced approach: protect people’s privacy while ensuring that legitimate information sharing is not unnecessarily prevented when it is important for their care.

Understanding the Caldicott Principles

A practical Caldicott principles definition is that they are eight good-practice principles for the responsible use, protection and sharing of confidential information within health and social care.

The purpose of Caldicott principles is to encourage organisations to think carefully before using or sharing identifiable information. Staff should be able to explain why the information is required, whether identification is necessary, how much information is needed, who should receive it and whether the proposed use is lawful.

So, what do the eight Caldicott principles achieve? Together, they provide a structured approach to making decisions about confidential information. They help organisations protect people’s privacy while ensuring that necessary information can still be shared appropriately to support safe and effective care.

This makes Caldicott principles confidentiality part of a wider system of responsible information handling. Similarly, Caldicott principles information governance involves much more than keeping computer systems secure. It covers the decisions, responsibilities, policies and procedures surrounding confidential information throughout its use.

What Is Patient-Identifiable and Confidential Information?

Confidential health and social care information can include information that identifies an individual directly or could allow them to be identified when combined with other details.

Examples include:

  • names, addresses and NHS numbers;
  • diagnoses and medical histories;
  • prescriptions and treatment records;
  • test results;
  • mental health information;
  • social care assessments;
  • information about disabilities or support needs; and
  • identifiable photographs, recordings or correspondence.

Simply removing someone’s name does not necessarily make information anonymous. Details such as age, location, diagnosis and treatment provider may still identify a person.

It is therefore important to distinguish properly anonymised information from identifiable or pseudonymised information when deciding how information should be handled.

The History and Development of the Caldicott Principles

The Caldicott principles history dates back to the 1990s. Dame Fiona Caldicott chaired a review examining how patient-identifiable information was being used throughout the NHS.

So, why were the Caldicott principles introduced? The increasing use of electronic information systems and the movement of patient data created a need for clearer safeguards. The original review aimed to ensure that identifiable information was used only when justified and that unnecessary information was not routinely circulated.

Six principles resulted from the 1997 review.

A seventh principle was introduced following a further information-governance review in 2013. It addressed concerns that excessive caution about confidentiality could prevent professionals from sharing information required for effective individual care.

In 2020, the wording of the principles was updated and an eighth principle was introduced, with a greater focus on transparency and informing patients and service users about how their confidential information is used.

Therefore, if you are wondering how many Caldicott principles are there, the current answer is eight. The Caldicott principles provide a practical framework for balancing confidentiality with the responsible sharing of information when it is genuinely needed.

The 8 Caldicott Principles Explained

So, what do the eight Caldicott principles achieve? Together, they provide a structured way to consider whether confidential information should be used or disclosed and, where it should be, how this can be done responsibly. The 8 Caldicott principles help organisations balance the need to protect confidentiality with the need to use and share information appropriately for health and social care.

Principle 1: Justify the Purpose(s) for Using Confidential Information

There should be a clear reason for every proposed use or transfer of confidential information.

An organisation should establish why the information is needed, document significant uses and periodically review arrangements that continue over time.

For example, sharing relevant information with a specialist treating a patient may have a clearly justified purpose. Using the same information for a different project would require its own justification.

The existence of information is not, by itself, a reason to use it.

Principle 2: Use Confidential Information Only When Necessary

After establishing a legitimate purpose, the organisation should ask whether identifiable confidential information is actually required.

Sometimes, anonymised or aggregated information can achieve the same goal. For example, managers analysing how many people use a particular service may need totals and trends rather than patients’ names and complete records.

Principle 2 therefore encourages organisations to consider less intrusive alternatives before using confidential information.

Principle 3: Use the Minimum Necessary Confidential Information

If confidential information is necessary, only the minimum required for the specific purpose should be used.

Imagine that a healthcare professional needs information about a person’s current medication. It does not automatically follow that the professional needs unrestricted access to every detail recorded throughout the person’s medical history.

Applying this principle can help protect privacy and reduce the amount of information that could potentially be exposed if an error or security incident occurs.

Principle 4: Access Confidential Information on a Strict Need-to-Know Basis

Only people who genuinely require confidential information for their work should have access to it.

This can be supported through measures such as role-based permissions, authentication, secure record-keeping and access logs.

The rule also applies to personal behaviour. An employee must not open the record of a friend, family member, neighbour, colleague or well-known person simply out of curiosity.

Being technically capable of viewing information does not establish a legitimate need to know.

Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities

Information security depends on people as well as technology.

Anyone handling confidential information should understand their responsibilities. This can include doctors, nurses, social workers, carers, receptionists, administrators, contractors and other authorised staff.

Responsibilities may include checking recipients before sending information, keeping passwords secure, avoiding inappropriate conversations, storing documents safely and reporting suspected information breaches.

Training can build awareness, but organisations also need suitable policies, supervision and procedures to translate knowledge into good workplace practice.

This is an important part of Caldicott principles information governance, which involves not only technology and security but also people’s behaviour, organisational processes and decision-making.

Principle 6: Comply with the Law

Every use of confidential information must be lawful.

Depending on the circumstances, relevant requirements can include UK GDPR, the Data Protection Act 2018 as amended, the common law duty of confidentiality and applicable health or social care legislation.

Health information generally receives additional protection because it is special-category personal data.

The Caldicott framework therefore does not replace legal requirements. An organisation cannot justify an unlawful disclosure merely by arguing that it appears consistent with another Caldicott principle.

Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Patient Confidentiality

Principle 7 highlights one of the most important features of modern confidentiality practice.

Protecting information does not mean refusing to share it whenever uncertainty arises.

A patient might receive care from a GP, hospital consultant, pharmacist, community nurse and social care professional. Safe and coordinated care can depend on relevant information being shared between these professionals.

Unnecessarily withholding important information could create its own risks.

This principle therefore supports appropriate information sharing for individual care while still requiring the other principles to be followed. Information shared should remain necessary, proportionate, lawful and limited to appropriate recipients.

Principle 8: Inform Patients and Service Users How Their Confidential Information Is Used

People should understand how and why confidential information about them is being used.

Organisations should provide accessible and appropriate information about normal uses and sharing arrangements, together with any relevant choices available to individuals.

This could involve privacy information, patient leaflets, online information or direct conversations where appropriate.

The aim is to reduce unexpected uses of information. Principle 8 does not mean that explicit consent must be obtained every time information is processed or shared, but people should not unnecessarily be kept unaware of significant uses.

If you are asking how many Caldicott principles are there, there are currently eight.

The 8 Caldicott principles work together rather than as isolated rules. They encourage organisations to justify the purpose of using confidential information, consider whether it is necessary, minimise what is used, restrict access, ensure people understand their responsibilities, comply with the law, support appropriate sharing for individual care and keep patients and service users informed.

Who Do the Caldicott Principles Apply To?

The Caldicott Principles apply to organisations and professionals who handle confidential health and social care information, helping them protect privacy and share information responsibly. 

Caldicott Principles in Health and Social Care

The Caldicott principles health and social care framework is primarily concerned with information collected in the provision of health and social care services where an identifiable patient or service user would reasonably expect privacy.

The Caldicott principles can therefore be relevant to NHS organisations, healthcare professionals, social care organisations and other bodies that handle appropriate confidential information.

The phrase Caldicott principles NHS is common because the framework originated within the NHS. However, its relevance now extends more broadly across health and social care.

Governance requirements and arrangements for Caldicott Guardians can differ across England, Scotland, Wales and Northern Ireland. Organisations should therefore check the rules and guidance that apply in their particular jurisdiction rather than assuming that arrangements are identical throughout the UK.

Do the Caldicott Principles Apply to the Deceased?

A frequently asked question is: do Caldicott principles apply to the deceased?

Confidentiality does not automatically end when someone dies. Health and care records relating to deceased people can remain subject to a duty of confidentiality, so information about a deceased person should not simply be treated as public.

The Caldicott principles deceased position is therefore different from ordinary UK GDPR protection. UK GDPR generally applies to information concerning living individuals, but separate confidentiality duties can continue after death.

In England and Wales, the Access to Health Records Act 1990 can also provide certain people with rights to access the health records of someone who has died, subject to relevant conditions and limitations.

A relative should therefore not assume that a deceased person’s complete health record automatically becomes available to the family. Requests for access need to be considered in accordance with the applicable legal and confidentiality requirements.

What Information Is Covered by the Caldicott Principles?

The Caldicott principles can apply to confidential information in many different forms, including electronic health records, paper files, referrals, assessments, emails, photographs, recordings and spoken communications.

The key issue is not the format of the information but its nature, whether the individual can be identified and whether they would reasonably expect the information to remain confidential.

Good Caldicott principles health and social care practice therefore involves protecting confidential information regardless of whether it is stored electronically, written on paper or communicated verbally.

What Is a Caldicott Guardian?

A Caldicott Guardian is a senior person who helps an organisation use and share confidential health and care information appropriately. The Guardian can provide specialist support when difficult legal, ethical or practical questions arise.

The role is closely connected with the Caldicott principles, particularly when an organisation needs to balance confidentiality with the legitimate need to share information for care or other justified purposes.

What Does a Caldicott Guardian Do?

A Caldicott Guardian may advise on:

  • unusual disclosure requests;
  • new information-sharing arrangements;
  • confidentiality and information-governance policies;
  • difficult decisions about using or sharing confidential information;
  • the appropriate application of the eight Caldicott principles; and
  • ethical considerations surrounding the use of confidential information.

The Guardian should have sufficient seniority to question proposed practices and influence organisational decisions.

However, appointing a Caldicott Guardian does not remove responsibility from other staff. Everyone who handles confidential information continues to have their own responsibilities and must follow relevant policies, procedures and legal requirements.

Caldicott Principles and GDPR

The relationship between Caldicott principles and GDPR is important because a Caldicott Guardian may need to consider both confidentiality and data-protection requirements when advising on information use or sharing.

The Caldicott principles provide an information-governance framework for confidential health and care information, whereas UK GDPR forms part of the legal framework governing the processing of personal data. They are complementary rather than interchangeable.

Caldicott Principles Data Protection

A Caldicott Guardian may also be involved in decisions where Caldicott principles data protection considerations overlap. For example, a proposed use of identifiable health information may need to be assessed in terms of necessity, minimisation, access controls, transparency, confidentiality and the applicable legal requirements.

The Guardian does not replace a Data Protection Officer or provide a substitute for specialist legal or data-protection advice. Where appropriate, these roles may work together.

Caldicott Principles and Data Protection Act

The Caldicott principles and Data Protection Act relationship is also relevant when confidential health information constitutes personal data. Organisations may need to consider the UK GDPR, the Data Protection Act 2018 as amended, the common law duty of confidentiality and other applicable legislation.

The Caldicott Guardian can help the organisation consider the confidentiality and ethical dimensions of a decision, while ensuring that relevant legal and data-protection requirements are also addressed.

Who Needs a Caldicott Guardian?

In England, statutory National Data Guardian guidance applies to specified public bodies in health services, adult social care and adult carer-support services that handle confidential information. Certain organisations contracted by those public bodies to provide relevant services are also within scope.

It would therefore be inaccurate to say that every private organisation throughout the UK automatically has precisely the same legal requirement to appoint a Caldicott Guardian. Organisations should establish what applies to their particular sector and jurisdiction.

Where an organisation is outside the scope of the English statutory guidance, it may still consider appointing a Caldicott Guardian or establishing an equivalent Caldicott function as part of good information governance.

How Are the Caldicott Principles Applied in Practice?

The Caldicott Principles are applied in practice by helping health and social care professionals make responsible decisions about using, accessing and sharing confidential information.

Examples of Applying the Caldicott Principles

Consider a person who has been discharged from hospital but needs continuing support from a community care team.

The hospital has a clear purpose for sharing the information: ensuring continuity of care. Some identifiable information is necessary because the community team needs to know whom it is supporting. However, only information relevant to that person’s care should be shared, and access should be restricted to appropriate staff.

Now consider a service manager analysing appointment waiting times. The purpose may be legitimate, but individual patient identities might not be necessary. Anonymised or aggregated information could potentially provide the required data instead.

These examples demonstrate how the Caldicott principles encourage thoughtful and proportionate decisions rather than creating a blanket ban on information sharing.

When Can Confidential Information Be Shared?

Confidential information may sometimes be shared for individual care, safeguarding, statutory duties or other properly justified purposes. There is no single rule stating that explicit consent must always be obtained before every disclosure.

Staff should instead consider why the information is being shared, whether it is necessary, how much information is required, whether the recipient has a legitimate need to know, and whether the disclosure is lawful and secure.

When considering Caldicott principles and GDPR, staff should remember that confidentiality and data protection are related but separate requirements. Depending on the circumstances, the organisation may need to consider UK GDPR, the common law duty of confidentiality and other applicable legal requirements.

A sound Caldicott principles data protection approach therefore involves considering both responsible information governance and the relevant legal framework. The Caldicott principles and Data Protection Act requirements should also be considered where applicable, including the Data Protection Act 2018 as amended.

Where the position is unclear or unusually complex, staff should follow organisational guidance and seek advice from an appropriate information-governance specialist or Caldicott Guardian.

Caldicott Principles and Data Protection Law

The Caldicott Principles work alongside data protection law to help health and social care organisations protect confidential information and ensure it is used and shared lawfully and appropriately. 

How Do the Caldicott Principles Relate to UK GDPR?

The relationship between Caldicott principles and GDPR is complementary rather than interchangeable. UK GDPR is legislation governing the processing of personal data, while the Caldicott principles provide an information-governance framework particularly concerned with confidential health and social care information.

A useful Caldicott principles definition is that they are good-practice principles designed to help organisations decide when confidential information should be used, accessed or shared and how this should be done responsibly.

Some concepts overlap between the two frameworks. For example, Principle 3 supports the principle of data minimisation, while Principle 8 reflects the importance of transparency and keeping people informed about how their information is used.

However, following the Caldicott framework does not, by itself, establish compliance with UK GDPR. The purpose of Caldicott principles is to support responsible decisions about confidential information; they do not replace data-protection legislation or other legal obligations.

A proper Caldicott principles data protection approach therefore involves considering both the Caldicott principles and all applicable legal requirements.

What Does the Data Protection Act 2018 Require?

The relationship between Caldicott principles and Data Protection Act requirements is equally important. The Data Protection Act 2018 supplements UK GDPR and contains additional rules relevant to certain types of processing, including processing involving special-category information.

The legal framework has also changed since 2018. The Data (Use and Access) Act 2025 amended parts of UK data-protection law, with its data-protection provisions coming into force by June 2026.

Health and social care organisations should therefore rely on current legislation and guidance from the Information Commissioner’s Office (ICO), rather than assuming that materials written several years ago still describe every requirement accurately.

Overall, the Caldicott principles and data-protection law should be viewed as complementary. The Caldicott principles help organisations make responsible decisions about confidential health and care information, while UK GDPR and the Data Protection Act 2018 establish important legal requirements for processing personal data.

Frequently Asked Questions About the Caldicott Principles

Why Are the Caldicott Principles Important?

The Caldicott principles help organisations protect sensitive information while still enabling appropriate information sharing. They encourage staff to justify why information is being used, avoid unnecessary access or disclosure, and ensure that information is handled responsibly.

Are the Caldicott Principles Legally Binding?

The eight principles themselves are good-practice principles rather than eight separate statutory offences or legal provisions. However, they operate alongside legal duties, and statutory National Data Guardian guidance concerning Caldicott Guardians applies to specified organisations in England.

Who Is Responsible for Following the Caldicott Principles?

Everyone who handles relevant confidential information has responsibilities. This includes clinical, care, administrative and other authorised staff, not just Caldicott Guardians.

What Is the Difference Between the Caldicott Principles and GDPR?

UK GDPR is data-protection legislation covering the processing of personal data generally. The Caldicott principles focus particularly on the responsible use and sharing of confidential health and social care information. Both frameworks may apply to the same activity.

The relationship between Caldicott principles and GDPR is therefore important. Although there is some overlap, following the Caldicott principles does not automatically mean that an organisation has met all its UK GDPR requirements. Organisations should consider both frameworks where applicable.

Are There Six, Seven or Eight Caldicott Principles?

There are eight Caldicott principles today. Six were introduced in 1997, a seventh followed in 2013, and Principle 8 was introduced in 2020.

Do the Caldicott Principles Prevent Patient Information from Being Shared?

No. Principle 7 specifically recognises that appropriate information sharing can be essential for individual care.

The principles are intended to support responsible information sharing rather than prevent it altogether. Information should be shared when there is a proper reason to do so and in accordance with the relevant confidentiality and legal requirements.

Does Removing a Patient’s Name Make Information Anonymous?

Not necessarily. Other details may still allow the person to be identified. Organisations therefore need to consider whether information is genuinely anonymised, pseudonymised or still identifiable.

When Should a Caldicott Guardian Be Involved?

A Caldicott Guardian is particularly useful where a proposed use or disclosure involves a novel, difficult or sensitive judgement that routine policies do not resolve clearly.

Key Takeaways

The Caldicott principles provide a practical framework for balancing confidentiality with appropriate information use in health and social care.

The eight principles require organisations and staff to justify why confidential information is needed, avoid using identifiable information unnecessarily, use only the minimum required, restrict access to people who need it, understand their responsibilities, comply with the law, share appropriately for individual care and inform people about how their information is used.

Understanding what are the 8 Caldicott principles is therefore not simply an exercise in memorising eight statements. Their value comes from applying them to everyday situations involving records, referrals, communications and information sharing.

The principles also need to operate alongside current law. Caldicott principles data protection responsibilities interact with UK GDPR, the Data Protection Act 2018 as amended and confidentiality duties, but these frameworks are not identical.

For learners developing their knowledge of health, care or information-handling topics, Tyne Academy provides an online course platform covering a range of subjects. Learning can help build awareness of confidentiality and professional responsibilities, but individual courses should be checked for their precise content, assessment and recognition, and course completion should not be treated as a substitute for workplace procedures or professional advice.

Ultimately, the Caldicott principles help organisations answer a practical question: how can confidential information be protected without preventing the appropriate information sharing that good health and social care may require?