For organisations

Consent and confidentiality

How healthcare organisations should approach asking for and recording consent to share personal data, and how UK GDPR consent differs from the common law duty of confidentiality.

If you deploy Patient Watch as a care or research organisation, you should be able to show that you have reviewed how you ask for and record consent where personal data is shared in ways that need it. That responsibility sits with your organisation as data controller for your deployment, alongside your wider information governance and your organisation data governance arrangements.

Two different ideas: GDPR consent and the duty of confidentiality

Consent under UK GDPR is one lawful basis for processing personal data. It must meet the standards in data protection law (for example freely given, specific, informed, and unambiguous). Guidance from the Information Commissioner's Office on consent explains when it is appropriate and how to document it.

Separately, health and care organisations often rely on the common law duty of confidentiality when using patient information. That duty can require consent (or another legal gateway) when information would be used in ways a patient would not reasonably expect, for example some research uses, or when sharing confidential patient information with a third party such as a carer or family member. You should clearly distinguish in your policies and procedures between consent under data protection law and consent (or other authority) under confidentiality rules.

Where this often comes up

Your organisation should describe its activities accurately in its own privacy notices, fair processing information, and internal policies. Consent is often covered within general data protection and confidentiality policies, or in a dedicated consent policy, aligned with ICO guidance and your professional obligations.

If you do not use consent for health or care processing

Many processing activities are lawfully based on grounds other than consent (for example contract, legal obligation, or legitimate interests, and for special-category health data the conditions in UK GDPR Article 9). If your organisation does not rely on consent as the lawful basis for processing health or care data in a given context, that should be documented in your records of processing and policies, with the correct basis named. Your DPO or information governance lead can confirm what to record for your setting.

For how Patient Watch Ltd processes data as platform provider, see our Privacy Policy, Records of processing (summary), and Data Security & Privacy page. They do not replace your organisation's own consent and confidentiality documentation.

This page is general information, not legal advice. For contractual terms, see the agreed Data Processing Agreement where applicable.