What Are the Caldicott Principles? The 8 Principles Explained
The Caldicott principles are eight principles designed to help health and social care organisations protect confidential information while still sharing it appropriately when there is a genuine need. They guide everyday decisions about patient records, care information, access to systems and communication between professionals.
Quick Overview
The Caldicott principles provide a practical framework for protecting confidential health and social care information while allowing appropriate information sharing. They help organisations and professionals justify the use of information, limit access, follow data protection law and share relevant information when it is needed for safe and effective care.
This guide covers:
✅ What the Caldicott Principles are and why they are important
✅ The Caldicott principles definition, purpose and history
✅ The 8 Caldicott Principles and how they guide everyday information handling
✅ What confidential and patient-identifiable information is covered
✅ Who the principles apply to, including health and social care professionals and organisations
✅ The role and responsibilities of a Caldicott Guardian
✅ How the principles support appropriate information sharing while protecting confidentiality
✅ How the Caldicott Principles work alongside the UK GDPR and Data Protection Act 2018
Understanding what the 8 Caldicott principles are is particularly useful for anyone handling sensitive health or social care information. The framework is not simply about keeping information secret; it is about ensuring that confidential information is used for a justified purpose, limited to what is necessary, protected from unnecessary access, and shared when doing so is essential for providing good care.
Understanding the Caldicott Principles
A simple Caldicott principles definition is that they are eight good-practice rules that help organisations decide how confidential health and social care information should be used, accessed and shared.
The purpose of Caldicott principles is to balance privacy with the appropriate use of information. Health and social care services often depend on information being shared between professionals, but patients and service users should also be able to trust that sensitive information about them will not be accessed or disclosed without a valid reason.
This balance lies at the heart of Caldicott principles confidentiality and wider information governance. In practice, the Caldicott principles help organisations make informed decisions about when information should be shared, who should have access to it and how it should be protected.

What Is Patient-Identifiable and Confidential Information?
Confidential information can include details that identify a patient or service user directly, as well as information that could identify them when combined with other details.
Examples include:
- a person’s name, address or NHS number;
- diagnoses and symptoms;
- test results;
- prescriptions and treatment history;
- mental health information;
- information about disabilities or care needs;
- social care assessments; and
- identifiable photographs, recordings or correspondence.
Removing someone’s name does not always make information anonymous. A combination of details, such as age, location, medical condition and place of treatment, may still reveal who the person is.
Organisations therefore need to consider whether information is genuinely anonymous, pseudonymised or still identifiable before deciding how it should be handled. The Caldicott principles support organisations in making these decisions while maintaining appropriate confidentiality and enabling information to be used when there is a legitimate need.
The History and Development of the Caldicott Principles
The Caldicott principles history began in the 1990s, when the growing use of electronic information within the NHS raised concerns about how patient-identifiable information was being used and transferred.
Dame Fiona Caldicott chaired a review of these practices. The resulting 1997 report introduced six original principles.
So, why were the Caldicott principles introduced? Their purpose was to ensure that organisations justified the use of identifiable information rather than assuming that information could be accessed or transferred simply because it was available.
The framework later developed. A seventh principle was added in 2013. It recognised that excessive caution around confidentiality could sometimes prevent information from being shared when doing so was important for an individual’s care.
In December 2020, the wording of the principles was revised and an eighth principle was introduced. Principle 8 focuses on transparency and ensuring that patients and service users understand how their information is being used.
Overall, what do the eight Caldicott principles achieve? They provide a practical framework for balancing the need to protect confidential information with the need to use and share information appropriately to support safe, effective and high-quality care.
If you are wondering how many Caldicott principles there are, the current answer is eight.
The 8 Caldicott Principles Explained
So, what do the eight Caldicott principles achieve? Together, they provide a practical series of checks for anyone deciding whether confidential information should be used or shared. The 8 Caldicott principles help health and social care organisations balance the need to protect confidentiality with the need to use information appropriately to support safe and effective care.
Understanding the Caldicott principles information governance framework is also important for organisations that manage sensitive health and social care information. The principles provide a practical approach to deciding what information can be used, who should have access to it and when sharing is justified.
Principle 1: Justify the Purpose(s) for Using Confidential Information
Every use or transfer of confidential information should have a clear and legitimate purpose.
An organisation should be able to explain why the information is needed, what it will be used for and whether the purpose remains appropriate.
For example, transferring relevant information to a specialist who is treating a patient may have a clear clinical purpose. Using the same information for an unrelated project would require separate consideration.
Long-standing information flows should also be reviewed. An arrangement should not continue automatically simply because it has existed for many years.
Principle 2: Use Confidential Information Only When Necessary
Once a purpose has been identified, the next question is whether confidential information is actually required.
Sometimes, the same objective can be achieved using anonymous or aggregated information.
For example, if a manager wants to know how many people used a particular service during a month, individual names and complete care records may not be necessary.
This principle encourages organisations to use a less intrusive alternative wherever that can reasonably achieve the same purpose.
Principle 3: Use the Minimum Necessary Confidential Information
If confidential information must be used, only the minimum amount needed should be included.
Suppose a healthcare professional needs to know a patient’s current medication. That does not necessarily mean they require unrestricted access to every detail in the person’s medical history.
The principle therefore asks professionals to consider each item of information rather than treating an entire record as automatically necessary.
Using less information can also reduce potential harm if information is accidentally disclosed.
Principle 4: Access Confidential Information on a Strict Need-to-Know Basis
Confidential information should only be available to people who genuinely need it for their role.
Organisations can support this through role-based access permissions, secure passwords, authentication controls and monitoring of access.
The principle also applies to individual behaviour. An employee should not look at the health record of a friend, family member, colleague or well-known person out of curiosity. Having technical access to a system does not create a legitimate reason to use it.
Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities
Protecting confidential information is everyone’s responsibility.
This can include doctors, nurses, social workers, care workers, administrators, receptionists, managers, contractors and other authorised staff.
People handling information should understand responsibilities such as:
- keeping login details secure;
- checking recipients before sending information;
- avoiding inappropriate conversations about patients or service users;
- protecting paper documents;
- following secure remote-working procedures; and
- reporting suspected information incidents.
Training can help staff understand these expectations, but organisations also need appropriate policies, systems and supervision.
Principle 6: Comply with the Law
The use of confidential information must comply with relevant legal requirements.
Depending on the situation, these can include UK GDPR, the Data Protection Act 2018, as amended, the common law duty of confidentiality and other legislation affecting health and social care information.
Health information is generally classed as special-category personal data. This means that organisations may need both an appropriate lawful basis and an additional condition for processing it.
The Caldicott framework does not replace the law. Instead, the Caldicott principles help organisations handle information responsibly within the wider legal and regulatory framework.
Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Patient Confidentiality
This principle makes clear that confidentiality should not become an unnecessary barrier to good care.
A person may receive support from several professionals. A GP, hospital consultant, pharmacist, community nurse and social care team may all need relevant information to provide coordinated services.
Withholding information that is genuinely necessary could itself create risks.
Principle 7 therefore encourages professionals to share relevant information confidently where individual care requires it.
This does not mean unlimited sharing. The purpose must still be justified, only necessary information should be disclosed, and access should remain restricted to appropriate people.
Principle 8: Inform Patients and Service Users How Their Confidential Information Is Used
Patients and service users should receive clear information about how and why confidential information about them is used.
Organisations may communicate this through privacy notices, patient information, websites or direct conversations.

The aim is to avoid unexpected uses of information and give people reasonable expectations about what happens to their records.
This does not mean that explicit consent must be obtained for every use of information. Consent is only one part of a wider legal and confidentiality framework. Principle 8 is primarily about transparency.
If you are wondering why were the Caldicott principles introduced, the key reason was to ensure that confidential information was properly justified, protected and used responsibly rather than being accessed or shared simply because it was available.
If you are asking how many Caldicott principles are there, there are currently eight. Together, the 8 Caldicott principles provide a framework for protecting confidentiality while ensuring that necessary information can be used and shared to support individual care and effective health and social care services.
Who Do the Caldicott Principles Apply To?
The Caldicott principles apply to organisations and professionals who handle confidential health and social care information, helping them use and share it appropriately while protecting people’s privacy.
Caldicott Principles in Health and Social Care
The Caldicott principles health and social care framework applies particularly to confidential information collected or used when providing health and social care services, where an identifiable person would reasonably expect privacy.
The principles are therefore relevant to many NHS organisations, healthcare professionals, social care providers and other organisations that handle confidential care information.
References to Caldicott principles NHS practice are common because the principles originated in the NHS. However, their use extends more broadly across health and social care.
The exact governance arrangements can differ between England, Scotland, Wales and Northern Ireland, so organisations should check the requirements that apply in their own jurisdiction.
For anyone working with confidential information, it is also useful to understand what are the 8 Caldicott principles and how they apply to the use, access and sharing of information in practice.
Do the Caldicott Principles Apply to the Deceased?
A common question is: do Caldicott principles apply to the deceased?
Confidentiality can continue after a person dies. Medical and care records should therefore not automatically be treated as freely available.
The Caldicott principles deceased position is different from ordinary UK GDPR protection because data protection legislation generally applies to living individuals.
However, other confidentiality duties can continue after death, and specific rules may govern access to records relating to deceased people.
For example, the Access to Health Records Act 1990 can provide certain rights of access to health records in England and Wales, subject to specific conditions and limitations.
This means that, although UK GDPR does not generally protect the personal data of deceased individuals, organisations should still consider their confidentiality obligations and any applicable legal requirements before disclosing information.
What Information Is Covered by the Caldicott Principles?
The Caldicott principles can apply to confidential information stored or communicated in many different forms.
This can include:
- electronic health records;
- paper documents;
- care assessments;
- referrals;
- emails;
- photographs;
- audio or video recordings; and
- verbal conversations.
What matters is whether the information relates to an identifiable person and would reasonably be expected to remain confidential.
The principles help organisations consider whether information should be used or shared, who should have access to it and what safeguards are needed to protect confidentiality.
What Is a Caldicott Guardian?
A Caldicott Guardian is a senior person who helps an organisation make appropriate decisions about confidential health and care information. The role is particularly valuable when organisations face difficult questions about whether information should be protected or shared.
A Caldicott Guardian also helps ensure that the Caldicott principles are applied consistently and appropriately within the organisation. Their work can overlap with wider requirements relating to Caldicott principles and GDPR, as well as broader information governance and Caldicott principles data protection responsibilities.
What Does a Caldicott Guardian Do?
A Caldicott Guardian may advise on:
- unusual disclosure requests;
- new information-sharing arrangements;
- difficult confidentiality decisions;
- organisational policies;
- the application of the Caldicott principles; and
- ethical considerations surrounding the use of information.
The Guardian should be sufficiently senior to question existing practices and influence organisational decisions.
However, responsibility does not rest with the Guardian alone. Everyone who handles confidential information remains responsible for using it appropriately and following relevant legal, confidentiality and information-governance requirements.
Who Needs a Caldicott Guardian?
In England, National Data Guardian statutory guidance applies to specified public bodies within health services, adult social care and adult carer support services that handle confidential patient or service-user information.
It also covers relevant organisations contracted by those bodies to deliver health or adult social care services while handling such information.
Requirements are not necessarily identical across the UK, so organisations should check the rules that apply to their particular sector and jurisdiction.
A Caldicott Guardian should work alongside other information governance and data protection roles where appropriate. The Guardian’s role is not to replace legal or data protection responsibilities, but to help the organisation make sound decisions about the use and sharing of confidential information.
How Are the Caldicott Principles Applied in Practice?
The Caldicott principles are applied in practice by helping health and social care professionals decide when confidential information can be used or shared, with whom, and how much information is necessary.
Examples of Applying the Caldicott Principles
Imagine that a patient is discharged from hospital and needs ongoing support from a community team.
The hospital has a clear reason to share relevant information: continuity of care. Identifiable information is necessary because the community team needs to know which patient it is supporting.
However, only information relevant to the person’s continuing care should be shared, and access should be limited to authorised staff who genuinely need it.
Now consider a manager analysing how many appointments were missed during the year. If anonymous statistics can answer the question, accessing complete identifiable patient records may be unnecessary.
The Caldicott principles therefore help staff choose a proportionate approach rather than assuming that either everything can be shared or nothing can be shared.
When Can Confidential Information Be Shared?
Confidential information can sometimes be shared for individual care, safeguarding, statutory requirements or other properly justified purposes.

There is no universal rule that explicit consent must always be obtained before every disclosure. The appropriate approach depends on the circumstances, the purpose of the disclosure, the relevant legal requirements and the nature of the information involved.
This is particularly important when considering the relationship between the Caldicott principles and GDPR. The principles do not replace data protection law. Instead, they work alongside the wider legal and information-governance framework to support responsible use and sharing of confidential information.
The same applies when considering Caldicott principles data protection requirements. Organisations should ensure that their handling of confidential information complies with applicable data protection and confidentiality obligations, including those under the UK GDPR and the Data Protection Act 2018.
Before sharing confidential information, professionals should consider:
- Why is the information required?
- Does the individual need to be identified?
- What is the minimum information necessary?
- Does the recipient genuinely need to know it?
- Is the disclosure lawful?
- Is the method of sharing secure?
- Has the individual been appropriately informed?
The Caldicott principles and Data Protection Act requirements should be considered together with other relevant legal and professional duties. Where the situation is difficult or unusual, advice should be obtained through the organisation’s information-governance arrangements.
Overall, the Caldicott framework encourages appropriate information sharing while ensuring that confidentiality, privacy and data protection remain central to decision-making.
Caldicott Principles and Data Protection Law
The Caldicott principles work alongside UK GDPR and the Data Protection Act 2018 to support the lawful, secure and appropriate use of confidential health and social care information.
How Do the Caldicott Principles Relate to UK GDPR?
The relationship between Caldicott principles and GDPR is complementary.
The UK GDPR forms part of the legal framework governing the processing of personal information. The Caldicott principles are good-practice principles focused particularly on the appropriate use, access and sharing of confidential health and social care information.
There are clear similarities between the two frameworks. For example, Principle 3 supports the idea of data minimisation, while Principle 8 reflects the importance of transparency.
However, following the Caldicott principles does not automatically mean that an organisation has complied with the UK GDPR. A complete Caldicott principles data protection approach therefore requires organisations to consider both their legal obligations and the practical safeguards provided by the Caldicott framework.
What Does the Data Protection Act 2018 Require?
The relationship between the Caldicott principles and Data Protection Act requirements is particularly important when health and social care information is involved.
The Data Protection Act 2018 supplements the UK GDPR and includes additional requirements relevant to certain types of special-category personal data processing.
UK data protection law has also developed since 2018. The Data (Use and Access) Act 2025 amended the data protection framework, with its data protection provisions coming into force by June 2026.
Organisations should therefore refer to current legislation and relevant guidance from the Information Commissioner’s Office (ICO), rather than relying solely on older training materials.
Overall, the Caldicott principles and data protection law work alongside each other. Organisations need to consider confidentiality, lawful processing, data minimisation, transparency, security and appropriate information sharing when handling confidential health and social care information.
Frequently Asked Questions About the Caldicott Principles
Why Are the Caldicott Principles Important?
The Caldicott principles provide a practical way to protect sensitive health and social care information without unnecessarily preventing appropriate information sharing. They encourage organisations to justify the use of confidential information, minimise what is accessed and keep information under appropriate safeguards.
Are the Caldicott Principles Legally Binding?
The eight principles are good-practice principles rather than eight separate laws. However, they operate alongside legal duties, and specified organisations in England must give due regard to statutory National Data Guardian guidance concerning Caldicott Guardians.
Who Is Responsible for Following the Caldicott Principles?
Everyone who handles relevant confidential information has responsibilities. This can include clinical staff, care workers, administrators, managers and other authorised personnel.
What Is the Difference Between the Caldicott Principles and GDPR?
UK GDPR is data protection legislation that applies broadly to personal information. The Caldicott principles and GDPR therefore have different but complementary roles. The Caldicott principles focus particularly on confidential health and social care information and how it should be used and shared.
Following the Caldicott principles does not, by itself, demonstrate compliance with the UK GDPR. Organisations must consider their separate legal obligations under data protection law as well as their confidentiality responsibilities.
Are There Still Seven Caldicott Principles?
No. There are eight Caldicott principles. The seventh principle was added in 2013, and the eighth was introduced in 2020.
Do the Caldicott Principles Mean Information Should Never Be Shared?
No. Principle 7 specifically recognises that appropriate information sharing for individual care can be just as important as protecting confidentiality.
The aim is not to prevent information sharing altogether, but to ensure that sharing is justified, lawful, proportionate and limited to those who genuinely need the information.
Does Removing a Name Make Health Information Anonymous?
Not necessarily. Other details may still make a person identifiable, particularly when several pieces of information are combined.
Organisations should therefore consider whether information is genuinely anonymous or whether a person could still be identified from the information available.
Is a Caldicott Guardian the Same as a Data Protection Officer?
No. The roles can work closely together, but they have different functions.
A Caldicott Guardian focuses particularly on the appropriate and ethical use of confidential health and care information. A Data Protection Officer has specific responsibilities under data protection law where the role is required.

Key Takeaways
The Caldicott principles provide a practical framework for protecting confidential health and social care information while allowing it to be used and shared where appropriate.
There are eight principles. They require organisations and staff to justify why confidential information is needed, avoid using it unnecessarily, use the minimum amount required, limit access, understand their responsibilities, comply with the law, recognise the importance of appropriate information sharing for individual care, and inform patients and service users about how their information is used.
Understanding what are the 8 Caldicott principles is therefore about applying them to real-world decisions, not simply memorising their titles.
The framework also needs to be understood alongside current legislation. Caldicott principles data protection responsibilities overlap with the UK GDPR, the Data Protection Act 2018 as amended, and wider confidentiality requirements, but these frameworks are not identical.
The relationship between the Caldicott principles and Data Protection Act requirements is particularly important when handling confidential health and social care information. Organisations should consider their obligations under data protection law alongside the Caldicott framework and other relevant confidentiality duties.
For learners developing their knowledge of confidentiality and health and social care practice, Skills Pack currently offers online courses, including Care Certificate Standards Fundamentals, which contains learning on data protection and confidentiality. Such learning may support awareness, but a certificate of completion should not automatically be treated as a regulated qualification, professional licence or proof that a person is competent to make complex information-governance decisions.
Ultimately, the Caldicott principles help professionals achieve a sensible balance: protect confidential information, use no more information than necessary, share it when legitimate care needs require it, and ensure that people understand how information about them is being handled.