The 8 Caldicott Principles Explained: What Are They and Why Do They Matter?
The Caldicott principles provide a practical framework for protecting confidential information in health and social care while ensuring that information can be used and shared when there is a legitimate need. They help professionals decide why information is required, how much should be used, who should have access, and when sharing is appropriate.
Quick Overview
The Caldicott Principles provide a practical framework for protecting confidential health and social care information while ensuring it is shared appropriately when needed. The eight principles focus on justifying information use, minimising data, restricting access, following the law, supporting safe information sharing and keeping people informed.
This guide covers:
✅ What the Caldicott Principles are and why they are important
✅ The Caldicott principles definition, purpose and history
✅ The 8 Caldicott Principles and how they guide everyday information handling
✅ What confidential and patient-identifiable information is covered
✅ Who the principles apply to, including health and social care professionals and organisations
✅ The role and responsibilities of a Caldicott Guardian
✅ How the principles support appropriate information sharing while protecting confidentiality
✅ How the Caldicott Principles work alongside the UK GDPR and Data Protection Act 2018
There are now 8 Caldicott principles. Understanding the Caldicott principles is particularly important for anyone who handles patient or service-user information, because good confidentiality is not simply about keeping information secret. It also means ensuring that important information reaches the right people when this is necessary for safe and effective care.
Understanding the Caldicott Principles
A straightforward definition of the Caldicott Principles is that they are eight good-practice principles designed to support the appropriate use, protection and sharing of confidential health and social care information.
The purpose of Caldicott principles is to balance two important responsibilities. Organisations must protect people's privacy while also avoiding unnecessary barriers to information sharing that could interfere with safe and effective care.
So, what do the eight Caldicott principles achieve? Together, they provide a practical framework for deciding why confidential information is needed, whether it is necessary, how much information should be used, who should have access, and when sharing is appropriate.

This balance is central to Caldicott principles, confidentiality, and modern Caldicott principles information governance.
What Is Patient-Identifiable and Confidential Information?
Confidential information can include health or social care information relating to an identifiable person that they would reasonably expect to remain private.
Examples include a person's:
- name, address or NHS number;
- diagnosis and medical history;
- medication and treatment information;
- test results;
- mental health information;
- care needs and social care assessments; and
- identifiable photographs, recordings or correspondence.
Removing a person's name does not automatically make information anonymous. Other details may still allow someone to identify the individual.
Organisations should therefore consider whether information is genuinely anonymised, pseudonymised or still identifiable before deciding how it should be handled. This is an important part of applying the Caldicott principles in practice.
The History and Development of the Caldicott Principles
The Caldicott principles history began with a review chaired by Dame Fiona Caldicott in the 1990s. The review considered how patient-identifiable information was being used across the NHS as electronic systems and information sharing became increasingly important.
So, why were the Caldicott principles introduced? The original aim was to prevent the unnecessary or poorly controlled use of identifiable patient information and to establish clearer standards for protecting confidentiality.
Six principles were introduced in 1997.
A seventh principle was added in 2013. This recognised that protecting confidentiality should not result in information being unnecessarily withheld when sharing is needed for an individual's care.
In 2020, the principles were revised again, and an eighth principle was introduced to strengthen transparency about how confidential information is used.
Therefore, if someone asks how many Caldicott principles are there, the current answer is eight. The Caldicott principles have evolved over time, but their central purpose remains the responsible protection and use of confidential health and social care information.
The 8 Caldicott Principles Explained
So, what do the eight Caldicott principles achieve in practice? Together, they provide a series of practical checks that organisations and staff can use whenever confidential information is accessed, used or shared.
Understanding the 8 Caldicott principles is an important part of effective information governance. The principles help organisations justify the use of confidential information, minimise unnecessary access, support appropriate sharing and maintain public trust.
Principle 1: Justify the Purpose(s) for Using Confidential Information
There should be a clear and legitimate reason for using confidential information.
An organisation should understand why the information is required, what it will be used for and whether the purpose remains appropriate.
For example, sharing relevant information with another healthcare professional involved in a patient's treatment may have a clear care-related purpose. Using the same information for an unrelated project would require separate justification.
Existing information flows should also be reviewed periodically rather than continuing indefinitely simply because they have always existed.
Principle 2: Use Confidential Information Only When Necessary
Having a legitimate purpose does not automatically mean that identifiable confidential information must be used.
Organisations should first consider whether the objective could be achieved using anonymised or less identifiable information.
For example, if managers only need to know how many patients used a service during a particular month, they may not need individual names or complete clinical records.
This principle encourages organisations to avoid using confidential information where there is a reasonable alternative.
Principle 3: Use the Minimum Necessary Confidential Information
Where confidential information is genuinely required, only the minimum amount necessary for the specific purpose should be used.
A professional who needs one relevant part of a record should not automatically receive access to the person's entire medical history.
This principle reduces unnecessary intrusion into people's privacy and can also limit the potential consequences of accidental disclosure.
Principle 4: Access Confidential Information on a Strict Need-to-Know Basis
Only people who genuinely need confidential information for their work should have access to it.
Organisations can support this through measures such as role-based system permissions, authentication controls, audit logs and secure storage.
The principle also applies to individual behaviour. An employee should never look at a friend, relative, colleague or public figure's medical record merely because the system allows them to do so.
Technical access does not create a legitimate need to know.
Principle 5: Everyone with Access to Confidential Information Must Understand Their Responsibilities
Confidentiality is not solely the responsibility of doctors, managers or information-governance specialists.
Anyone handling confidential information should understand how to protect it. This may include clinicians, social workers, care workers, reception staff, administrators, contractors and temporary employees.
Staff awareness should cover matters such as:
- communicating information securely;
- checking recipients before sending information;
- protecting passwords and authentication details;
- avoiding inappropriate conversations in public areas;
- handling paper records securely; and
- reporting suspected information incidents.
Policies and training can support good practice, but organisations also need appropriate supervision, secure systems and effective workplace procedures.
Principle 6: Comply with the Law
Every use of confidential information must comply with applicable law.
Relevant requirements may include the UK GDPR, the Data Protection Act 2018 as amended, the common law duty of confidentiality and other legislation governing health and social care information.
Health information will commonly constitute special-category personal data. Organisations therefore need to establish the appropriate lawful basis and any additional conditions required for its processing.
The Caldicott principles do not replace these legal requirements. Applying the principles is part of responsible information governance, not an alternative to legal compliance.
Principle 7: The Duty to Share Information for Individual Care Is as Important as the Duty to Protect Patient Confidentiality
This principle addresses a common misunderstanding about confidentiality.
Information should not be shared unnecessarily, but neither should staff refuse to share relevant information simply because they are concerned about confidentiality.
For example, a GP, hospital team, pharmacist and community care provider may need to exchange appropriate information to coordinate a person's treatment safely.
Principle 7 therefore supports necessary information sharing for individual care.
However, the other principles still apply. Sharing should have a clear purpose, involve only necessary information, be limited to appropriate recipients and comply with the law.
Principle 8: Inform Patients and Service Users How Their Confidential Information Is Used
Patients and service users should understand how organisations use confidential information about them.
This includes explaining why information may be collected or shared and, where relevant, what choices the person may have.
Organisations can provide this information through privacy notices, patient information, discussions with staff or other suitable forms of communication.
The aim is transparency. People should not be unnecessarily surprised by significant uses of their confidential information.
This principle does not mean that explicit consent is required for every possible use. Consent, confidentiality and lawful processing are related but distinct issues.
Who Do the Caldicott Principles Apply To?
Caldicott Principles in Health and Social Care
The Caldicott principles health and social care framework applies particularly to confidential information collected and used in connection with health and social care services where individuals can be identified and would reasonably expect the information to remain private.

The Caldicott principles are therefore relevant to a wide range of professionals and organisations that handle confidential health and care information.
References to Caldicott principles NHS practice are common because the principles originated within the NHS. However, they now have wider relevance across health and social care.
The precise legal and governance arrangements are not identical throughout England, Scotland, Wales and Northern Ireland. Organisations should therefore follow the legislation, guidance and information-governance requirements that apply to their own jurisdiction.
Do the Caldicott Principles Apply to the Deceased?
A common question is: do Caldicott principles apply to the deceased?
Confidentiality can continue after someone dies, so information about a deceased patient should not simply be treated as public information.
The Caldicott principles deceased issue is different from ordinary UK GDPR protection because UK GDPR generally applies to information relating to living individuals. However, confidentiality obligations can continue after death, and health and care records relating to deceased people may remain subject to a duty of confidentiality.
Requests for records should therefore be considered carefully. In England and Wales, the Access to Health Records Act 1990 can provide certain rights of access to the health records of deceased individuals in specified circumstances.
The fact that a person has died does not, by itself, mean that their medical or care information can be freely disclosed.
What Information Is Covered by the Caldicott Principles?
The Caldicott principles can apply to confidential information in many different forms, including:
- clinical records;
- social care assessments;
- referrals;
- emails and electronic messages;
- photographs and recordings;
- paper documents;
- appointment information; and
- verbal communications.
The format of the information does not determine whether it is confidential. A conversation can involve confidential information just as an electronic record can.
The important questions are whether the information relates to an identifiable person, was obtained or used in connection with health or social care, and would reasonably be expected to remain private.
What Is a Caldicott Guardian?
A Caldicott Guardian is a senior person who helps ensure that confidential health and care information is used lawfully, ethically and appropriately. Guardians can provide advice when organisations face difficult decisions about protecting confidentiality or sharing information.
A Caldicott Guardian also supports the practical application of the Caldicott principles, particularly where decisions involve balancing the need to protect confidential information with the need to share information appropriately for care.
What Does a Caldicott Guardian Do?
A Caldicott Guardian may advise on:
- difficult confidentiality decisions;
- new information-sharing arrangements;
- organisational information-governance policies;
- unusual disclosure requests;
- the appropriate application of the eight Caldicott principles; and
- ethical issues surrounding the use and sharing of confidential information.
The Guardian should be sufficiently senior to challenge decisions where necessary and promote responsible information handling across the organisation.
However, responsibility for confidentiality does not transfer entirely to the Caldicott Guardian. Everyone who handles confidential information remains responsible for following relevant policies, procedures and legal requirements.
The role should also be understood alongside other responsibilities, including Caldicott principles and GDPR requirements. A Caldicott Guardian does not replace a Data Protection Officer, and the two roles may need to work together when decisions involve both confidentiality and data-protection law.
Who Needs a Caldicott Guardian?
In England, the National Data Guardian's statutory guidance applies to public bodies in the health service, adult social care and adult carer-support sectors that handle confidential patient or service-user information. It also covers certain organisations contracted by those public bodies to provide relevant health or adult social care services while handling such information.
Organisations elsewhere in the UK should check the arrangements applicable to their own jurisdiction rather than assuming that England's statutory guidance applies unchanged.
The Caldicott Guardian's role can also be relevant when considering information about deceased individuals. Caldicott principles deceased information should not automatically be treated as public information simply because the person has died. Confidentiality obligations may continue after death, so decisions about accessing or sharing such information should be considered carefully and in accordance with applicable law and guidance.
How Are the Caldicott Principles Applied in Practice?
The Caldicott Principles are applied in practice by helping health and social care professionals make responsible decisions about using, accessing and sharing confidential information.
Examples of Applying the Caldicott Principles
Consider a patient leaving hospital who needs community nursing support. The hospital has a legitimate reason to share relevant information with the community nursing team. Some identifiable information is necessary because the team needs to know whom it is caring for. However, only information relevant to the patient's continuing care should be shared, and it should be provided to authorised professionals through appropriate and secure channels.
Alternatively, imagine that an organisation wants statistics showing how many people have used a particular service. If anonymous or aggregated figures can answer the question, sharing complete identifiable records may be unnecessary. This demonstrates how the Caldicott principles encourage organisations to consider whether less identifiable information could achieve the same purpose.
These examples show that the principles are designed to guide responsible decisions rather than prevent the use or sharing of confidential information altogether. They encourage a balanced approach in which information is protected while still being available when it is genuinely needed.
When Can Confidential Information Be Shared?
There is no universal rule that confidential information can only be shared with explicit consent. Depending on the circumstances, information may appropriately be shared for individual care, safeguarding, statutory requirements or other properly justified purposes.
As part of Caldicott principles data protection practice, staff should consider:
- the purpose of the proposed disclosure;
- whether confidential information is genuinely necessary;
- the minimum amount of information required;
- who needs to receive or access it;
- the relevant legal and confidentiality basis;
- whether the information is being shared securely; and
- whether the individual should be appropriately informed.
The Caldicott principles and Data Protection Act requirements should also be considered together where personal data is involved. The Caldicott principles do not replace data-protection law, and organisations may need to consider the UK GDPR, the Data Protection Act 2018, the common law duty of confidentiality and other applicable requirements.
Where a situation is unusual, sensitive or unclear, staff should follow their organisation's procedures and seek advice from an appropriate information-governance professional or Caldicott Guardian.
Caldicott Principles and Data Protection Law
The Caldicott Principles work alongside data protection law to help health and social care organisations protect confidential information and ensure it is used and shared lawfully and appropriately.

How Do the Caldicott Principles Relate to UK GDPR?
The relationship between Caldicott principles and GDPR is complementary rather than interchangeable. UK GDPR is legislation governing the processing of personal data, while the Caldicott principles provide an information-governance framework particularly concerned with confidential health and social care information.
A useful Caldicott principles definition is that they are good-practice principles designed to help organisations decide when confidential information should be used, accessed or shared and how this should be done responsibly.
Some concepts overlap between the two frameworks. For example, Principle 3 supports the principle of data minimisation, while Principle 8 reflects the importance of transparency and keeping people informed about how their information is used.
However, following the Caldicott framework does not, by itself, establish compliance with UK GDPR. The purpose of Caldicott principles is to support responsible decisions about confidential information; they do not replace data-protection legislation or other legal obligations.
A proper Caldicott principles data protection approach therefore involves considering both the Caldicott principles and all applicable legal requirements.
What Does the Data Protection Act 2018 Require?
The relationship between Caldicott principles and Data Protection Act requirements is equally important. The Data Protection Act 2018 supplements UK GDPR and contains additional rules relevant to certain types of processing, including processing involving special-category information.
The legal framework has also changed since 2018. The Data (Use and Access) Act 2025 amended parts of UK data-protection law, with its data-protection provisions coming into force by June 2026.
Health and social care organisations should therefore rely on current legislation and guidance from the Information Commissioner's Office (ICO), rather than assuming that materials written several years ago still describe every requirement accurately.
Overall, the Caldicott principles and data-protection law should be viewed as complementary. The Caldicott principles help organisations make responsible decisions about confidential health and care information, while UK GDPR and the Data Protection Act 2018 establish important legal requirements for processing personal data.
Frequently Asked Questions About the Caldicott Principles
Why Are the Caldicott Principles Important?
The Caldicott principles help organisations protect sensitive information while supporting appropriate information sharing. They encourage staff to justify why information is needed, minimise what is used and restrict access to appropriate people.
What Is the Caldicott Principles Definition?
A useful Caldicott principles definition is that they are eight good-practice principles designed to guide the responsible use, protection and sharing of confidential health and social care information.
They help organisations make practical decisions about why information is needed, whether identifiable information is necessary, how much should be used, who should have access and when information should be shared.
Are the Caldicott Principles Legally Binding?
The eight principles are good-practice principles rather than eight separate statutory laws. However, they operate alongside legal duties, and National Data Guardian statutory guidance concerning Caldicott Guardians applies to specified organisations in England.
Who Is Responsible for Following the Caldicott Principles?
Everyone who handles relevant confidential information has responsibilities. This can include healthcare professionals, social care staff, administrators, managers and other authorised workers.
Responsibility is therefore not limited to a Caldicott Guardian. Organisations should also provide appropriate policies, training, supervision and information-governance arrangements.
What Is the Difference Between the Caldicott Principles and GDPR?
UK GDPR is data-protection legislation that applies broadly to personal data. The Caldicott principles focus particularly on the responsible use and sharing of confidential health and social care information.
There is some overlap between the two frameworks, but they are not interchangeable. Organisations may need to comply with both, as well as the Data Protection Act 2018 and applicable confidentiality obligations.
Are There Still Only Seven Caldicott Principles?
No. There are currently eight Caldicott principles. The seventh principle was added in 2013, and Principle 8 was introduced in 2020.
Do the Principles Mean Patient Information Must Never Be Shared?
No. Principle 7 specifically recognises the importance of sharing information where this is necessary for individual care.
The principles are intended to support appropriate information sharing while preventing unnecessary or excessive disclosure.
Is Consent Always Required Before Information Is Shared?
No. Consent is not the only possible basis for using or sharing information. The appropriate approach depends on the purpose, applicable law, confidentiality obligations and the circumstances.
Staff should therefore avoid assuming that consent is always required or that it is never necessary.
When Should a Caldicott Guardian Be Consulted?
A Caldicott Guardian may be particularly useful where a proposed disclosure or information use is novel, complex or difficult and routine organisational guidance does not provide a clear answer.

Key Takeaways
The purpose of Caldicott principles is to help health and social care organisations find the correct balance between protecting confidentiality and enabling appropriate information sharing.
The eight principles require organisations to justify the purpose for using confidential information, avoid using it unnecessarily, use only the minimum required, restrict access, ensure people understand their responsibilities, comply with the law, recognise the importance of sharing for individual care and keep patients and service users appropriately informed.
Understanding what are the 8 Caldicott principles is therefore more useful than simply memorising their names. Staff need to know how to apply them to everyday decisions about records, communications, access and information sharing.
The principles must also be considered alongside current Caldicott principles data protection requirements, including UK GDPR and the Data Protection Act 2018 as amended. Training can help people build awareness of confidentiality and information governance, but it does not replace workplace policies, professional responsibilities or specialist advice where complex situations arise.
For learners exploring health and social care topics through providers such as Training Facility UK, understanding the principles can provide a useful foundation for responsible information handling. Any individual course should still be checked for its precise content, assessment method, certification and recognition rather than assuming that course completion demonstrates professional competence.
Ultimately, the Caldicott principles support a simple but important goal: protect confidential information, use only what is genuinely needed, share information appropriately when care requires it, and make sure people understand how information about them is being used.