A Better NHS Data Sharing Framework: Moving Beyond One-Off Agreements

Stop drowning in one-off data sharing agreements. Learn how a robust NHS data sharing framework reduces risk, improves efficiency, and ensures UK GDPR compliance.

· AI & Digital Health

Understanding the Need for Structured Data Sharing in Healthcare

In modern healthcare, collaboration is essential. GP federations, Primary Care Networks (PCNs), and acute trusts routinely share data to support integrated services. A frailty service may require primary care records to identify patients, while a children’s service needs to link community and hospital activity. Each initiative aims to improve patient outcomes through better-informed care.

Historically, each new data flow has prompted a new, separate data sharing agreement. This bilateral model, negotiated and signed on a case-by-case basis, was manageable when sharing was infrequent. Today, it has become a significant bottleneck, slowing down progress and, more critically, introducing serious information governance risks.

This approach is no longer proportionate or sustainable. It exposes organisations to compliance failures under UK General Data Protection Regulation (UK GDPR). This article explains the weaknesses of the one-off agreement model and outlines a more robust, efficient, and compliant alternative: the NHS data sharing framework.

The Risks of One-Off Data Sharing Agreements

When we review data sharing arrangements for healthcare organisations, four problems consistently emerge from a reliance on single, disconnected agreements. These issues create administrative friction and undermine legal obligations to protect patient data.

Administrative Burden Slows Essential Services

Every new service requires a new agreement. This means a fresh round of drafting, negotiation, and signing for every GP practice involved, even if the new arrangement is almost identical to a previous one. Clinical teams who are ready to launch a service often find themselves waiting weeks or months for the paperwork to be completed.

This delay is not just an inconvenience; it can stall the delivery of vital patient services. In some cases, projects may even launch without the correct governance in place because the process was too slow to keep up with clinical need, creating immediate compliance risks.

Inconsistent Governance Weakens Accountability

Because each agreement is created in isolation, they inevitably diverge over time. One document might state that data is shared in a pseudonymised format, while another, covering a similar flow, treats it as identifiable. The list of parties can differ, and definitions for the same terms can vary.

When documents describing the same processing activity contradict each other, neither can be relied upon as an accurate record. This makes it impossible for an organisation to demonstrate it has proper oversight of its data processing. This is a direct failure of the accountability principle, one of the UK GDPR's core principles.

Incorrect Controller and Processor Roles

Perhaps the most common and serious error is the incorrect assignment of data controllership. GP federations are often named as the data controller for information held within their member practices’ clinical systems. However, the GP practice, as the holder of the GMS, PMS, or APMS contract, is the controller of its registered patient records.

By signing an agreement as the controller, the federation mistakenly accepts legal accountability, transparency duties, and responsibility for handling data subject rights for records it does not control. This misallocation of roles exposes the federation to significant risk that properly belongs to the practice. Correctly identifying these roles begins with understanding your organisation's data flows.

Detached and Ineffective Risk Assessments

Under UK GDPR, a Data Protection Impact Assessment (DPIA) is required for processing likely to result in a high risk to individuals, which includes most large-scale sharing of confidential health data. In the bilateral model, the DPIA is often a separate document produced at a different time from the agreement itself.

This detachment means the risk assessment can become a tick-box exercise rather than a tool that actively shapes the data sharing arrangement. Critical risks, such as the potential for re-identifying pseudonymised data, can be missed because the two documents are not properly aligned. You can learn more about how to conduct a Data Protection Impact Assessment (DPIA) in our dedicated guide.

Implementing a Proactive NHS Data Sharing Framework

A more effective model separates the overarching rules from the specific activity. An NHS data sharing framework achieves this by establishing a single master agreement between the main parties, such as the federation and the local hospital trust. This master agreement sets out the common terms once.

Think of it as a constitutional document for data sharing. It defines the consistent rules that apply to all collaboration. Each new service is then added via a simple, short schedule that only describes the specifics of that activity, integrating the risk assessment directly into the process.

The Core Framework Agreement

The master agreement is the foundation of the framework. It is agreed once and reviewed periodically. It should contain all the common legal and operational terms, including:

  • The roles and responsibilities of each party (controller, processor).
  • Shared security standards and expectations.
  • Confidentiality and data handling obligations.
  • Agreed data retention and destruction policies.
  • A clear process for managing breaches and subject access requests.

The Individual Data Sharing Schedule

For each new service or data flow, a simple schedule is completed and appended to the master agreement. This document is concise because it does not need to repeat the core terms. It focuses only on the specifics of the processing activity:

  • The precise purpose of the data sharing.
  • The specific data items to be shared.
  • The lawful basis for processing under UK GDPR and common law.
  • A summary of the integrated risk assessment or DPIA.

This structure ensures consistency, clarifies accountability, and dramatically speeds up the process for launching new services. It is a practical example of adopting a proportionate, risk-based approach to information governance.

A Practical 5-Step Plan to Transition

Moving from a series of one-off agreements to an NHS data sharing framework does not require starting from scratch. A phased and logical approach makes the transition manageable.

  1. Audit and Catalogue: Begin by creating a central register of all current data sharing agreements your federation holds. For each one, log the parties, purpose, data flows, and review date.
  2. Analyse and Identify Gaps: Review the register to identify inconsistencies, contradictions, and gaps. This analysis will highlight the administrative duplication and governance risks, building a strong case for adopting a framework model.
  3. Develop the Master Agreement: Work collaboratively with your key partners, such as the local acute trust, to draft and agree on the terms of the master framework agreement.
  4. Design a Standard Schedule Template: Create a clear, simple template for the activity-specific schedules. Ensure it includes a mandatory section for risk assessment to integrate this crucial step.
  5. Plan a Phased Migration: As existing one-off agreements come up for their scheduled review, migrate them into the new framework by creating a schedule for each. All new sharing arrangements should use the framework from the outset.

Frequently Asked Questions about Data Sharing Frameworks

Does a framework replace the need for a DPIA?
No, it integrates it more effectively. The schedule for each high-risk activity must be supported by a DPIA. By making the risk assessment part of the schedule template, the framework ensures that the DPIA directly informs the specific data sharing arrangement.

How do we persuade partner organisations to adopt this model?
Frame the proposal around mutual benefits. An NHS data sharing framework reduces the administrative burden for all parties, speeds up the launch of joint initiatives, and provides greater assurance of collective compliance with the ICO Data Sharing Code of Practice.

What if a GP practice is hesitant to sign up?
Explain that the framework is designed to reduce their governance workload. Instead of being asked to review and sign multiple, repetitive agreements, they authorise the federation to operate on their behalf within the clear, pre-agreed rules of the framework. This provides them with stronger, more consistent protection.

The move towards integrated care systems requires more data sharing, not less. Relying on an outdated model of one-off agreements is no longer viable. It creates unnecessary work, introduces governance risks, and fails to meet the standards required by UK GDPR and NHS guidance on confidentiality.

Adopting a robust NHS data sharing framework is a strategic move from reactive paperwork to proactive and scalable governance. This approach provides the assurance needed to protect patient data, enables clinical innovation, and demonstrates true accountability. It is a foundational element for any organisation serious about managing information responsibly.

If your GP federation or PCN needs support in reviewing existing arrangements or developing a data sharing framework, our information governance consultancy services can provide practical, expert guidance.