In health and social care, protecting people’s confidential information is more than a legal requirement — it is a core ethical responsibility. One of the most important roles in maintaining this trust is that of the Caldicott Guardian. Yet, outside clinical governance circles, many people are unfamiliar with what a Caldicott Guardian actually does, especially when things go wrong with data security.
Caldicott Guardians, Data Protection, and Patient Confidentiality: What You Need to Know
This article explains who Caldicott Guardians are, what they do during a data breach, how the Caldicott Principles guide their work, and how these principles connect to GDPR — even in relation to people who have died. They address some of the questions we get asked most about this key data protection role.

Who or what is a Caldicott Guardian?
A Caldicott Guardian is a senior person within a health or social care organisation responsible for protecting the confidentiality of service users’ information and ensuring personal data is used ethically and legally.
These Guardians are typically:
- Medical Directors
- Directors of Nursing
- Social care leaders
- Senior managers with operational authority
Every NHS organisation and local authority providing social services must appoint a Caldicott Guardian. Many private healthcare providers also have one.
Their role focuses on ensuring that confidential patient information is handled with respect, minimising unnecessary use or exposure. You can find out more about the work and role of a Caldicott Guardian here.
What role does a Caldicott Guardian have in a data breach?
When a personal data breach involves health information — one of the most sensitive categories of personal data — the Caldicott Guardian plays a key decision-making and advisory role.
They may:
- Help assess the severity and risk of the breach
- Guide decisions on clinical harm, distress, or reputational impact
- Ensure that the response aligns with ethical duties and professional standards
- Approve notifications to affected individuals where appropriate
- Support internal governance reviews to prevent recurrence
While the Data Protection Officer (DPO) leads compliance under law, the Caldicott Guardian ensures that patient confidentiality and care ethics sit at the heart of breach decisions.
Sign Up Here:
Originally developed in 1997 following a review led by Dame Fiona Caldicott, the Caldicott Principles guide the ethical handling of patient information. They were last updated in 2020 and now include eight principles: These principles ensure that data-sharing decisions are balanced, ethical, and justified. The Caldicott Principles and the UK GDPR are closely aligned. Both emphasise: However, their focus differs slightly: Together, they create a double layer of protection — safeguarding privacy while enabling safe, necessary information sharing for patient outcomes. A critical distinction: in the UK the GDPR does not apply to the data of deceased individuals. Once a person has passed away, their health information is no longer considered personal data under data protection law. However — the Caldicott Principles do still apply. This ensures: Healthcare confidentiality is a lifelong obligation, reinforcing public trust even after an individual’s care has ended. Caldicott Guardians occupy a crucial intersection between ethics, patient trust, and legal compliance. In a healthcare environment increasingly shaped by digital systems and data sharing, their presence ensures that decision-making remains anchored in respect for confidentiality and dignity. Whether responding to a data breach, reviewing information-sharing requests, or guiding policy, Caldicott Guardians help organisations uphold a simple but essential principle: People’s most sensitive information deserves the highest standard of care.. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
What are the Caldicott Principles?
How do the Caldicott Principles relate to GDPR?
Caldicott Principles
UK GDPR
Ethics of patient confidentiality and care
Legal compliance and individual rights
Applies specifically to health and care
Applies to all personal data across all sectors
Duties include sharing information where necessary for care
Allows processing where legally justified
How do the Caldicott Principles relate to the deceased?
Conclusion
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: