The UK National Data Opt Out and GDPR

The UK National Data Opt Out: What It Is and How It Relates to the GDPR

The use of patient data plays a vital role in improving health and care services. It supports research, planning, and the delivery of safer, more effective treatment. At the same time, patients rightly expect a high level of control over how information about them is used beyond their direct care. The UK National Data Opt Out exists to balance these competing interests. It sits alongside, rather than replaces, the rights provided by the UK GDPR.

Understanding how the two interact is essential for organisations that process health and care data.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

Periodic Table of the GDPR

 


What is the National Data Opt Out?

The National Data Opt Out allows patients in England to choose whether their confidential patient information is used for purposes beyond their individual care, such as:

  • health service planning,
  • commissioning and policy development,
  • research and population health analysis.

If a patient sets a national data opt out, their confidential patient information should not be used for these secondary purposes unless a specific exemption applies.

The opt out applies across the health and adult social care system in England and is implemented through NHS policy and directions issued to relevant organisations.


What the National Data Opt Out does not apply to

The opt out does not prevent the use of data for:

  • direct care and treatment,
  • safeguarding activities,
  • public health emergencies,
  • legal or regulatory requirements,
  • uses where data is anonymised to the required standard.

This distinction is critical. The opt out is not a blanket refusal of data use, but a targeted control over how confidential patient information is used beyond care.


How the National Data Opt Out relates to GDPR

The National Data Opt Out and the UK GDPR operate in parallel, serving different but complementary purposes.

Under GDPR, processing personal data requires:

  • a lawful basis under Article 6, and
  • where health data is involved, a condition under Article 9.

The National Data Opt Out does not remove or replace these requirements. Instead, it acts as an additional policy control layered on top of GDPR compliance.

An organisation may have a valid lawful basis under GDPR—such as public task or legitimate interests—but still be prohibited from using patient data if a national opt out applies.


Is the National Data Opt Out a GDPR “right”?

Strictly speaking, no. It is not one of the data subject rights listed in the GDPR, such as the right to object or the right to erasure.

However, it aligns closely with GDPR principles, particularly:

  • lawfulness, fairness, and transparency,
  • purpose limitation,
  • respect for individual autonomy.

In practice, the opt out functions as a system-wide expression of patient choice, similar in effect to an objection to certain types of processing.


Lawful bases and the opt out

Most secondary uses of patient data rely on:

  • Article 6(1)(e) – public task, or
  • Article 6(1)(f) – legitimate interests (in limited contexts),
    alongside an Article 9 condition such as public health, research, or health and care management.

Even where these conditions are met, organisations must still check whether the national data opt out applies. If it does, and no exemption is available, the processing should not proceed.

This means lawful does not automatically mean permitted.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 


Responsibilities for organisations

Organisations within scope of the National Data Opt Out must:

  • have processes to check and apply opt out preferences,
  • ensure suppliers and data processors do the same,
  • clearly explain secondary data uses in privacy information,
  • distinguish between direct care and non-care purposes,
  • keep records demonstrating compliance and decision-making.

They will be required to provide evidence of compliance as part of their Data Security and Compliance Toolkit submission. Failure to apply the opt out correctly can result in loss of trust, regulatory scrutiny, and reputational harm—even where GDPR compliance appears technically sound.


Transparency and patient communication

GDPR requires organisations to be open about how personal data is used. For health and care bodies, this includes explaining:

  • what the National Data Opt Out is,
  • how patients can set or change their preference,
  • which uses of data it affects,
  • and which uses it does not.

Clear communication supports informed choice and reduces confusion between consent, objection, and opt-out mechanisms.


How the opt out supports GDPR accountability

The opt out reinforces the GDPR principle of accountability. Organisations must not only comply with the law but be able to demonstrate that they have respected patient preferences across complex data flows.

This often requires:

  • robust data mapping,
  • clear governance for secondary uses,
  • strong information-sharing controls,
  • and effective oversight of partners and processors.

Final thoughts

The UK National Data Opt Out reflects a uniquely UK approach to protecting patient trust while enabling data-driven improvement in health and care. It does not override GDPR, nor does GDPR make it redundant. Instead, the two work together.

For organisations, the message is clear: GDPR compliance is necessary, but not always sufficient. Respecting the National Data Opt Out is essential to lawful, ethical, and trustworthy use of patient data.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial