The UK National Data Opt Out: What It Is and How It Relates to the GDPR
The use of patient data plays a vital role in improving health and care services. It supports research, planning, and the delivery of safer, more effective treatment. At the same time, patients rightly expect a high level of control over how information about them is used beyond their direct care. The UK National Data Opt Out exists to balance these competing interests. It sits alongside, rather than replaces, the rights provided by the UK GDPR.
Understanding how the two interact is essential for organisations that process health and care data.

What is the National Data Opt Out?
The National Data Opt Out allows patients in England to choose whether their confidential patient information is used for purposes beyond their individual care, such as:
- health service planning,
- commissioning and policy development,
- research and population health analysis.
If a patient sets a national data opt out, their confidential patient information should not be used for these secondary purposes unless a specific exemption applies.
The opt out applies across the health and adult social care system in England and is implemented through NHS policy and directions issued to relevant organisations.
What the National Data Opt Out does not apply to
The opt out does not prevent the use of data for:
- direct care and treatment,
- safeguarding activities,
- public health emergencies,
- legal or regulatory requirements,
- uses where data is anonymised to the required standard.
This distinction is critical. The opt out is not a blanket refusal of data use, but a targeted control over how confidential patient information is used beyond care.
How the National Data Opt Out relates to GDPR
The National Data Opt Out and the UK GDPR operate in parallel, serving different but complementary purposes.
Under GDPR, processing personal data requires:
- a lawful basis under Article 6, and
- where health data is involved, a condition under Article 9.
The National Data Opt Out does not remove or replace these requirements. Instead, it acts as an additional policy control layered on top of GDPR compliance.
An organisation may have a valid lawful basis under GDPR—such as public task or legitimate interests—but still be prohibited from using patient data if a national opt out applies.
Is the National Data Opt Out a GDPR “right”?
Strictly speaking, no. It is not one of the data subject rights listed in the GDPR, such as the right to object or the right to erasure.
However, it aligns closely with GDPR principles, particularly:
- lawfulness, fairness, and transparency,
- purpose limitation,
- respect for individual autonomy.
In practice, the opt out functions as a system-wide expression of patient choice, similar in effect to an objection to certain types of processing.
Lawful bases and the opt out
Most secondary uses of patient data rely on:
- Article 6(1)(e) – public task, or
- Article 6(1)(f) – legitimate interests (in limited contexts),
alongside an Article 9 condition such as public health, research, or health and care management.
Even where these conditions are met, organisations must still check whether the national data opt out applies. If it does, and no exemption is available, the processing should not proceed.
This means lawful does not automatically mean permitted.
Sign Up Here:
Organisations within scope of the National Data Opt Out must: They will be required to provide evidence of compliance as part of their Data Security and Compliance Toolkit submission. Failure to apply the opt out correctly can result in loss of trust, regulatory scrutiny, and reputational harm—even where GDPR compliance appears technically sound. GDPR requires organisations to be open about how personal data is used. For health and care bodies, this includes explaining: Clear communication supports informed choice and reduces confusion between consent, objection, and opt-out mechanisms. The opt out reinforces the GDPR principle of accountability. Organisations must not only comply with the law but be able to demonstrate that they have respected patient preferences across complex data flows. This often requires: The UK National Data Opt Out reflects a uniquely UK approach to protecting patient trust while enabling data-driven improvement in health and care. It does not override GDPR, nor does GDPR make it redundant. Instead, the two work together. For organisations, the message is clear: GDPR compliance is necessary, but not always sufficient. Respecting the National Data Opt Out is essential to lawful, ethical, and trustworthy use of patient data. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
Responsibilities for organisations
Transparency and patient communication
How the opt out supports GDPR accountability
Final thoughts
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: