Examples
Worked examples
- Is an instance
A research team wants to link historic hospital records held under different NHS trusts to build a longitudinal cohort for an epidemiological study. Because full re-consent from thousands of patients, some deceased, is not practicable, and because the linkage requires identifiable fields (NHS number, date of birth) to match records accurately, the team applies to CAG for Section 251/Regulation 5 support. CAG reviews the necessity of using identifiable rather than anonymised data, the safeguards proposed (e.g. data minimisation, secure processing, restricted access), and the wider public interest, then advises the HRA, which issues the final approval alongside the study's Research Ethics Committee opinion.
- Is an instance
A national audit or disease registry (for example, a cancer registration function) needs ongoing, non-research collection of identifiable patient data from multiple NHS organisations to track incidence and outcomes over time. Because this is a non-research use, CAG's advice in this case goes to the Secretary of State for Health and Social Care (or, depending on the function, NHS England) rather than the HRA, but the underlying Section 251/COPI Regulations 2002 legal basis and CAG review process are the same.
Counter-examples
Looks similar, but isn't
- Not an instance
A study that only ever processes data that has been fully anonymised before the research team receives it, with no realistic possibility of re-identification, does not need Section 251/CAG support, because the common law duty of confidentiality attaches to identifiable (or reasonably re-identifiable) patient information, not to genuinely anonymised data.
- Not an instance
A study that can be delivered by obtaining specific, informed patient consent to the processing (rather than relying on an exception to consent) does not need CAG advice either, since Section 251 exists specifically as a route for situations where consent is not a practicable basis — it is not a shortcut to be used instead of consent when consent is in fact obtainable.
Editorial commentary
The Confidentiality Advisory Group (CAG) sits at the intersection of UK health research governance and data protection law: it is the body researchers approach when a study genuinely needs identifiable or potentially identifiable patient data and cannot obtain individual consent or rely on anonymisation. Understanding when CAG review is required — and what it does and doesn’t decide — is a recurring practical question for anyone designing an NHS-data-dependent study in England and Wales.
Origins and legal basis
Section 251 of the National Health Service Act 2006 gives the Secretary of State for Health and Social Care the power to make regulations that temporarily set aside the common law duty of confidentiality, for defined purposes, where it is not reasonably practicable to use anonymised information or to seek consent. That power is exercised through the Health Service (Control of Patient Information) Regulations 2002 (SI 2002/1438), commonly called the COPI Regulations. The two operative provisions researchers most often encounter are Regulation 5, which supports processing confidential patient information for research and other specified purposes, and Regulation 3, which supports processing for identifying, controlling, or preventing communicable disease and other public health risks.
CAG itself was established, in its current form, under the Health and Social Care Act 2012, which moved responsibility for the underlying National Information Governance Board function into a dedicated advisory committee. Since the Health Research Authority (HRA) was established, CAG has operated as a committee providing independent expert advice to the HRA on research applications, while continuing to advise the Secretary of State (and, for some data-dissemination functions, NHS England) on non-research applications.
What CAG does and does not decide
It is worth being precise about CAG’s role because it is easy to conflate with the decision itself. CAG is an advisory body: it reviews the application, considers whether identifiable data is genuinely necessary, examines the safeguards proposed, and weighs the public interest in the work against the individual’s interest in confidentiality, then issues advice. The decision-making authority sits elsewhere:
- For research applications, the HRA makes the final decision, informed by CAG’s advice alongside the relevant Research Ethics Committee (REC) opinion where the study also requires one.
- For non-research applications (registries, surveillance, and similar functions), the Secretary of State for Health and Social Care, or in some cases NHS England, is the decision-maker.
In practice the HRA places significant weight on CAG’s advice and expects to rely on it, but the two roles — advisory committee and decision-making body — remain formally separate.
How this relates to UK GDPR and the Data Protection Act 2018
Section 251/CAG approval addresses the common law duty of confidentiality, which is a separate legal obligation from data protection law. A study using confidential patient information under Section 251 support still needs an independent, lawful basis and a condition for processing special category data under UK GDPR and the Data Protection Act 2018 — Section 251 support does not substitute for GDPR compliance, and GDPR compliance does not substitute for Section 251 support where the common law duty of confidentiality also applies. Researchers planning a study that will rely on identifiable NHS data without consent typically need to address both legal bases in parallel; see CASRAI’s guide on GDPR and Data Protection Compliance in Research for the data-protection side of that analysis.
When to apply
An application for Section 251/Regulation 5 support is typically needed when a study cannot achieve its aims using anonymised or pseudonymised data alone, and obtaining consent from every individual patient is not practicable — commonly because the cohort is very large, historic, deceased, or otherwise not realistically traceable for re-consent. The application is reviewed by CAG alongside, and coordinated with, other approvals a study needs, including REC review via the HRA’s combined approvals process. Applicants should consult the HRA’s own guidance for CAG applicants directly, since the process, forms, and review timelines are set and updated by the HRA rather than fixed in the underlying legislation.
Machine-readable encodings
Use in your systems
<role vocab="credit"
vocab-identifier="https://casrai.org/dictionary/"
vocab-term="Confidentiality Advisory Group (CAG) / Section 251"
vocab-term-identifier="https://casrai.org/dictionary/term/confidentiality-advisory-group-cag-section-251" />{
"@context": "https://schema.org",
"@type": "DefinedTerm",
"@id": "https://casrai.org/dictionary/term/confidentiality-advisory-group-cag-section-251",
"name": "Confidentiality Advisory Group (CAG) / Section 251",
"identifier": "https://casrai.org/dictionary/term/confidentiality-advisory-group-cag-section-251",
"description": "The Confidentiality Advisory Group (CAG) is an independent advisory body in England and Wales that reviews applications from researchers and other organisations seeking to access or use confidential patient information without patient consent, and advises whether there is sufficient public interest to justify granting that access. CAG does not itself hold decision-making power: for research applications it advises the Health Research Authority (HRA), which makes the final decision; for non-research applications (for example, national disease registries or public health surveillance) it advises the Secretary of State for Health and Social Care, or in some cases NHS England. The legal basis CAG operates under is <strong>Section 251 of the NHS Act 2006</strong>, which allows the common law duty of confidentiality to be set aside temporarily where anonymised or pseudonymised data cannot meet the research purpose and seeking individual consent is not practicable. Section 251 is given operational effect through the <strong>Health Service (Control of Patient Information) Regulations 2002</strong> (the “COPI Regulations”) — specifically Regulation 5 (support for research and other purposes) and Regulation 3 (support for communicable disease surveillance and other public health risks). Approval obtained this way is commonly referred to as “Section 251 support,” “Regulation 5 support,” or a “CAG approval,” and the terms are used largely interchangeably in UK research-governance practice. CAG membership is drawn from a mix of clinicians, academics, and lay members, reflecting the requirement to weigh both the research/public-interest case and the patient-confidentiality interest.",
"inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
"url": "https://casrai.org/dictionary/term/confidentiality-advisory-group-cag-section-251",
"sameAs": [],
"license": "https://creativecommons.org/licenses/by/4.0/",
"publisher": {
"@id": "https://casrai.org/#organization"
},
"dateModified": "2026-07-23T06:05:42",
"inLanguage": "en"
}






