Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us
Dictionary termTrack DProposedv2026.1

MRC Guidance on GDPR and Confidentiality in Health Research

MRC GDPR and confidentiality guidance refers to the compliance framework the UK Medical Research Council (MRC), acting through UKRI and its MRC Regulatory Support Centre (RSC), sets out for researchers processing personal data -- especially health data -- in MRC-funded or MRC-affiliated research. It treats UK GDPR/Data Protection Act 2018 (DPA 2018) compliance and the separate common law duty of confidentiality as two distinct, cumulative obligations: satisfying one does not satisfy the other, and MRC-funded research is only compliant when both are addressed. Meeting the standard means (1) identifying a lawful basis for processing under UK GDPR Article 6 -- for MRC/UKRI research this is typically 'public task' or 'legitimate interests' rather than consent, since consent as a GDPR lawful basis carries withdrawal rights that are usually impractical for long-running research datasets -- (2) satisfying a separate condition for processing special category (e.g. health) data under UK GDPR Article 9(2) and DPA 2018 Schedule 1, and (3) independently respecting the common law duty of confidence owed to anyone whose confidential information -- most often identifiable NHS or health/social care data -- is accessed or shared, which GDPR compliance alone does not discharge.

ByCASRAI Editorial Board
· Last updated 23 Jul 2026

Examples

Worked examples

  • Is an instance

    An MRC-funded cohort study analysing anonymised NHS hospital records under a data-sharing agreement with an NHS Digital-successor body relies on 'public task' as its UK GDPR Article 6 lawful basis and the DPA 2018 Schedule 1, Part 1, paragraph 4 research condition for the special category health data involved -- and separately confirms the data was obtained and is being used consistently with the common law duty of confidence owed to the patients whose records they are (e.g. via an approved secondary-use pathway rather than a breach of the confidence in which the data was originally given to clinicians).

  • Is an instance

    An MRC Unit collecting new identifiable health data directly from participants relies on informed consent as the basis for the common law duty of confidentiality (participants agree to what will be done with their information) while still needing a UK GDPR Article 6 lawful basis and Article 9(2) special category condition for the data processing itself -- MRC/UKRI guidance is explicit that participant consent to take part in a study is not automatically the same thing as 'consent' as a GDPR Article 6 lawful basis, and researchers should not assume ticking one box satisfies both.

Counter-examples

Looks similar, but isn't

  • Not an instance

    A researcher who has a valid UK GDPR lawful basis and special category condition for processing identifiable patient data, but who obtained that data by asking an NHS clinician to hand over records outside any approved research-access or information-governance pathway, is not compliant with MRC guidance even though the GDPR paperwork is in order -- the common law duty of confidentiality owed by the clinician to the patient has been breached independently of data protection law, and GDPR compliance does not cure that breach.

Editorial commentary

MRC guidance on GDPR and confidentiality sets out how researchers funded by or affiliated with the UK Medical Research Council (MRC) — one of UKRI’s seven research councils — should handle personal and health data so that it satisfies both UK data protection law and the separate, older common law duty of confidentiality. The MRC’s Regulatory Support Centre (RSC) is the body that produces and maintains this guidance for researchers, data protection officers, and research governance staff working with identifiable or potentially identifiable information about people, including through resources such as its ‘GDPR: lawful basis, research consent and confidentiality’ guidance and a companion training course of the same name.

Two separate obligations, not one

The central operational point in MRC/UKRI guidance is that UK GDPR compliance and the common law duty of confidentiality are legally distinct requirements that both apply, cumulatively, to health and social care research. As MRC/UKRI guidance puts it, GDPR does not stop researchers sharing data, but any sharing still has to be managed consistently with common law confidentiality obligations. A study can have a fully documented, textbook-correct GDPR basis for processing and still fall foul of confidentiality law if the underlying information was obtained or is being used in a way that breaches the confidence in which it was originally shared — most commonly, identifiable clinical information given to a healthcare professional in a clinical relationship. Conversely, having valid participant consent (which supports confidentiality) does not by itself supply a UK GDPR Article 6 lawful basis.

Lawful basis under UK GDPR for MRC-funded research

MRC/UKRI guidance steers researchers away from treating consent as their default UK GDPR Article 6 lawful basis. Consent as a formal GDPR lawful basis must be freely given, specific, and withdrawable at any time — conditions that sit awkwardly with long-running cohort studies, secondary analysis of archived data, or research where re-contacting participants to honour a withdrawal request is impractical or impossible. In practice, MRC/UKRI-funded research more commonly relies on:

  • Public task (Article 6(1)(e)) — available where the research organisation is a public authority or is carrying out a task in the public interest, which covers most UK universities and MRC-funded units for research purposes.
  • Legitimate interests (Article 6(1)(f)) — more often used by non-public-sector organisations, subject to a documented balancing test against the interests and rights of the individuals concerned.

Participant consent to take part in a study remains important as an ethical and common-law matter — see the informed consent entry — but MRC/UKRI guidance is explicit that this is a separate question from which GDPR Article 6 basis a controller relies on for the data processing itself.

Special category data: DPA 2018 Schedule 1

Health data is ‘special category data’ under UK GDPR Article 9, which prohibits its processing unless both an Article 9(2) condition and a corresponding UK domestic condition in DPA 2018 Schedule 1, Part 1 are met. For MRC-funded research this is typically paragraph 2 (health or social care purposes, where the processing is by or under the responsibility of a professional subject to a duty of confidentiality) or paragraph 4 (archiving, scientific research, or statistics, carried out in the public interest and in accordance with the UK GDPR’s research safeguards). Paragraph 3 covers public health purposes specifically. These Schedule 1 conditions govern whether special category processing is lawful at all; they are a different question from the Schedule 2 exemptions covered next, which govern which data-subject rights apply once processing is already lawful.

The research exemption: DPA 2018 Schedule 2, paragraph 27

Once an MRC-funded project has a lawful basis and special category condition in place, a further, separate provision — DPA 2018 Schedule 2, Part 6, paragraph 27 — can disapply specific data-subject rights (access, rectification, restriction, and objection) where complying with them would prevent or seriously impair the research, subject to the UK GDPR’s own research safeguards being met. This is a narrow, conditional exemption from certain rights, not a general exemption from GDPR, and it does not touch the common law duty of confidentiality at all — researchers relying on it still need an independent basis for handling confidential information lawfully. See the linked entry for the exemption’s exact conditions and limits.

The common law duty of confidentiality

Separately from data protection law, English common law recognises a duty of confidence owed by anyone who receives information in circumstances that import an obligation of confidence — most commonly a clinician-patient relationship. This duty predates and operates independently of the UK GDPR and DPA 2018. For MRC-funded health research, the duty of confidence is most often satisfied through one of: explicit participant consent to the specific research use, an approved secondary-use or information-governance pathway for existing NHS or health data (such as data made available through an NHS-approved trusted research environment), or — in narrower circumstances — a statutory basis that sets aside the common law duty for a defined purpose. Simply having a UK GDPR lawful basis is not, by itself, one of these routes.

Practical implications for MRC-funded projects

  • Identify and document the UK GDPR Article 6 lawful basis and, for special category data, the Article 9(2)/Schedule 1 condition separately from any consideration of consent to take part in the study.
  • Confirm and document the basis for lawfully accessing or sharing confidential information under common law — this is a distinct step, not a by-product of GDPR paperwork.
  • Where relying on the Schedule 2, paragraph 27 research exemption for specific data-subject rights, confirm the UK GDPR research safeguards are actually met, not just that the exemption is theoretically available.
  • Remember that MRC/UKRI guidance places ultimate compliance responsibility on the research organisation, not the individual researcher alone — institutional data protection officers and information governance teams are part of the compliance chain, not an optional check.

Related CASRAI content

See also the DPA 2018 in health and social care research guide for the fuller Schedule 1/Schedule 2 treatment, the GDPR and DPA 2018 Schedule 2, paragraph 27 dictionary entries, and informed consent.

Machine-readable encodings

Use in your systems

JATS XML <role> element
xml
<role vocab="credit"
      vocab-identifier="https://casrai.org/dictionary/"
      vocab-term="MRC Guidance on GDPR and Confidentiality in Health Research"
      vocab-term-identifier="https://casrai.org/dictionary/term/mrc-gdpr-and-confidentiality" />
Schema.org DefinedTerm (JSON-LD)
json
{
  "@context": "https://schema.org",
  "@type": "DefinedTerm",
  "@id": "https://casrai.org/dictionary/term/mrc-gdpr-and-confidentiality",
  "name": "MRC Guidance on GDPR and Confidentiality in Health Research",
  "identifier": "https://casrai.org/dictionary/term/mrc-gdpr-and-confidentiality",
  "description": "MRC GDPR and confidentiality guidance refers to the compliance framework the UK Medical Research Council (MRC), acting through UKRI and its MRC Regulatory Support Centre (RSC), sets out for researchers processing personal data -- especially health data -- in MRC-funded or MRC-affiliated research. It treats UK GDPR/Data Protection Act 2018 (DPA 2018) compliance and the separate common law duty of confidentiality as two distinct, cumulative obligations: satisfying one does not satisfy the other, and MRC-funded research is only compliant when both are addressed. Meeting the standard means (1) identifying a lawful basis for processing under UK GDPR Article 6 -- for MRC/UKRI research this is typically 'public task' or 'legitimate interests' rather than consent, since consent as a GDPR lawful basis carries withdrawal rights that are usually impractical for long-running research datasets -- (2) satisfying a separate condition for processing special category (e.g. health) data under UK GDPR Article 9(2) and DPA 2018 Schedule 1, and (3) independently respecting the common law duty of confidence owed to anyone whose confidential information -- most often identifiable NHS or health/social care data -- is accessed or shared, which GDPR compliance alone does not discharge.",
  "inDefinedTermSet": "https://casrai.org/dictionary/domain/compliance-regulatory#set",
  "url": "https://casrai.org/dictionary/term/mrc-gdpr-and-confidentiality",
  "sameAs": [],
  "license": "https://creativecommons.org/licenses/by/4.0/",
  "publisher": {
    "@id": "https://casrai.org/#organization"
  },
  "dateModified": "2026-07-23T07:49:14",
  "inLanguage": "en"
}

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →