Skip to main content
v2026.11,772 entries · CC-BY 4.0

Information Governance in UK Health Research: The HRA Framework

How the Health Research Authority frames Information Governance for UK health research: UK GDPR, the Data Protection Act 2018, common law confidentiality, and Section 251/CAG support.

Ask about Information Governance in UK Health Research: The HRA Framework

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

In UK health research, “information governance” (IG) is not a generic corporate compliance label — it is the specific framework the Health Research Authority (HRA) and NHS organisations use to decide whether, and how, a study can collect, hold, and share information about research participants. The HRA is explicit that “good Information Governance in research is about more than legal compliance. It underpins public trust, participant confidence, and research integrity” — treating IG as a research-design question, not just a data-protection sign-off completed after the science is settled.

What frameworks IG in research actually spans

HRA guidance for researchers and study coordinators draws on several distinct legal sources, and conflating them is a common source of delay at HRA/REC review:

  • UK GDPR and the Data Protection Act 2018 — the general data-protection regime, including the specific research safeguards in the Act’s Section 19, which is what CASRAI’s Data Protection Act 2018 Section 19 entry covers in detail.
  • The common law duty of confidentiality — a separate, older legal obligation that exists independently of statutory data protection law. Satisfying UK GDPR does not automatically satisfy this duty, and HRA reviewers check both.
  • The Health Service (Control of Patient Information) Regulations — the legal basis behind Section 251 support, which is what lets research use confidential patient information without individual consent in defined circumstances, administered through the Confidentiality Advisory Group (CAG).
  • The Human Fertilisation and Embryology (Disclosure of Information for Research Purposes) Regulations — a narrower, sector-specific disclosure regime relevant only to studies touching HFEA-regulated data.

A single study can sit under two or three of these at once — for example, a cohort study using UK GDPR as its lawful basis for routine processing, while also relying on Section 251/CAG support to access historic identifiable records without re-contacting every participant for consent.

Why this is reviewed separately from ethics

An HRA/REC application effectively runs two related but distinct assessments: a Research Ethics Committee gives a favourable opinion on the ethics of the study (see CASRAI’s Favourable Opinion (NHS REC) entry), while the HRA’s own information governance review checks that the data-handling plan itself — what’s collected, how it’s stored, who can see it, how long it’s kept, and what legal basis justifies each step — is sound and consistent with what the participant was told. A protocol can pass ethical review on its scientific merits and participant-protection design while still being sent back for gaps in its IG plan, most commonly a mismatch between what the participant information sheet promises about data handling and what the actual data-flow diagram in the application describes.

Practical resources the HRA publishes

The HRA maintains standing guidance aimed specifically at reducing this kind of mismatch: published “GDPR guidance for researchers and study coordinators,” template GDPR transparency wording that sponsors and NHS sites can adapt rather than draft from scratch, and more detailed technical material aimed at data protection officers and governance leads reviewing a study on the sponsor side. The HRA has also been piloting a consolidated Information Governance guide intended to reduce uncertainty in IRAS submissions — a signal that IG remains one of the more common friction points in UK health research applications even for experienced sponsors, not just first-time applicants.

Worked example

A university sponsors a study linking hospital admission records to a self-report survey, and wants to use identifiable NHS records to first identify and invite eligible participants before consent is obtained. Because that initial identification step requires processing confidential patient information without prior consent, the sponsor applies for Section 251 support via the Confidentiality Advisory Group alongside the standard HRA application. Once participants consent, ongoing processing of their survey and linked data is then governed by UK GDPR and the Data Protection Act 2018 in the usual way — the Section 251 route only covers the specific pre-consent identification step, not the whole study.

Counter-example

A study using only fully anonymised, aggregate hospital statistics with no patient-identifiable information at any stage does not need Section 251/CAG support, because there is no confidential patient information being processed in the first place. It still needs a UK GDPR-compliant basis if any personal data is processed upstream of the anonymisation step (for example, by whoever performs the anonymisation), and the common law duty of confidentiality may still apply to how the source records were originally obtained — anonymisation resolves the data-protection question but does not, on its own, resolve every information-governance question a study raises.

Related reading

See also Genomics England’s National Genomic Research Library for a live example of a governed research-data-access environment built around exactly this kind of layered IG framework, and the research data management pillar for the broader data-stewardship context.

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.