Written and maintained by CASRAI Editorial Board
Last updated
In UK health research, “information governance” (IG) is not a generic corporate compliance label — it is the specific framework the Health Research Authority (HRA) and NHS organisations use to decide whether, and how, a study can collect, hold, and share information about research participants. The HRA is explicit that “good Information Governance in research is about more than legal compliance. It underpins public trust, participant confidence, and research integrity” — treating IG as a research-design question, not just a data-protection sign-off completed after the science is settled.
What frameworks IG in research actually spans
HRA guidance for researchers and study coordinators draws on several distinct legal sources, and conflating them is a common source of delay at HRA/REC review:
- UK GDPR and the Data Protection Act 2018 — the general data-protection regime, including the specific research safeguards in the Act’s Section 19, which is what CASRAI’s Data Protection Act 2018 Section 19 entry covers in detail.
- The common law duty of confidentiality — a separate, older legal obligation that exists independently of statutory data protection law. Satisfying UK GDPR does not automatically satisfy this duty, and HRA reviewers check both.
- The Health Service (Control of Patient Information) Regulations — the legal basis behind Section 251 support, which is what lets research use confidential patient information without individual consent in defined circumstances, administered through the Confidentiality Advisory Group (CAG).
- The Human Fertilisation and Embryology (Disclosure of Information for Research Purposes) Regulations — a narrower, sector-specific disclosure regime relevant only to studies touching HFEA-regulated data.
A single study can sit under two or three of these at once — for example, a cohort study using UK GDPR as its lawful basis for routine processing, while also relying on Section 251/CAG support to access historic identifiable records without re-contacting every participant for consent.
Why this is reviewed separately from ethics
An HRA/REC application effectively runs two related but distinct assessments: a Research Ethics Committee gives a favourable opinion on the ethics of the study (see CASRAI’s Favourable Opinion (NHS REC) entry), while the HRA’s own information governance review checks that the data-handling plan itself — what’s collected, how it’s stored, who can see it, how long it’s kept, and what legal basis justifies each step — is sound and consistent with what the participant was told. A protocol can pass ethical review on its scientific merits and participant-protection design while still being sent back for gaps in its IG plan, most commonly a mismatch between what the participant information sheet promises about data handling and what the actual data-flow diagram in the application describes.
Practical resources the HRA publishes
The HRA maintains standing guidance aimed specifically at reducing this kind of mismatch: published “GDPR guidance for researchers and study coordinators,” template GDPR transparency wording that sponsors and NHS sites can adapt rather than draft from scratch, and more detailed technical material aimed at data protection officers and governance leads reviewing a study on the sponsor side. The HRA has also been piloting a consolidated Information Governance guide intended to reduce uncertainty in IRAS submissions — a signal that IG remains one of the more common friction points in UK health research applications even for experienced sponsors, not just first-time applicants.
Worked example
A university sponsors a study linking hospital admission records to a self-report survey, and wants to use identifiable NHS records to first identify and invite eligible participants before consent is obtained. Because that initial identification step requires processing confidential patient information without prior consent, the sponsor applies for Section 251 support via the Confidentiality Advisory Group alongside the standard HRA application. Once participants consent, ongoing processing of their survey and linked data is then governed by UK GDPR and the Data Protection Act 2018 in the usual way — the Section 251 route only covers the specific pre-consent identification step, not the whole study.
Counter-example
A study using only fully anonymised, aggregate hospital statistics with no patient-identifiable information at any stage does not need Section 251/CAG support, because there is no confidential patient information being processed in the first place. It still needs a UK GDPR-compliant basis if any personal data is processed upstream of the anonymisation step (for example, by whoever performs the anonymisation), and the common law duty of confidentiality may still apply to how the source records were originally obtained — anonymisation resolves the data-protection question but does not, on its own, resolve every information-governance question a study raises.
Related reading
See also Genomics England’s National Genomic Research Library for a live example of a governed research-data-access environment built around exactly this kind of layered IG framework, and the research data management pillar for the broader data-stewardship context.








