In June 2016, the National Data Guardian, Dame Fiona Caldicott, published her Review of Data Security, Consent and Opt-Outs in relation to patient confidential data. She did so at the request of the Secretary of State for Health who had asked for recommendations on new data security standards, methods for compliance testing, and a new consent or opt-out model for sharing patient data for care and other purposes, such as services commissioning and research.Dame Fiona is best known for her six Caldicott Principles for protecting confidentiality first issued in 1997. A further report in 2013 added a seventh Principle – that the duty to share information can be as important as the duty to protect patient confidentiality – but it seems that the message has been not getting through. Furthermore, the fallout from the ill-conceived and poorly executed care.data initiative is widespread in England. Although the 2016 Review did not address this directly, it undoubtedly cast a pall over proceedings (see further: Safe data, safe care).

