Skip to content
Company Logo

Information Sharing

Effective sharing of information between practitioners and organisations and agencies is essential for early identification of need, assessment and service provision to keep children safe. Safeguarding Practice Reviews have highlighted that missed opportunities to record, understand the significance of and share information in a timely manner can have severe consequences for the safety and welfare of children.

Practitioners should be proactive in sharing information as early as possible to help identify, assess and respond to risks or concerns about the safety and welfare of children, whether this is when problems are first emerging, or where a child is already known to local authority children's social care (e.g. they are being supported as a child in need or have a child protection plan).

Practitioners should also be alert to sharing important information about any adults with whom that child has contact, which may impact on the child's safety or welfare.

Information sharing is also essential for the identification of patterns of behaviour when a child is at risk of going missing or has gone missing; when multiple children appear associated to the same context or locations of risk; or in relation to children in the secure estate where there may be multiple local authorities involved in a child’s care.

Those providing services to adults and children, for example GP's, may be concerned about the need to balance their duties to protect children from harm and their general duty of care towards their patient or service user, e.g. a parent. Some practitioners and staff face the added dimension of being involved in caring for or supporting more than one family member - the abused child, siblings, and an alleged abuser. However, in English Law, where there are concerns that a child is, or may be, at risk of significant harm, the overriding consideration is to safeguard the child (The Children Act 1989).

The General Data Protection Regulations (GDPR) and the Data Protection Act 2018 supersede the Data Protection Act 1998. Practitioners must have due regard to the relevant data protection principles which allow them to share personal information.

The GDPR and Data Protection Act 2018 place greater significance on the need for organisations to be transparent and accountable in relation to their use of data. All organisations handling personal data must ensure they have comprehensive and proportionate arrangements for collecting, storing, and sharing information in place. This also includes arrangements on informing service users about the information they will collect and how this may be shared.

The GDPR and Data Protection Act 2018 do not prevent, or limit, the sharing of information for the purposes of keeping children and young people safe.

To effectively share information:

  • All practitioners should be confident of the processing conditions which allow them to store, and share, the information that they need to carry out their safeguarding role. Information which is relevant to safeguarding will often be data which is considered 'special category personal data' meaning it is sensitive and personal;
  • Where practitioners need to share special category personal data, they should be aware that the Data Protection Act 2018 includes 'safeguarding of children and individuals at risk' as one of conditions that allows practitioners to share information with others without consent:
    • Information can be shared legally without consent, if a practitioner is unable to, cannot be reasonably expected to gain consent from the individual, or if to gain consent could place a child at risk;
    • Relevant personal information can also be shared lawfully if it is to keep a child or individual at risk safe from neglect or physical, emotional or mental harm, or if it is protecting their physical, mental, or emotional well-being.

Practitioners looking to share information without consent should consider which processing condition in the Data Protection Act 2018 is most appropriate in the particular circumstances of the case. This may be the safeguarding processing condition or another relevant provision.

  1. All children have a right to be protected from abuse and neglect. Protecting a child from such harm takes priority over protecting their privacy, or the privacy rights of the person(s) failing to protect them. The UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 (DPA) provide a framework to support information sharing where practitioners have reason to believe failure to share information may result in the child being at risk of harm;
  2. When you have a safeguarding concern, wherever it is practicable and safe to do so, engage with the child and/or their carer(s), and explain who you intend to share information with, what information you will be sharing and why. You are not required to inform them, if you have reason to believe that doing so may put the child at increased risk of harm (e.g., because their carer(s) may harm the child, or react violently to anyone seeking to intervene, or because the child might withhold information or withdraw from services);
  3. You do not need consent to share personal information about a child and/or members of their family if a child is at risk or there is a perceived risk of harm. You need a lawful basis to share information under data protection law, but when you intend to share information as part of action to safeguard a child at possible risk of harm, consent may not be an appropriate basis for sharing. It is good practice to ensure transparency about your decisions and seek to work cooperatively with a child and their carer(s) wherever possible. This means you should consider any objection the child or their carers may have to proposed information sharing, but you should consider overriding their objections if you believe sharing the information is necessary to protect the child from harm;
  4. Seek advice promptly whenever you are uncertain or do not fully understand how the legal framework supports information sharing in a particular case. Do not leave a child at risk of harm because you have concerns you might be criticised for sharing information. Instead, find out who in your organisation/agency can provide advice about what information to share and with whom. This may be your manager/supervisor, the designated safeguarding children professional, the data protection/information governance lead (e.g., Data Protection Officer), Caldicott Guardian, or relevant policy or legal team. If you work for a small charity or voluntary organisation, follow the NSPCC's safeguarding guidance;
  5. When sharing information, ensure you and the person or agency/organisation that receives the information take steps to protect the identities of any individuals (e.g., the child, a carer, a neighbour, or a colleague) who might suffer harm if their details became known to an abuser or one of their associates;
  6. Only share relevant and accurate information with individuals or agencies/organisations that have a role in safeguarding the child and/or providing their family with support, and only share the information they need to support the provision of their services. Sharing information with a third party rarely requires you to share an entire record or case-file – you must only share information that is necessary, proportionate for the intended purpose, relevant, adequate and accurate;
  7. Record the reasons for your information sharing decision, irrespective of whether or not you decide to share information. When another practitioner or organisation requests information from you, and you decide not to share it, be prepared to explain why you chose not to do so. Be willing to reconsider your decision if the requestor shares new information that might cause you to regard information you hold in a new light. When recording any decision, clearly set out the rationale and be prepared to explain your reasons if you are asked.

Information on children and families can be held in many different ways, including in case records or electronically on a variety of IT systems which are accessible to different practitioners. Information may be shared face to face, over the telephone or via secure email. Whenever information is shared, a record of this should be made in the individual's record and the information should not be kept any longer than is necessary. In some rare circumstances, this may be indefinitely, but if this is the case, there should be a review process scheduled at regular intervals to ensure data is not retained where it is unnecessary to do so.

Working Together to Safeguard Children states:

You do not need consent to share personal information. It is one way to comply with the data protection legislation, but not the only way. The UK GDPR provides a number of bases for sharing personal information. It is not necessary to seek consent to share information for the purposes of safeguarding and promoting the welfare of a child provided that there is a lawful basis to process any personal information required.

The legal bases that may be appropriate for sharing data in these circumstances could be 'legal obligation' or 'public task' which includes performance of a task in the public interest or the exercise of official authority. Each of the legal bases under GDPR has different requirements.

It is good practice to be transparent and to inform parents/carers that you are sharing information for these purposes and seek to work co-operatively with them, where it is safe to do so.

Working Together to Safeguard Children states that:

  • All organisations and agencies should have arrangements in place that set out clearly the processes and the principles for sharing information. The arrangement should cover how information will be shared within their own organisation/agency; and with others who may be involved in a child's life;
  • All practitioners should not assume that someone else will pass on information that they think may be critical to keeping a child safe. If a practitioner has concerns about a child's welfare and considers that they may be a child in need or that the child has suffered or is likely to suffer significant harm, then they should share the information with local authority children's social care and/or the police. All practitioners should be particularly alert to the importance of sharing information when a child moves from one local authority into another, due to the risk that knowledge pertinent to keeping a child safe could be lost;
  • The General Data Protection Regulation (GDPR) provides a number of bases for sharing personal information. It is not necessary to seek consent to share information for the purposes of safeguarding and promoting the welfare of a child provided that there is a lawful basis to process any personal information required. The legal bases that may be appropriate for sharing data in these circumstances could be ‘legal obligation’ or ‘public task’ which includes the performance of a task in the public interest or the exercise of official authority. Each of the lawful bases under GDPR has different requirements. In some circumstances, it may be appropriate to obtain consent to share data but it is important to note that the GDPR sets a high standard for consent which is specific, time limited and can be withdrawn (in which case the information would have to be deleted).

Information Sharing: Advice for Safeguarding Practitioners supports frontline practitioners working in child or adult services who have to make decisions about sharing personal information on a case-by-case basis. The guidance can be used to supplement local guidance and encourage good practice in information sharing.

The UK General Data Protection Regulation and Data Protection Act 2018 provides a framework to ensure that personal information is shared and processed appropriately. They ensure personal information is obtained and processed fairly and lawfully; only disclosed in appropriate circumstances; is accurate, relevant and not held longer than necessary; and is kept securely.

They balance the rights of the information subject (the individual whom the information is about) with the need to share information about them.

The UK GDPR and the Data Protection Act 2018 provides a number of lawful bases for sharing personal information. It is not necessary to seek consent for the purposes of safeguarding and promoting the welfare of child where there is an alternative lawful basis. The lawful basis that may be appropriate for sharing personal data in these circumstances may be:

  • Article 6. 1(c) legal obligation; or
  • 1 (e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Where special category data is being processed (e.g. health data), you must also be able to meet one of the specific conditions from Article 9 such as:

  • 2(g) processing is necessary for substantial public interest; or
  • 2(h) for the provision of health or social care or treatment or the management of health or social care systems and services.

The Data Protection Act 2018 sets out the lawful grounds for processing of special category personal information where it is in the substantial public interest to safeguard children and individuals at risk.  Further details are set out in Schedule 8 Section 35(5) of the Data Protection Act which states:

  1. 4 (1) This condition is met if:
    1. The processing is necessary for the purposes of:
      1. Protecting an individual from neglect or physical, mental or emotional harm; or
      2. Protecting the physical, mental or emotional well-being of an individual.
    2. The individual is:
      1. Aged under 18; or
      2. Aged 18 or over and at risk.

Where there is a clear risk of significant harm to a child, or serious harm to adults the decision to share information is clear, as actions must be taken to respond to the disclosure. In other cases, for example, neglect, the indicators may be more subtle and appear over time. In these cases, decisions about what information to share, and when, may be more difficult to judge. Decisions in this area need to be made by, or with the advice of, people with suitable competence in Child Protection work such as named or designated practitioners or senior managers. The information shared should be proportionate.

Caldicott Guardian Principles:

A Caldicott Guardian is a senior person responsible for protecting the confidentiality of patient and service-user information and enabling appropriate information-sharing.

  1. Justify the purpose(s) for using confidential information;
  2. Use personal confidential data only when it is necessary;
  3. Use the minimum necessary confidential information;
  4. Access to confidential information should be on a strict need-to-know basis;
  5. Everyone with access to confidential information should be aware of their responsibilities;
  6. Comply with the law;
  7. The duty to share information for an individual’s care is as important as the duty to protect patient confidentiality;
  8. Inform patient and service users about how their confidential information is used.

The Guardian plays a key role in ensuring that the NHS, Local Authority Social Services Departments and partner organisations satisfy the highest practicable standards for handling patient/client identifiable information.

Section 115 of the Crime and Disorder Act 1998 establishes:

The power to disclose information is central to the Act's partnership approach. The Police have an important general power under common law to disclose information for the prevention, detection and reduction of crime. However, some other public bodies that collect information may not previously have had power to disclose it to the Police and others. This section puts beyond doubt the power of any organisation to disclose information to Police authorities, local authorities, Probation Service, Health Authorities, or to persons acting on their behalf, so long as such disclosure is necessary or expedient for the purposes of crime prevention. These bodies also have the power to use this information.

Part 3 of the Data Protection Act 2018 covers the processing of personal data for 'law enforcement purposes'. It covers processing for the prevention, investigation, detection or prosecution of criminal offences, or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.

The Domestic Violence Disclosure Scheme ('Clare's Law'):

The Domestic Violence Disclosure Scheme (DVDS) gives members of the public a formal mechanism to make enquires about an individual who they are in a relationship with, or who is in a relationship with someone they know, where there is a concern that the individual may be violent towards their partner. This scheme adds a further dimension to the information sharing about children where there are concerns that domestic abuse is impacting on the care and welfare of children within the family.

Members of the public can make an application for a disclosure, known as the 'right to ask'. Anybody can make an enquiry, but information will only be given to someone at risk or a person in a position to safeguard the victim. The scheme is for anyone in an intimate relationship regardless of gender.

Partner agencies can also request disclosure is made of an offender's past history where it is believed someone is at risk of harm. This is known as 'right to know'.

If a potentially violent individual is identified as having convictions for violent offences, or information is held about their behaviour which reasonably leads the police and other agencies to believe they pose a risk of harm to their partner, a disclosure will be made. 

Article 8 in the European Convention on Human Rights states that:

Everyone has the right to respect for their private and family life, home and correspondence:

There shall be no interference by a public authority with the exercise of this right except such as in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of rights and freedoms of others.

The Child Sex Offender Review Disclosure Scheme (CSODS) is designed to provide members of the public with a formal mechanism to ask for disclosure about people they are concerned about, who have unsupervised access to children and may therefore pose a risk. This scheme builds on existing, well established third-party disclosures that operate under the Multi-Agency Public Protection Arrangements (MAPPA).

Police will reveal details confidentially to the person most able to protect the child (usually parents, carers or guardians) if they think it is in the child's interests.

The scheme is managed by the Police and information can only be accessed through direct application to them.

If a disclosure is made, the information must be kept confidential and only used to keep the child in question safe. Legal action may be taken if confidentiality is breached. A disclosure is delivered in person (as opposed to in writing) with the following warning:

  • 'That the information must only be used for the purpose for which it has been shared i.e. in order to safeguard children;
  • The person to whom the disclosure is made will be asked to sign an undertaking that they agree that the information is confidential and they will not disclose this information further;
  • A warning should be given that legal proceedings could result if this confidentiality is breached. This should be explained to the person and they must sign the undertaking.' See GOV.UK - Child sex offender disclosure scheme guidance.

If the person is unwilling to sign the undertaking, the police must consider whether the disclosure should still take place.

The Police, Crime, Sentencing and Courts Act 2022 requires ‘specified authorities’ for a local government area to work together and plan to prevent and reduce serious violence, including identifying the kinds of serious violence that occur in the area, the causes of that violence (so far as it is possible to do so), and to prepare and implement a Strategy for preventing, and reducing serious violence in the area.

‘Specified’ authorities are:

  • Police;
  • Probation Services;
  • Youth Offending Teams;
  • Integrated Care Boards;
  • Local authorities.

To recognise the importance of effective multi-agency information sharing, the Serious Violence Duty legislation includes specific provisions to support partners to share information, intelligence and knowledge to prevent and reduce serious violence.

These provisions create information-sharing gateways to permit disclosure to a specified authority of information held by specified authorities, local policing bodies and educational, prison or youth custody authorities and to enable local policing bodies to request information from specified authorities, educational authorities, prison or youth custody authorities within its police force area, or any other local policing body for the purposes of the Serious Violence Duty. The provisions will not replace existing data sharing agreements or protocols that are already established. The new information-sharing gateways for the purposes of the Serious Violence Duty are intended to enable the sharing of relevant data where existing powers alone would not be sufficient.

Section 16 Police, Crime, Sentencing and Courts Act 2022 provides a permissive information-sharing gateway that enables specified authorities, local policing bodies (PCCs or equivalents), educational, prison and youth custody authorities to disclose information to each other for the purposes of their functions under the Serious Violence Duty. Information-sharing to support effective collaboration with partnerships should be considered carefully and in line with data protection requirements ensuring that any disclosure is necessary and proportionate for the proposed purpose.

Personal information may be disclosed under section 16 by specified authorities (with the exception of health or social care authorities), local policing bodies (PCCs or equivalents), educational, prison and youth custody authorities. Any sharing of personal information must comply with data protection legislation (most importantly, the Data Protection Act 2018). There are restrictions on the disclosure of patient information and/or personal information by health or social care authorities.

The powers permit requests to be made for sharing information, or for information to be shared pro-actively, but do not oblige any specified authority to share information (either pro-actively or following a request).

Section 17 Police, Crime, Sentencing and Courts Act 2022 creates a power for local policing bodies (PCCs and equivalents) to request any specified authority and any educational, prison or youth justice authority within its police force area to supply it with such information as it may specify for the purpose of its functions relating to the Serious Violence Duty.

For more information see Serious Violence Duty - Preventing and Reducing Serious Violence: Statutory Guidance for Responsible Authorities.

Information Sharing: Advice for Safeguarding Practitioners

Local Resources

Please see the following in Local Resources:

  • Information sharing procedure;
  • Summary-children who move across LA borders;
  • Tier 1 children safeguarding procedure;
  • Tier 2 children safeguarding procedure. 

Last Updated: November 15, 2024

v27