Can you share safeguarding information without consent?

If you work in a charity, a housing provider or a contracting business, and someone in your team has ever hesitated over a concern because they were unsure whether data protection let them pass it on, this is for you.

Yes. UK GDPR and the Data Protection Act 2018 let you share personal information without consent where it is necessary to protect a child or an adult at risk from harm, and consent is usually the wrong lawful basis to rely on in a safeguarding situation: you still need a lawful basis, but a person withholding or withdrawing consent does not remove your ability to share.

That is not a generous reading. It is the published position of the Information Commissioner's Office, it is what the Department for Education tells practitioners, and the Data Protection Act 2018 carries a condition written for safeguarding.

What the law actually requires

Does data protection law stop you from sharing safeguarding information?

No. Data protection law is a framework for sharing information lawfully, not a barrier to sharing it, and the Information Commissioner's Office states directly that data protection is a framework to help you share information and does not prevent you from sharing information to safeguard a child.

The regulator names the opposite risk too: it can be more harmful not to share information needed to protect a child. The Department for Education's advice of May 2024 says the same in its first golden rule, that protecting a child from abuse and neglect takes priority over their privacy, or that of the people failing to protect them.

Data protection is not the only duty in play. Where information was given in the expectation it would stay confidential, the common law duty of confidentiality applies too. The same guidance says when you may set it aside: where you are legally required to share, or where an overriding public interest outweighs the interest in confidentiality and you share only the minimum needed.

What lawful basis do you use if not consent?

You must identify at least one lawful basis under Article 6 of the UK GDPR before you share, and the Information Commissioner's Office states that the most common lawful bases suitable for safeguarding purposes are public task, legitimate interests and legal obligation.

Which fits depends on what kind of organisation you are. A public authority usually relies on public task or legal obligation, and the Department for Education says so for practitioners exercising statutory duties under the Children Acts 1989 and 2004, such as the section 11 duty on councils, NHS bodies and the police to have regard to the need to safeguard children's welfare. A charity or a contractor more often relies on legitimate interests. Where a life is at risk, vital interests is open to anyone.

Consent is a poor fit, and not because safeguarding is an exception. Consent under UK GDPR must be specific, freely given, unambiguous, time limited and capable of being withdrawn at any time, and on withdrawal the information would have to be deleted. None of that describes a safeguarding record, which you are under a professional duty to keep whatever the family thinks of it. And seeking consent from someone you suspect of causing harm is likely to undermine safeguarding procedures and increase the risk.

Can you rely on the new recognised legitimate interest basis?

Recognised legitimate interest is a seventh lawful basis added to Article 6(1) of the UK GDPR by the Data (Use and Access) Act 2025, and safeguarding a vulnerable individual is one of its five pre-approved purposes, so where the condition fits you can rely on it without weighing the person's rights against your own interest.

The condition sits at paragraphs 6 to 8 of Annex 1 to the UK GDPR. Safeguarding there means protecting a vulnerable individual from neglect or physical, mental or emotional harm, or protecting their wellbeing, and a vulnerable individual is anyone under 18, or 18 or over and at risk. It came fully into force on 5 February 2026.

Two limits matter. The Commissioner's guidance of 23 March 2026 confirms you need not assess whether a person's rights outweigh the recognised legitimate interest, but you must still show what you are doing is necessary, meaning more than merely useful. And a public authority cannot use it for its own functions, so a local authority still relies on public task. Outside the public sector, it is likely the cleanest basis available.

Do you need anything extra to share health or other sensitive information?

Yes. Health, sexual orientation, racial or ethnic origin, religious belief, genetic and biometric data are special category data under Article 9 of the UK GDPR, and to share them you need both a lawful basis under Article 6 and a separate condition under Article 9(2).

The condition safeguarding relies on is Article 9(2)(g), substantial public interest, given effect by section 10 of and Schedule 1 to the Data Protection Act 2018. Paragraph 18 of that Schedule is titled "Safeguarding of children and of individuals at risk", and exists for precisely this situation.

Paragraph 18 is met where the processing is necessary to protect someone from neglect or physical, mental or emotional harm, or to protect their wellbeing; they are under 18, or 18 or over and at risk; it is necessary for reasons of substantial public interest; and it is done without consent for one of three stated reasons. Those reasons: consent cannot be given, you cannot reasonably be expected to obtain it, or obtaining it would prejudice the protection you are providing. Read that last one twice. Parliament wrote permission not to ask into the Act.

What is an appropriate policy document, and do you need one?

If you rely on the safeguarding condition in paragraph 18 of Schedule 1 to the Data Protection Act 2018 to share special category data, you must have an appropriate policy document in place at the time you do it, and this is the requirement smaller organisations most often miss.

Part 4 of Schedule 1 says what it must contain, and it is short. It must explain your procedures for complying with the Article 5 data protection principles when processing under that condition, and explain your retention and erasure policy, indicating how long such information is likely to be kept.

You must keep it under review, retain it until six months after the processing ends, and produce it to the Commissioner on request. Your record of processing must name the condition relied on and how it satisfied Article 6. A safeguarding policy is not a substitute: this is a separate document with a specific job.

Does the answer change when the person is an adult?

The principle is the same, but for an adult you have to establish that they are at risk rather than assume it, because the protection that applies automatically to anyone aged under 18 applies to an adult only where a further test is met.

Both paragraph 18 of Schedule 1 and Annex 1 to the UK GDPR treat an adult as at risk where you have reasonable cause to suspect they have needs for care and support, are experiencing or at risk of neglect or harm, and as a result cannot protect themselves. That is deliberately close to section 42 of the Care Act 2014, so facts prompting a section 42 referral usually satisfy the data protection condition too.

One consequence catches people out. A young person you have been safeguarding is not automatically covered after their eighteenth birthday, and the Commissioner is explicit that where someone no longer meets the definition you must identify a different lawful basis.

Do you have to tell the person you have shared information about them?

Usually yes, and you should try to, but you are not required to tell them where you have reason to believe that doing so would put someone at increased risk of harm.

The second golden rule is to engage with the child or their carers wherever it is practicable and safe, explaining who you intend to share with, what you will share and why. It names the exceptions: where a carer may harm the child or react violently to anyone intervening, or the child might withhold information or withdraw from services. Nor should you tell them where it could compromise a police investigation.

An objection is not a veto. Consider it, then override it where you believe sharing is necessary to protect them from harm. Where you share over an objection, the guidance is explicit: record your reasons and the legal basis.

What should you record when you share, or when you decide not to?

Record the decision and the reasons for it either way, because the seventh of the Department for Education's golden rules requires you to record the reasons for an information sharing decision irrespective of whether or not you decide to share information.

The Commissioner says the same from the data protection side: keep a record of your decision and reasons even where you conclude you have no lawful basis and cannot share. That record satisfies the accountability principle, and it is what a safeguarding practice review will ask to see. The data sharing code of practice, statutory and in force since 5 October 2021, is the standard it is read against.

Record proportionality too. Sharing with a third party rarely requires an entire record or case file: share only what is necessary, proportionate, relevant, adequate and accurate. If uncertain, the fourth golden rule is to seek advice promptly, and it carries the line worth putting in front of any team that hesitates: do not leave a child at risk of harm because you have concerns you might be criticised for sharing information.

This isn't legal advice. It's a plain reading of published legislation and regulator guidance, all of it linked below. We're happy to talk through your specific position.

Sources

Almost nobody gets this wrong by reading the law and disagreeing with it. It goes wrong because the decision is taken in a hurry, by someone who is not a data protection specialist, with nothing written down to point back to. A named lawful basis, an appropriate policy document that genuinely exists, and a team trained to record the decision either way, are what turn a defensible position into an evidenced one.

The pages below set out how we work with community organisations, housing providers and contractors. Synergy Safe accreditation is how you evidence it to a funder, a Board or a client.