The report also contains important guidance for the increasing number of digital intermediary services being used to help identify potential participants.

These services can offer real benefits. Digital and AI-enabled tools can make searches more efficient, and privacy-enhancing technologies can allow potential participants to be identified without researchers themselves seeing identifiable information.

But using technology does not remove the common law duty of confidentiality.

The report describes a privacy-preserving model where a third party can carry out pseudonymisation or eligibility checking for recruitment without breaching confidentiality - provided that a number of safeguards are met.

These include:

  • using privacy-enhancing technologies
  • carrying out the processing entirely within an existing clinical system whose primary purpose remains care
  • accessing only the minimum necessary information
  • avoiding bulk extraction of confidential patient information to the third party,
  • revealing the identities of potential participants only to somebody who has a legitimate relationship with them for their care

That is different from an arrangement in which confidential patient information is routinely extracted from GP practices, hospitals or other care organisations into an external platform or database.

Where confidential patient information is transferred to a digital intermediary so that it can be pseudonymised or screened for eligibility, a legal basis under the common law duty of confidentiality is needed for that transfer. This remains the case even if the receiving organisation removes identifiers immediately after receipt.

By contrast, there is no confidentiality issue where the information has already been made anonymous at source before it is transferred to the third party.

Researchers, sponsors, NHS organisations and digital intermediaries should therefore look beyond descriptions such as ‘privacy-enhancing’, ‘de-identified’, ‘AI-enabled’ or ‘recruitment platform’ and understand the actual data flow.

If confidential patient information is being accessed outside the care team, or transferred in bulk to a third party outside the existing clinical system, the question should be asked early.

What is the confidentiality basis for that access or disclosure?

Where consent or another confidentiality route is not available, this may mean considering whether section 251 support is required in England and Wales. Applicants should seek advice early from the Confidentiality Advisory Group (CAG) where this may be relevant. Different arrangements apply in Scotland and Northern Ireland.

Thinking about this early is much easier than discovering during study set-up that a recruitment model depends on access to confidential information that has not been properly addressed.

Digital intermediaries should also be able to explain their arrangements clearly, including where information is held, whether and when it is identifiable, who can access it, the relevant legal bases and the safeguards in place.

Appropriate security assurance, transparency and patient and public involvement are important parts of this.

It is also important to think about contact as well as identification.

A system may identify somebody without revealing their identity to a researcher, but there still needs to be an appropriate route for approaching that person.

If identifiable information is passed to a third party so that it can make the initial contact, the confidentiality implications of that disclosure need to be addressed too.

Back to finding and contacting people about research