ICO Approves UK GDPR Code for Information Sharing Across Welsh Public Services
Key Takeaways
- WASPI Launches UK GDPR Code: The new Article 40 Code provides a formal framework for organizations sharing personal information across Welsh public services.
- Six Requirements Underpin the Code: Participating organizations must meet requirements covering governance, approved templates, quality assurance, accountability, regular reviews, and ongoing monitoring.
- More Than 1,000 Organizations Already Use WASPI: The Code builds on an established information-sharing framework rather than creating a new system from scratch.
- Regular Review Is Central: Information-sharing arrangements must be revisited to ensure they remain lawful, necessary, and properly governed.
- Monitoring Arrangements Are Still Being Established: WASPI will continue working with the ICO to establish the WASPI service as an independent monitoring body.
Deep Dive
More than 1,000 organizations in Wales already work under the Wales Accord on the Sharing of Personal Information. What changes now is the footing beneath that work. WASPI has launched its UK GDPR Code of Conduct for Information Sharing Protocols, an Article 40 Code designed to give organizations a consistent framework for sharing personal information across health, education, social care, safeguarding, and other public services.
The Code takes a familiar problem in public services and gives it considerably more structure. Sharing information can be necessary to deliver a service or protect someone from harm. It can also expose an organization to serious data protection failures when nobody can adequately explain what was shared, why it was necessary, or who was responsible for the decision.
WASPI's answer is not to discourage sharing. It is to make the arrangements behind it easier to defend. Organizations participating in the Code will work through six requirements covering governance, the use of approved templates, quality assurance, accountability, reviews of information-sharing arrangements, and ongoing monitoring. The mandatory WASPI Information Sharing Protocol template sits at the heart of that framework.
The result is meant to be something more durable than an agreement signed and filed away. Information-sharing arrangements are expected to be reviewed regularly, with organizations able to demonstrate how their practices meet UK GDPR principles including lawfulness, transparency, accountability, security, and data minimization.
That matters particularly in safeguarding, health, and social care, where the consequences of getting information sharing wrong run in both directions. Personal information needs protection. Relevant information can also become critical when different organizations are trying to protect a vulnerable person or coordinate services around them.
WASPI said the Code is intended to provide a recognized and consistent approach to reciprocal information sharing while ensuring those arrangements continue to be examined after they are established. Dave Parsons, WASPI Code Manager, called its publication "a significant step forward" for organizations trying to share information lawfully and consistently.
"By providing clear standards, robust governance arrangements and independent monitoring, the Code helps organisations meet their information-sharing responsibilities while maintaining the trust of the people they serve," Parsons said.
The Code was developed under Article 40 of the UK GDPR with support from the Information Commissioner's Office. Parsons described it as the first UK GDPR Code of Conduct in the UK covering public and third sector partners and thanked colleagues from the ICO's Code Team and Wales Team for their work on its development.
The existing reach of WASPI gives the Code a substantial starting point. More than 1,000 organizations have already signed up to the Accord, meaning the new framework is being introduced into an information-sharing system with an established presence across Wales rather than built from scratch.
Chris Hogan, Head of Regulatory Strategy at the ICO, said the Code builds on that existing practice while giving organizations a clearer way to demonstrate responsible handling of personal information.
"This kind of consistent approach is what helps promote and maintain public trust, particularly in areas like safeguarding, health and social care, where effective information sharing can be critical," Hogan said.
WASPI said it will continue working with the ICO to establish the WASPI service as an independent monitoring body and will support organizations applying for Code membership over the coming months. That monitoring function gives the Code much of its practical weight. Templates can standardize what organizations put on paper. Governance requirements can establish who is responsible. Regular review and monitoring are what test whether those arrangements continue to describe what organizations are actually doing with people's information.
The GRC Report is your premier destination for the latest in governance, risk, and compliance news. As your reliable source for comprehensive coverage, we ensure you stay informed and ready to navigate the dynamic landscape of GRC. Beyond being a news source, the GRC Report represents a thriving community of professionals who, like you, are dedicated to GRC excellence. Explore our insightful articles and breaking news, and actively participate in the conversation to enhance your GRC journey.

