National Institute for Health and Care Research (NIHR)
Information governance framework for national patient-data sharing across the UK's original Biomedical Research Centres
Strongest proof
National multi-centre research data-sharing framework
- Sector
- Higher Education / Research · Healthcare / NHS · Public Sector
- Capability
- Information Governance · Data Privacy & DPO · NHS & HealthTech
- Geography
- Oxford, Cambridge and London, United Kingdom
- Engagement model
- Strategic & programme advisory
- Evidence
- Named client · Public evidence

At a glance
- Who
- National Institute for Health and Care Research (NIHR) · Higher Education / Research · Healthcare / NHS · Public Sector
- Why it mattered
- The Chief Medical Officer challenged five national Biomedical Research Centres to share complex patient datasets for population-level research.
- IG-Smart's role
- Data-sharing consultancy and information governance strategy
01The exposure
Dame Sally Davies, then Chief Medical Officer, challenged the UK's five original national Biomedical Research Centres to share complex and voluminous patient datasets for pioneering population-level research.
Sharing patient data across multiple NHS and academic organisations required lawful, secure and trusted arrangements for anonymising, pseudonymising and merging data from many clinical systems — without which the research could not proceed.
02The mandate
Legal, information governance and information security leadership to design a framework under which data could be shared safely across all five centres.
Commissioned scope
- Information governance framework for multi-centre data sharing
- Legal, information governance and information security consultancy
- Governance of anonymisation, pseudonymisation and data-merging across multiple clinical systems
- Programme management of the governance workstream
03Environment
Organisation context
Describes the client organisation — not the size of IG-Smart's work.
- National health research funder and its five original Biomedical Research Centres
Frameworks in scope
- UK data protection law
- NHS information governance requirements
- Anonymisation and pseudonymisation practice
Scope boundary
- No client testimonial is reproduced.
- Dataset volumes and programme dates are not stated.
04IG-Smart's approach
- 01
Assess
Worked with academicians, clinicians, technologists and programme managers across the centres to understand data flows and research needs.
- 02
Build
Developed the information governance framework covering lawful sharing, anonymisation, pseudonymisation and merging of data from multiple clinical systems.
- 03
Assure
Provided legal, information governance and information security consultancy so the framework could be adopted across all five centres.
Engagement phases: Assess · Build · Assure
05Engagement scale
What IG-Smart's work covered
- Five Biomedical Research Centres
- Legal, IG and information security leadership
06What we delivered
- Multi-centre information governance framework
- Data-sharing governance arrangements
- Anonymisation and pseudonymisation governance approach
07Outcome
Engagement result
The NIHR Health Informatics Collaborative successfully shared data for research under the information governance framework developed by IG-Smart.
Professional assessment
The source material describes the programme as the first of its kind in the UK.
08What this demonstrates
Relevant to research consortia, NHS and academic partnerships, trusted research environments and data platforms that need lawful, trusted data-sharing frameworks.
09What buyers can verify
Public
- Named client
- Engagement scope
- Deliverable types described
Further evidence can be discussed subject to confidentiality and client permissions.
Related services
Related evidence
Healthcare / NHS, Information Governance · NHS & HealthTech · Cyber Governance & Assurance · Data Privacy & DPO
Royal Brompton & Harefield NHS Foundation Trust
Three-year managed Information Governance, clinical safety and data-security service for a specialist NHS trust's big-data transformation
A world-leading specialist trust needed governance, clinical safety and security built into a pioneering NHS big-data platform — and across the trust.
Three years managing IG, Information Security, Data Quality and IT Training teams, end to end from design and procurement to User Acceptance Testing.
Read the case studyHealthcare / NHS, Information Governance · Data Privacy & DPO
NHS England
National data-privacy and information-governance advisory for NHS England
A national health body needed privacy embedded in digital transformation, new care models and national publications.
Read the case studyHigher Education / Research, Information Governance · NHS & HealthTech
UCL
Information-governance audit and DSPT readiness for a leading research university
A research-intensive school handling sensitive health data needed to understand its readiness for the NHS Data Security and Protection Toolkit.
The client reports the audit report helped shape and focus its final DSPT submission.
Read the case study
Facing a comparable requirement?
This case reference is passed to the form so you don't need to re-enter it.
Submit a Requirement