ComplyChat Start free

Guide · Safeguarding

Information sharing between agencies

Child safeguarding practice reviews keep returning to the same finding: several agencies each held part of the picture, and nobody put it together in time. From 30 September 2026 the law in England answers that with a duty. Schools, health and care services, the police, local authorities and the other organisations with a safeguarding function must share information that may help another of them safeguard children and young people. This guide explains what the duty requires and what it leaves alone, the three tests every practitioner applies, why consent and confidentiality are no longer the obstacle they were thought to be, how sharing about adults differs, and the record that shows each decision was made properly.

By ComplyChatPublished 14 minute read

A health visitor, a family support worker and a school pastoral lead talk in the car park of a family hub on a bright autumn morning, lanyards and bags over their shoulders
01

The duty to share, and where it comes from

Working Together to Safeguard Children 2026 starts where the case reviews do: "No single practitioner can have a full picture of a child's needs and circumstances so effective sharing of information between practitioners, local organisations and agencies is essential for early identification of need, assessment, and service provision to keep children safe" (paragraph 29). It adds that "practitioners should not assume that someone else will pass on information that they think may be critical to keep a child safe".

What was guidance is now also law. The Children's Wellbeing and Schools Act inserted section 16LA into the Children Act 2004, and the Department for Education's statutory guidance on the information sharing duty, updated on 10 September 2026, confirms that it applies from 30 September 2026. The section applies where a relevant person "holds information about a child or information about another individual that relates to the child, and considers that the information is relevant to safeguarding or promoting the welfare of the child". It then "must ensure that the information is disclosed" to another relevant person "if and only so far as the relevant person considers that the disclosure may facilitate" that recipient's relevant functions. The same duty applies when the information is requested. And subsection (7) settles an old anxiety: "A disclosure of information under this section does not breach any obligation of confidence owed by the person making the disclosure."

The duty binds organisations, and the practitioners who work for them. The guidance lists who is in scope: the section 11 bodies (local authorities, integrated care boards, NHS trusts, the police, prison and probation services, youth justice and youth custody services), the designated childcare and education agencies, and providers delivering services under arrangements made by them, which "includes GPs, dentists, and other primary care providers". Organisations in scope "must have regard to" the guidance, which "should be complied with, unless exceptional circumstances arise", and regulators and inspectorates "may consider compliance when assessing effectiveness". The duty applies to situations arising after its commencement on 30 September 2026; there is no obligation to revisit earlier ones, though an organisation may choose to.

02

What the duty changes, and who it leaves out

Practitioners had told the department they were unsure whether "a specific statutory threshold – such as child protection enquiries under section 47 of the Children Act 1989 – must be met before information can be shared". The guidance answers that "there is no requirement for a child to meet a particular statutory threshold before information can be shared", and information "must be shared where it is relevant to safeguarding and promoting a child's welfare, including where concerns relate to early help, prevention and unmet need". In practice that means:

  • Early and partial information counts. Relevant information "can include contextual, partial, historical and pattern-based information". A falling attendance record, a parent's disclosure of stress at a GP appointment, a new adult collecting a child from school are all within scope.
  • Information about other people counts. The duty covers information about "any individual – a peer or an adult – within a child's life" where it is relevant to the child's safety or welfare, such as a carer's substance misuse or an adult's history of violence.
  • Moves are covered. Organisations must share concerns across boundaries within England "where a child is known to be relocating, to avoid important information being lost".

Just as important is what the duty leaves alone. It does not replace existing safeguarding procedures: a child at risk of significant harm is still referred to children's social care or the police in the usual way. It sits beside, not in place of, the mandatory reporting duty in the Crime and Policing Act 2026 "once it has commenced". And it has three edges, which decide whether the duty is the route at all before any test is applied:

  • Charities, community groups and private providers. The duty "only covers sharing between organisations and practitioners to whom it applies". A charity, a youth club, a church or a private provider outside those categories shares under ordinary data protection law and, where it applies, the common law duty of confidentiality. The guidance's chapter on those recipients is "non-statutory advice": it strongly encourages them to feed relevant information to the statutory safeguarding partners, "both proactively and in response to a request", and asks anyone sharing with a small charity to check whether it is likely to have "the appropriate security infrastructure to manage sensitive personal data appropriately".
  • Scotland, Wales and Northern Ireland. Safeguarding organisations in the devolved administrations "are not encompassed by the duty". Concerns should still be shared across the border where necessary, and "can be shared ordinarily, provided an appropriate lawful basis is identified under data protection, e.g. public task."
  • Young people turning 18. Until then a young person is a child for the duty, and being 16, living independently or in further education "does not change their status or entitlements to services or protection". At 18 the duty stops. Processes for those over 18 "will vary from those for children", so organisations that work with both, "such as schools", should understand "the respective routes for sharing information for each group" and prepare for the move to adult services.
03

The three tests, and the narrow exception

The guidance gives practitioners three questions to apply before sharing:

  1. Relevance. "Does all of the information considered for sharing have a bearing on safeguarding or promoting the child's welfare? If information has been requested, is there sufficient context to determine relevance?"
  2. May facilitate. "Is the recipient covered by the information sharing duty? Could sharing information reasonably help the recipient to safeguard or promote the welfare of the child", through its own functions? The guidance adds that this includes cases "when the child potentially poses a risk to others".
  3. Detriment. "Could sharing be of greater detriment to the child than not sharing? Are there any mitigating steps that can be taken to reduce risk?"

The detriment exception is deliberately narrow. The duty does not apply "in extremely limited circumstances" where sharing "would be more detrimental to the child than not sharing", and any such decision "should be rare, and carefully considered". The guidance lists what usually lies behind it: the child being placed at immediate risk of harm by the sharing, interference with a police investigation such that a child is put at greater risk, or a breach of the Family Procedure Rules or a Family Court order. It is equally clear about what does not justify withholding. Information "must still be shared" even if the only concern is not having consent, a parent being "unhappy, on principle", "fear of criticism or complaint", a practitioner "feeling unsure or uncomfortable", or data protection. Doubt is a reason to ask, not to withhold: the guidance tells practitioners to "seek prompt advice from their manager, Caldicott Guardian or the organisation's safeguarding lead", and where the doubt is about detriment, to consider "requesting information from other organisations and practitioners in order to better assess need".

Before refusing, the guidance expects mitigation: "limiting the information shared or providing more general observations, avoiding stigmatising language, identity labels, historical narrative and untested allegations about the child, unless strictly relevant". Its own worked example is a child hidden from an abusive parent: the practitioner shares everything except the location, shares that only with the few professionals who need it, and makes "a clear record … of what information has not been shared, why, and under what conditions it may be shared in future".

A multi-agency strategy meeting in a council meeting room seen through a glass wall, a police officer, a nurse and three colleagues around a table with paper files
05

Feedback and the record of each decision

How information moves, through the partnership's data sharing agreement and its separate routes for referrals, early help, smaller pieces of information and urgent concerns, is set locally, and our guide to information sharing agreements covers what those documents contain.

Whatever the route, the guidance expects organisations to act promptly, to give enough context in a request for the recipient to judge relevance, to acknowledge what they receive and give feedback to whoever shared it, and to record each decision to share or not to share with its reasons against the three tests. An entry that does that is short:

An information sharing record entry – fictional example

Child ref C-2291 · Wednesday 7 October 2026, 14:10 · Request received from children's social care (family help team) by secure email, asking for attendance and any welfare concerns since September · Relevance: yes – attendance down to 81%, two late collections by an unknown adult noted in concern records · May facilitate: yes – family help assessment under way · Detriment: none identified · Shared: attendance summary and the two concern entries (extracts, not the file), 15:30, by secure email to the named worker · Family informed: mother told by phone 16:00 what was shared and why · Acknowledgement received 8 October · Decision by: deputy DSL, reviewed by DSL.

The entry answers the three tests, shows what was shared and how, and records the transparency step and the acknowledgement. A decision not to share would carry the same fields and a reason.

That record belongs in the organisation's own system: the child protection file, the health record or the case management system. It is also what a later child safeguarding practice review or inspection will read, so a safeguarding chronology built from it should show every exchange with another agency in date order.

06

The information shared in a message, and the record nobody holds

Much multi-agency sharing never passes through the partnership's routes at all. After a strategy discussion, the professionals involved set up a group chat so they can "keep each other posted": the social worker, the health visitor, the school's designated lead, the youth worker, a police officer. Over the next month it carries the most current information anyone has about the child – a missed appointment, a new partner at the house, a sighting at the station at midnight. It is on personal phones, in an app none of their organisations runs. When the group dissolves, no agency holds the exchange, and each agency's record shows only what someone remembered to copy across.

Every message in that chat is a decision to share under section 16LA, or a request, and the guidance asks each organisation to record it with its rationale. Nobody can, because nobody holds it. The practitioners are doing exactly what Working Together asks – sharing early, not assuming someone else will – and their organisations cannot show it.

The fix is for one organisation to host the conversation somewhere it controls. ComplyChat's paid plans bring staff and inter-agency work into a named Microsoft Teams channel, and everyone added to a channel is told it is on the record and can object or leave. Messages are recorded on the server as they are sent, and on paid plans the lasting record files into the host organisation's own Microsoft 365 once its tenant is connected, under its own retention rules. ComplyChat is not a case management system, a referral route or secure email, and it does not decide what may be shared; each agency still records its own decisions in its own system, and the partnership's agreed routes still apply. Hosting cross-agency messages also makes the host responsible for them, so agree it with partners and your data protection officer first.

A question for the next leadership or partnership meeting: of the information our staff shared with other agencies last month, how much went through an agreed route, and how much through messages we could not produce?

07

Official guidance and your next step

The primary sources are section 16LA of the Children Act 2004 and the DfE's Information Sharing Duty: statutory guidance (September 2026); Working Together to Safeguard Children 2026, chapter 1; the ICO's data sharing code of practice and 10 step guide; and, for adults, chapter 14 of the Care and support statutory guidance with section 45 of the Care Act 2014. Quotations are from those documents as read on 25 and 26 September 2026, days before the duty's commencement on 30 September 2026.

This guide is a summary for England, not legal advice. On an individual decision, speak to your safeguarding lead, data protection officer or Caldicott Guardian, and follow your partnership's procedures.

Then do one thing: check now that your organisation's safeguarding procedure tells staff the three tests, the partnership's routes including the urgent one, and where to record each decision to share or not to share.

Why we publish this

We build ComplyChat for the conversations organisations need to keep. The information sharing duty asks every organisation to record what it shared and why, and a great deal of that sharing happens in messages between practitioners that no organisation holds. Explore Free for personal messaging, or compare the paid plans if your organisation needs a lasting record in its own Microsoft 365.

Explore Free · How it works · Compare plans

Sources

Every document this guide quotes or links to, in the order it first cites them.

  1. Working Together to Safeguard Children 2026 gov.uk
  2. Section 16LA into the Children Act 2004 legislation.gov.uk
  3. Statutory guidance on the information sharing duty gov.uk
  4. 10 step guide to sharing information to safeguard children ico.org.uk
  5. Care and support statutory guidance gov.uk
  6. Section 45 of the Care Act 2014 legislation.gov.uk
  7. Data sharing code of practice ico.org.uk