The duty to share, and where it comes from
Working Together to Safeguard Children 2026 starts where the case reviews do: "No single practitioner can have a full picture of a child's needs and circumstances so effective sharing of information between practitioners, local organisations and agencies is essential for early identification of need, assessment, and service provision to keep children safe" (paragraph 29). It adds that "practitioners should not assume that someone else will pass on information that they think may be critical to keep a child safe".
What was guidance is now also law. The Children's Wellbeing and Schools Act inserted section 16LA into the Children Act 2004, and the Department for Education's statutory guidance on the information sharing duty, updated on 10 September 2026, confirms that it applies from 30 September 2026. The section applies where a relevant person "holds information about a child or information about another individual that relates to the child, and considers that the information is relevant to safeguarding or promoting the welfare of the child". It then "must ensure that the information is disclosed" to another relevant person "if and only so far as the relevant person considers that the disclosure may facilitate" that recipient's relevant functions. The same duty applies when the information is requested. And subsection (7) settles an old anxiety: "A disclosure of information under this section does not breach any obligation of confidence owed by the person making the disclosure."
The duty binds organisations, and the practitioners who work for them. The guidance lists who is in scope: the section 11 bodies (local authorities, integrated care boards, NHS trusts, the police, prison and probation services, youth justice and youth custody services), the designated childcare and education agencies, and providers delivering services under arrangements made by them, which "includes GPs, dentists, and other primary care providers". Organisations in scope "must have regard to" the guidance, which "should be complied with, unless exceptional circumstances arise", and regulators and inspectorates "may consider compliance when assessing effectiveness". The duty applies to situations arising after its commencement on 30 September 2026; there is no obligation to revisit earlier ones, though an organisation may choose to.
What the duty changes, and who it leaves out
Practitioners had told the department they were unsure whether "a specific statutory threshold – such as child protection enquiries under section 47 of the Children Act 1989 – must be met before information can be shared". The guidance answers that "there is no requirement for a child to meet a particular statutory threshold before information can be shared", and information "must be shared where it is relevant to safeguarding and promoting a child's welfare, including where concerns relate to early help, prevention and unmet need". In practice that means:
- Early and partial information counts. Relevant information "can include contextual, partial, historical and pattern-based information". A falling attendance record, a parent's disclosure of stress at a GP appointment, a new adult collecting a child from school are all within scope.
- Information about other people counts. The duty covers information about "any individual – a peer or an adult – within a child's life" where it is relevant to the child's safety or welfare, such as a carer's substance misuse or an adult's history of violence.
- Moves are covered. Organisations must share concerns across boundaries within England "where a child is known to be relocating, to avoid important information being lost".
Just as important is what the duty leaves alone. It does not replace existing safeguarding procedures: a child at risk of significant harm is still referred to children's social care or the police in the usual way. It sits beside, not in place of, the mandatory reporting duty in the Crime and Policing Act 2026 "once it has commenced". And it has three edges, which decide whether the duty is the route at all before any test is applied:
- Charities, community groups and private providers. The duty "only covers sharing between organisations and practitioners to whom it applies". A charity, a youth club, a church or a private provider outside those categories shares under ordinary data protection law and, where it applies, the common law duty of confidentiality. The guidance's chapter on those recipients is "non-statutory advice": it strongly encourages them to feed relevant information to the statutory safeguarding partners, "both proactively and in response to a request", and asks anyone sharing with a small charity to check whether it is likely to have "the appropriate security infrastructure to manage sensitive personal data appropriately".
- Scotland, Wales and Northern Ireland. Safeguarding organisations in the devolved administrations "are not encompassed by the duty". Concerns should still be shared across the border where necessary, and "can be shared ordinarily, provided an appropriate lawful basis is identified under data protection, e.g. public task."
- Young people turning 18. Until then a young person is a child for the duty, and being 16, living independently or in further education "does not change their status or entitlements to services or protection". At 18 the duty stops. Processes for those over 18 "will vary from those for children", so organisations that work with both, "such as schools", should understand "the respective routes for sharing information for each group" and prepare for the move to adult services.
The three tests, and the narrow exception
The guidance gives practitioners three questions to apply before sharing:
- Relevance. "Does all of the information considered for sharing have a bearing on safeguarding or promoting the child's welfare? If information has been requested, is there sufficient context to determine relevance?"
- May facilitate. "Is the recipient covered by the information sharing duty? Could sharing information reasonably help the recipient to safeguard or promote the welfare of the child", through its own functions? The guidance adds that this includes cases "when the child potentially poses a risk to others".
- Detriment. "Could sharing be of greater detriment to the child than not sharing? Are there any mitigating steps that can be taken to reduce risk?"
The detriment exception is deliberately narrow. The duty does not apply "in extremely limited circumstances" where sharing "would be more detrimental to the child than not sharing", and any such decision "should be rare, and carefully considered". The guidance lists what usually lies behind it: the child being placed at immediate risk of harm by the sharing, interference with a police investigation such that a child is put at greater risk, or a breach of the Family Procedure Rules or a Family Court order. It is equally clear about what does not justify withholding. Information "must still be shared" even if the only concern is not having consent, a parent being "unhappy, on principle", "fear of criticism or complaint", a practitioner "feeling unsure or uncomfortable", or data protection. Doubt is a reason to ask, not to withhold: the guidance tells practitioners to "seek prompt advice from their manager, Caldicott Guardian or the organisation's safeguarding lead", and where the doubt is about detriment, to consider "requesting information from other organisations and practitioners in order to better assess need".
Before refusing, the guidance expects mitigation: "limiting the information shared or providing more general observations, avoiding stigmatising language, identity labels, historical narrative and untested allegations about the child, unless strictly relevant". Its own worked example is a child hidden from an abusive parent: the practitioner shares everything except the location, shares that only with the few professionals who need it, and makes "a clear record … of what information has not been shared, why, and under what conditions it may be shared in future".
Consent, confidentiality and adults
The most persistent myth in multi-agency working is that data protection law stops agencies sharing personal data. Working Together says the Data Protection Act 2018 and UK GDPR "provide a framework to ensure that personal information is shared appropriately". The second myth is that you need consent to share, and Working Together answers it directly: "No, you do not need consent to share personal information." The statutory guidance explains why consent is usually the wrong basis anyway: it is "highly unlikely to be the most appropriate choice when sharing information under the duty because there is often an imbalance of power between parties, meaning consent may not be freely given, and consent may be withdrawn later". It points instead to legal obligation or public task for most organisations in scope, and to recognised legitimate interests or legitimate interests, which may suit voluntary and private organisations.
Health information and other special category data need an Article 9 condition as well, and criminal offence data needs official authority or a condition in Schedule 1 to the Data Protection Act 2018. Paragraph 18 of that Schedule, safeguarding of children and of individuals at risk, is the one most often relied on. The data protection principles still apply: share the minimum necessary, keep it accurate, and when sharing opinion "it must be made clear that it is an opinion, rather than a matter of fact". Recognised legitimate interest is one of the changes made by the Data (Use and Access) Act 2025, all of whose data protection changes are now in force while the ICO reviews some of its guidance, so check the date on any ICO page you rely on; the ICO's 10 step guide to sharing information to safeguard children is the short version.
Confidentiality is where the duty changes most. The guidance describes the old position: "Previously, practitioners had to judge whether disclosure of confidential information (or 'confidential patient information') was legally required, justified in the overriding public interest or required consent." Within the duty that judgement has gone. The common law duty of confidentiality, or CLDoC, "does not apply to information shared in compliance with the information sharing duty", so confidential information can be shared without consent and "without the need to consider whether sharing is in the overriding public interest". In the guidance's worked example, a GP learns that a 14-year-old's parent is known to adult mental health services for alcohol use: the information is confidential, but "it is directly relevant to the child's welfare", consent from the parent "is not required", and it goes to the family help front door. Outside the duty the old judgement returns: practitioners sharing with a recipient the duty does not cover "must pay due regard to CLDoC where applicable".
Not needing consent is not the same as not telling children and families. The guidance expects practitioners, "where safe to do so", to "be open and transparent about why information is shared, what might be shared and how it will be used", and to record decisions about when and how to inform a family. Its advice on explaining this is candid: tell families that "information cannot always be kept confidential if it relates to a child's safety or welfare", and do not ask permission for something that will happen anyway, because seeking consent and then sharing on another basis when it is refused "presents the individual with a false choice".
Adults are different. Section 16LA stops at 18, and there is no equivalent duty for adults at risk, so the confidentiality judgement the duty removed for children still has to be made for them. The Care and support statutory guidance asks agencies to draw up "a common agreement relating to confidentiality", consistent with the Caldicott principles, ensuring that information is shared "on a 'need to know' basis when it is in the interests of the adult", that "confidentiality must not be confused with secrecy", that "informed consent should be obtained but, if this is not possible and other adults are at risk of abuse or neglect, it may be necessary to override the requirement", and that "it is inappropriate for agencies to give assurances of absolute confidentiality in cases where there are concerns about abuse" (paragraph 14.187). Where an adult refuses, practitioners "must consider whether there is an overriding public interest that would justify information sharing", involving the Caldicott Guardian "wherever possible" (paragraph 14.188).
The Care Act also gives safeguarding adults boards their own power to obtain information. Under section 45 of the Care Act 2014, a person the board asks, because it is likely to hold information relevant to the board's work, "must comply with the request" where the section's conditions are met, and the board may use what it receives "only for the purpose of enabling or assisting the SAB to exercise its functions". Schools, colleges and youth services working with young people turning 18 need to know the children's route and the adults' route, and which one applies on the day.

Feedback and the record of each decision
How information moves, through the partnership's data sharing agreement and its separate routes for referrals, early help, smaller pieces of information and urgent concerns, is set locally, and our guide to information sharing agreements covers what those documents contain.
Whatever the route, the guidance expects organisations to act promptly, to give enough context in a request for the recipient to judge relevance, to acknowledge what they receive and give feedback to whoever shared it, and to record each decision to share or not to share with its reasons against the three tests. An entry that does that is short:
Child ref C-2291 · Wednesday 7 October 2026, 14:10 · Request received from children's social care (family help team) by secure email, asking for attendance and any welfare concerns since September · Relevance: yes – attendance down to 81%, two late collections by an unknown adult noted in concern records · May facilitate: yes – family help assessment under way · Detriment: none identified · Shared: attendance summary and the two concern entries (extracts, not the file), 15:30, by secure email to the named worker · Family informed: mother told by phone 16:00 what was shared and why · Acknowledgement received 8 October · Decision by: deputy DSL, reviewed by DSL.
The entry answers the three tests, shows what was shared and how, and records the transparency step and the acknowledgement. A decision not to share would carry the same fields and a reason.
That record belongs in the organisation's own system: the child protection file, the health record or the case management system. It is also what a later child safeguarding practice review or inspection will read, so a safeguarding chronology built from it should show every exchange with another agency in date order.
The information shared in a message, and the record nobody holds
Much multi-agency sharing never passes through the partnership's routes at all. After a strategy discussion, the professionals involved set up a group chat so they can "keep each other posted": the social worker, the health visitor, the school's designated lead, the youth worker, a police officer. Over the next month it carries the most current information anyone has about the child – a missed appointment, a new partner at the house, a sighting at the station at midnight. It is on personal phones, in an app none of their organisations runs. When the group dissolves, no agency holds the exchange, and each agency's record shows only what someone remembered to copy across.
Every message in that chat is a decision to share under section 16LA, or a request, and the guidance asks each organisation to record it with its rationale. Nobody can, because nobody holds it. The practitioners are doing exactly what Working Together asks – sharing early, not assuming someone else will – and their organisations cannot show it.
The fix is for one organisation to host the conversation somewhere it controls. ComplyChat's paid plans bring staff and inter-agency work into a named Microsoft Teams channel, and everyone added to a channel is told it is on the record and can object or leave. Messages are recorded on the server as they are sent, and on paid plans the lasting record files into the host organisation's own Microsoft 365 once its tenant is connected, under its own retention rules. ComplyChat is not a case management system, a referral route or secure email, and it does not decide what may be shared; each agency still records its own decisions in its own system, and the partnership's agreed routes still apply. Hosting cross-agency messages also makes the host responsible for them, so agree it with partners and your data protection officer first.
A question for the next leadership or partnership meeting: of the information our staff shared with other agencies last month, how much went through an agreed route, and how much through messages we could not produce?
Official guidance and your next step
The primary sources are section 16LA of the Children Act 2004 and the DfE's Information Sharing Duty: statutory guidance (September 2026); Working Together to Safeguard Children 2026, chapter 1; the ICO's data sharing code of practice and 10 step guide; and, for adults, chapter 14 of the Care and support statutory guidance with section 45 of the Care Act 2014. Quotations are from those documents as read on 25 and 26 September 2026, days before the duty's commencement on 30 September 2026.
This guide is a summary for England, not legal advice. On an individual decision, speak to your safeguarding lead, data protection officer or Caldicott Guardian, and follow your partnership's procedures.
Then do one thing: check now that your organisation's safeguarding procedure tells staff the three tests, the partnership's routes including the urgent one, and where to record each decision to share or not to share.
We build ComplyChat for the conversations organisations need to keep. The information sharing duty asks every organisation to record what it shared and why, and a great deal of that sharing happens in messages between practitioners that no organisation holds. Explore Free for personal messaging, or compare the paid plans if your organisation needs a lasting record in its own Microsoft 365.
Sources
Every document this guide quotes or links to, in the order it first cites them.
- Working Together to Safeguard Children 2026 gov.uk
- Section 16LA into the Children Act 2004 legislation.gov.uk
- Statutory guidance on the information sharing duty gov.uk
- 10 step guide to sharing information to safeguard children ico.org.uk
- Care and support statutory guidance gov.uk
- Section 45 of the Care Act 2014 legislation.gov.uk
- Data sharing code of practice ico.org.uk


