NHS England Engagement Series – Cohort 4: Linking Health and Non-Health Data
As health and administrative systems go digital, linking health data with non-health data – benefits records, education data, immigration status – promises real gains: better care, sharper research, more responsive services. It also raises hard questions about privacy, fairness, and trust. That’s exactly what NHS England set out to explore in Cohort 4 of its National Engagement on Data Linkage: Not just whether the public supports linking their data, but what it would actually take to earn that support.
Through a national survey, 18 hours of deliberative workshops, and targeted engagement with marginalised groups, the research found that public support and trust is never unconditional. It is granted – or withheld – case by case. One message comes through clearly:
Public trust in data linkage is conditional on purpose, public benefit, transparency, safeguards, meaningful engagement, and accountability.
At a glance:
- Support is conditional – people need to see a clear purpose and benefit before they’ll accept linkage.
- Minimising and safeguarding data builds confidence; more sensitive data demands more caution.
- Trust depends on visible governance: transparency, accountability, and independent oversight.
- People expect proactive communication – and a genuine, ongoing role in shaping data governance.
- Choice matters, but a simple opt-out may not be the whole answer.
1. Purpose and public benefit: When people say yes
Support for data linkage rises and falls with two questions: why is this happening, and who does it help? Participants were comfortable with linkage that removed bottlenecks – not having to repeat the same information across services, for example. They grew far more cautious as sensitivity increased: mental health, substance use, and enforcement-related linkage triggered concerns about misuse and re-identification.
Crucially, participants didn’t want blanket rules. They wanted every linkage project to be judged on its own – by purpose, data type, who’s accessing it, and what safeguards are in place – rather than a one-size-fits-all policy applied to whole categories of data.
One gap is worth flagging: participants deliberated extensively on governance and oversight, but comparably less on how linkage actually works. Concepts like deterministic versus probabilistic matching, linkage quality, or privacy-preserving and federated linkage models received little attention. Without that technical grounding, it is possible that participants weighed the risks of linkage more heavily than its mechanism or its upside. A fuller picture of public trust needs participants to understand not just why data is linked, but how – and how that process is kept safe and secure.
2. Transparency: A two-way street
Trust doesn’t survive in the dark. Study participants wanted more than a general awareness that linkage was happening – they wanted to know why, by whom, using what data, and with what protections. Two concrete mechanisms stood out: accessible explanations of data flows, and a publicly available audit trail showing how linkage decisions get made.
Done well, this turns transparency from a one-way information street into a tool the public can actually use to hold institutions accountable – not just a notice that something happened, but a way to check whether it happened properly.
3. Safeguards: Trust needs guardsrails
Participants did not underplay risk. They wanted the minimum data necessary to be used, access to data limited in time and scope, and the proper guardrails and trained personnel in place before a linkage requested is even granted. They required all linking and access to be confined to accredited Secure Data Environments (SDEs), with extra protection for sensitive categories.
It’s easy to see why Secure Data Environments have become the default: they’re well governed, well-understood, and increasingly embedded. But should one architecture be the model for every future linkage use case? As linkage technology matures, federated analysis and privacy-preserving record linkage are emerging as real alternatives – reducing how much data needs to move at all, and making it easier for multiple data custodians to collaborate. However, their advantages won’t be universal; how well they work will depend heavily on context.
Take the European Health Data Space as an instructive example: its infrastructure doesn’t pick a single model – it combines federated digital services for secondary data use with secure processing environments, layering the two together rather than betting on a single architecture. That’s probably where things are heading: not one technical standard, but interoperable systems that remain flexible to the use case. The more durable recommendation might therefore be to define the security, accountability, and disclosure-control outcomes that must be achieved – and allow the technical architecture used to get there evolve.
4. Meaningful engagement: Individual choice and data sovereignty
Trust isn’t built through information alone. Participants were clear that engagement needs to be proactive, and ongoing – through citizen panels, community dialogue, and regular surveys – so governance can evolve as expectations shift. And it has to be meaningful: people don’t just want to be asked; they want to see their input actually change decisions. That’s a shift from consultation to participatory governance, where citizens sit alongside researchers, policymakers, and data custodians rather than being surveyed from a distance.
Individual choice is part of this picture, but it is more nuanced than simply providing an opt-out mechanism. Participants valued having control over whether their data gets linked – especially those with past experience of discrimination or institutional mistrust. Yet, this can become a double-edged sword: if people who are most wary of data use are also most likely to opt out, linked datasets may become less representative of precisely the communities that services most need to reach, potentially deepening existing inequalities rather than reducing them.
The National Data Opt-Out illustrates an important evidence gap. While people can change their minds and reverse a previous opt-out, public reporting focuses largely on how many people are currently opted out, with little clear documentation of how often people subsequently opt back in. Without it, there’s no way to tell whether opting out is a settled preference, a response to a particular controversy, or a decision that might shift with better information, engagement, and institutional trust.
This is where the report could dig deeper. Rather than a binary opt-in/opt-out toggle, a model of data sovereignty would give people ongoing agency: the ability to permit linkage for specific purposes only, to revisit and change that decision over time, and to opt back in later without major roadblocks or judgement. In practice, this could look like a dynamic consent dashboard – a platform where someone can see every active linkage permission tied to their data, adjust it by purpose or organisation, and opt back in as circumstances or trust levels may change, rather than facing a one-time, all-or-nothing choice.

5. Accountability: Who should be the overseers
Participants converged on a single, independent national oversight body – diverse, free from political interference, and empowered to approve or reject linkage proposals, with the authority to overrule government departments. Data misuse, as argued, needs to face real consequences: warnings, fines, or a ban from further linkage.
A central authority could help ensure consistency and public confidence, but it raises a practical question the report doesn’t fully resolve: should the same body oversee research, operational service delivery, and public health planning, when each carries different objectives and risks? A single approval pipeline could become a bottleneck as linkage scales across health and social care. A federated oversight model – national standards paired with specialised review pathways for different types of linkage – may offer more flexibility without giving up public trust.
Path forward
Overall, this report makes a genuinely valuable contribution: it shows that public trust in data linkage is rarely binary. People weigh benefit against risk, and their support is conditional – on demonstrable purpose, robust safeguards, transparent decision-making, real opportunities to shape how their data is used, and confidence that linkage won’t lead to discrimination or profiling.
Building that trust isn’t a one-off achievement, and it isn’t a simple one either. It’s a continuous practice – dialogue, responsive governance, and demonstrated benefit – sustained across the entire lifecycle of the data, from collection and linkage through to analysis, use, and evaluation. It means holding several things in balance at once: individual autonomy with collective benefit, oversight with ownership, accountability with context.
But governance is only one part of informed participation. To make meaningful choices – and to contribute meaningfully to decisions – people may also need opportunities to understand how records are linked, why matches can be missed or made incorrectly, and how these errors can affect some groups more than others. That is the focus of the second part of this series: why conversations about linkage methods, uncertainty and bias are essential to building not only public trust, but genuine public capability.
