Skip to content

Domain C: Governance & Access

Using the domain reference

Domain C includes the five maturity descriptors and the source-verified minimum evidence for L3–L5. Expand the evidence section beneath each indicator and retain an auditable assessment record. See How to Apply HDRL.

Focus: Legal, regulatory, and procedural frameworks; UK-wide coordination

Indicators: 11 (9 Core, 2 Enhancement)

The business question

How fast can we approve safe research? This is the primary friction point for industry.

Governance is the largest single determinant of whether a health data service can attract and retain users. Time-to-data metrics vary from weeks to years across the UK. This domain assesses the legal foundations, access committee efficiency, and UK-wide interoperability that determine whether researchers experience a streamlined pathway or an opaque bureaucracy. Three of the five proposed Foundational Indicators sit in this domain.

Contains 3 proposed Foundational Indicators

HDRL v1.0.1 treats indicators C.1.1, C.2.2, and C.4.1 as proposed Foundational Indicators with a minimum of Level 3 in its internal baseline assessment logic. They are not official UK Health Data Research Service (HDRS) participation requirements.


Indicator Summary

ID Indicator Type Class Unit Foundational
C.1.1 Legal Basis for Processing Core B0 System ⚠
C.1.2 Legislative Environment Enhancement O System
C.2.1 Time-to-Data Core B0 Both
C.2.2 Data Access Committee Core B0 Both ⚠
C.2.3 Ethics Pathway Integration & Proportionality Core B0 Both
C.3.1 Mutual Recognition & Standards Core B0 Both
C.3.2 Cross-Border Legal Alignment Enhancement O System
C.3.3 Cross-sector Data Sharing & Linkage Governance Core C6 System
C.4.1 Statistical Disclosure Control Core B0 Service ⚠
C.4.2 Researcher Accreditation Core B0 Both
C.4.3 Consent, Permissions & Restrictions Governance Core B0 Both

CORE · B0 · System · ⚠ FOUNDATIONAL REQUIREMENT (minimum L3)

Level Description
L1 Legal basis unclear. Reliance on consent for all research. No systematic review.
L2 Framework developing. Review initiated. GDPR options assessed.
L3 Primary basis established. Controller/processor defined. Review process exists. Some ambiguity.
L4 Comprehensive basis. Clear documentation per dataset. Agreements in place. Timely guidance.
L5 Robust framework. Proactive horizon scanning. Contributing to national guidance. UK-wide and international support.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Documented legal basis and roles for key datasets (controller/processor clarity)
  • Evidence legal review process exists and is used (DPIA/TRA, sign-off records)

L4 minimum evidence

  • Per-dataset legal basis documentation (lawful basis, purposes, roles) with sign-off
  • Template agreements (DAA/DSA, controller/processor arrangements) in routine use
  • DPIA/TRA artefacts and governance process evidence (review cycle, updates)

L5 minimum evidence

  • Horizon scanning/legal review process evidence (register + update cadence)
  • Evidence of contribution to national/UK-wide guidance or shared legal patterns
  • Evidence framework supports UK-wide operation (cross-node legal arrangements, resolved issues)

C.1.2 Legislative Environment

ENHANCEMENT · O · System

Level Description
L1 Significant barriers. Key statutes block secondary use. No reform pathway.
L2 Barriers identified. Policy engagement initiated. Interim approaches defined.
L3 Permits research under conditions. Constraints remain. Active in legislative review.
L4 Enabling environment with safeguards. Clear pathway. Compatible with UK-wide operation.
L5 Actively enables research. Legislation updated. Supports innovation within ethics.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Assessment of legal/legislative constraints with documented workarounds
  • Evidence of active engagement in policy/legislative review processes

L4 minimum evidence

  • Documented assessment of legislative barriers/enablers + mitigation pathway
  • Evidence of enabling safeguards and clear pathway for secondary use
  • Demonstrated compatibility with UK-wide operation (policy/guidance mapping)

L5 minimum evidence

  • Evidence of updated/modernised legislation or formal policy instruments enabling research
  • Evaluation evidence showing reduced barriers while maintaining safeguards
  • Evidence of leadership in policy shaping (consultations, published positions)

C.2 — Access Efficiency

C.2.1 Time-to-Data

CORE · B0 · Both

Level Description
L1 No standard process. Case-by-case. >12 months where successful.
L2 Central function exists. Documentation drafted. Median 6-12 months.
L3 Operational process. Single application. Median 3-6 months. SLAs defined but not consistent.
L4 Single-gateway. Median <90 days. SLAs met >= 80%. Applicant support.
L5 Median <45 days. Tiered/fast-track approvals. Automated workflows. Top-quartile UK.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Operational access workflow with a single application route (process map + artefacts)
  • Time-to-data measurement evidence supporting Level 3 claim (median 3--6 months; SLA defined)

L4 minimum evidence

  • End-to-end process map + SOP defining start/stop points for the clock
  • Time-to-data distribution (median + 90th percentile) showing Level 4 claim
  • SLA compliance report showing >=80% plus evidence of applicant support workflow

L5 minimum evidence

  • Time-to-data distribution showing median <45 days + tiered/fast-track pathway evidence
  • Automation evidence (workflow tooling, integration) reducing manual steps
  • Benchmarking evidence (UK comparative position) or independent review

C.2.2 Data Access Committee

CORE · B0 · Both · ⚠ FOUNDATIONAL REQUIREMENT (minimum L3)

Level Description
L1 No formal DAC. Ad-hoc decisions. No criteria. No public benefit assessment.
L2 DAC established/forming. Terms defined. Public benefit criteria developing. Infrequent meetings.
L3 Operational DAC meeting monthly. Published criteria including NDG public benefit. Decisions documented. Lay members initiated.
L4 Efficient with clear criteria. Public benefit per NDG for every decision. Lay >= 25% with voting. Decisions within 2 weeks.
L5 Streamlined with risk-proportionate pathways. Public benefit methodology shared. Appeal process. Lay co-governance.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • DAC operating with published criteria and decision logging (minutes/records)
  • Evidence of regular meetings and decisions (e.g., monthly cadence)

L4 minimum evidence

  • DAC terms of reference + membership list (incl. lay representation) and decision criteria
  • Sample minutes/decision logs (redacted) showing timely decisions (<=2 weeks) and NDG public benefit use
  • Published guidance for applicants and audit trail of decisions

L5 minimum evidence

  • Evidence of risk-proportionate pathways (tiering rules + examples)
  • Appeals process evidence + outcomes
  • Evidence DAC criteria/method is shared or adopted more widely (templates, training)

C.2.3 Ethics Pathway Integration & Proportionality

CORE · B0 · Both

Level Description
L1 Ethics pathway unclear or duplicative. Handled ad-hoc.
L2 Pathway mapped and documented. Proportionality intent stated.
L3 Standard ethics triage for common studies. Variable duplication remains.
L4 Integrated, risk-proportionate pathway. Tiered routes and SLAs tracked.
L5 Optimised pathway. Reuse/mutual recognition where lawful; learning loop and benchmarking.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Ethics triage guidance available for common study types (process doc)
  • Evidence of at least some approval reuse/portability or reduced duplication (cases)

L4 minimum evidence

  • Documented ethics pathway integrated with access (triage rules + decision rights)
  • SLA/turnaround reporting for ethics steps (where applicable)
  • Evidence of templates/support for multi-site studies (guidance, examples)

L5 minimum evidence

  • Evidence of approval reuse/mutual recognition where lawful (agreements + cases)
  • Metrics showing reduced duplication (trend over time) and documented learning loop
  • Contribution to sector guidance or external review endorsing the pathway

C.3 — UK-Wide Integration

C.3.1 Mutual Recognition & Standards

CORE · B0 · Both

Level Description
L1 No UK-wide engagement. Organisation-specific agreements.
L2 Standards reviewed. Gap analysis. Participation initiated.
L3 Partial adoption (Alliance DAA). Mutual recognition of some approvals. Additional steps for UK-wide.
L4 Full adoption of UK-standard DAA. Mutual accreditation recognition. Single approval for UK-wide. Participating in governance.
L5 Leading contributor. Full interoperability. Supporting others. Contributing to Alliance standards.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Evidence of partial adoption of UK standards (e.g., Alliance DAA) and engagement
  • Evidence of mutual recognition for at least some approvals or accreditations (cases)

L4 minimum evidence

  • Evidence of adoption of UK-standard DAA (or equivalent) and mutual recognition arrangements
  • Evidence single approval works in practice (case studies + reduced duplicative steps)
  • Participation evidence in UK governance/standards bodies (minutes/roles)

L5 minimum evidence

  • Evidence of leadership contributions (standards proposals, tooling, guidance)
  • Interoperability evidence across nodes (tests, joint exercises)
  • Support evidence provided to other nodes (mentoring, implementation packs)

ENHANCEMENT · O · System

Level Description
L1 No consideration of cross-border issues.
L2 Issues identified (NI-Ireland, Scotland common law). Initial assessment.
L3 Complexities documented with workarounds. Some friction.
L4 Arrangements address cross-border. Controller agreements enable UK-wide. Manageable overhead.
L5 Framework designed for UK-wide. Proactive resolution. International arrangements where relevant.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Documented cross-border legal issues and practical workarounds
  • Evidence of at least one cross-border case managed/delivered

L4 minimum evidence

  • Documented cross-border legal arrangements enabling data flow/linkage
  • Controller agreements and DPIA/TRA addressing cross-border issues
  • Case example showing cross-border project delivered with manageable overhead

L5 minimum evidence

  • Proactive framework design evidence (policy/agreements anticipating cross-border needs)
  • Evidence of resolving cross-border friction (issue log + fixes)
  • International arrangements evidence where relevant

C.3.3 Cross-sector Data Sharing & Linkage Governance

CORE · C6 · System

Capability module

Within HDRL v1.0's original six-capability mapping, this indicator is included only when assessing Capability 6 (Cross-sector linkage). The mapping preserves the initial 2025 HDRS proposition; it should not be treated here as a current programme requirement.

Level Description
L1 No cross-sector pathway. Roles, decision rights and feasibility unclear.
L2 Priority sectors identified. Draft principles/templates; DPIA/TRA approach emerging.
L3 Governance operational for >=1 sector. Templates in use; pilot linkage delivered.
L4 Repeatable pathway for multiple sectors. Defined accountabilities; performance tracked.
L5 Scaled and assured cross-sector linkage. Quality/bias monitored; good practice shared.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Identified priority partner sector(s) and documented principles/roles (controllers/processors)
  • Evidence of at least one cross-sector linkage/data sharing project delivered (case)

L4 minimum evidence

  • Named partner sectors + documented controller/processor roles and decision rights
  • Template agreements and DPIA/TRA approach (reusable where appropriate)
  • Delivery evidence for cross-sector linkage across multiple sectors + cycle-time metrics

L5 minimum evidence

  • Breadth/maintenance evidence (published approach; refreshed partner list)
  • Linkage quality/bias monitoring evidence (metrics + improvement actions)
  • Independent assurance and evidence of sharing templates/good practice cross-UK

C.4 — Governance Assurance

C.4.1 Statistical Disclosure Control

CORE · B0 · Service · ⚠ FOUNDATIONAL REQUIREMENT (minimum L3)

Level Description
L1 No systematic control. Outputs released without review.
L2 Policy drafted. Training identified. Manual checking for some.
L3 Policy operational. Trained checkers. Manual review. Some delays.
L4 Systematic with guidelines. Trained team with capacity. SLA met. Semi-automated tools.
L5 Advanced with automated tools. Risk-based. Contributing to standards. Rarely delays.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • SDC policy operational with trained reviewers
  • Evidence of disclosure review decisions logged (audit trail)

L4 minimum evidence

  • SDC policy and guidelines + trained checker list
  • SLA/performance evidence for disclosure review (turnaround, backlog)
  • Evidence of semi-automated tooling use and documented decisions/audit trail

L5 minimum evidence

  • Automated or advanced tooling evidence (risk-based rules, tool validation)
  • Evidence of contributing to SDC standards/guidance (methods shared)
  • Performance evidence showing minimal delays without compromising safety

C.4.2 Researcher Accreditation

CORE · B0 · Both

Level Description
L1 No requirements. Access without competency demonstration.
L2 Requirements defined. Curriculum developing. Enforcement not systematic.
L3 Accreditation required. Training available. Status tracked. Some legacy gaps.
L4 Comprehensive with mandatory training, renewal, enforcement. Aligned with ONS RAS. Integrated.
L5 Advanced pathway. Tiered accreditation. Contributing to UK standards. Mentorship.
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Accreditation requirement in place with training offer
  • Evidence accreditation status is tracked and used in access decisions

L4 minimum evidence

  • Accreditation/training requirements policy + renewal rules
  • Tracking system evidence (who is accredited, expiry, enforcement)
  • Alignment evidence with ONS RAS (or equivalent) and integration with access workflow

L5 minimum evidence

  • Tiered accreditation pathway evidence + mentoring/support arrangements
  • Contribution to UK-wide accreditation standards (materials, working groups)
  • Evaluation evidence of improved compliance/quality (audit findings, incidents reduced)

CORE · B0 · Both

Level Description
L1 Permissions/restrictions not captured. Applied inconsistently or discovered late.
L2 Inventory initiated. Key restrictions documented; enforcement mainly manual.
L3 Most restrictions documented and used in decisions. Manual checks common.
L4 Restrictions captured and enforced end-to-end. Audit trail and change control in place.
L5 Automated policy enforcement. Routine audits; scalable reuse (e.g., standard models where applicable).
Minimum evidence for L3–L5

Use this source-defined minimum evidence with the maturity descriptors above. Record the artefact, date, scope and the claim it supports.

L3 minimum evidence

  • Permissions/restrictions documented for most datasets and used in decisions
  • Evidence of manual compliance checks and handling of edge cases (logs)

L4 minimum evidence

  • Permissions/restrictions inventory linked to datasets/cohorts + governance sign-off
  • End-to-end enforcement evidence (triage rules, provisioning controls, access controls)
  • Audit trail + change control evidence for restriction updates

L5 minimum evidence

  • Automated policy enforcement evidence (rules engine, attribute-based controls, etc.)
  • Routine audit evidence (internal/external) covering compliance with permissions
  • Evidence of scalable reuse patterns shared (standard models, templates; dynamic consent where applicable)