Decoding the world of cybersecurity

· ·

Welsh data sharing code formalises public sector governance

An ICO-approved code will impose a common governance framework for organisations sharing personal information across Welsh health, education, social care, safeguarding, and other public services.

Welsh data sharing code formalises public sector governance
Summary
  • The WASPI Code has been approved under Article 40 of UK GDPR.
  • It introduces mandatory templates, governance controls, quality assurance, monitoring, and regular review.
  • The framework covers information sharing across sensitive Welsh public services where inconsistent governance can create both privacy and operational risk.

A new UK GDPR code of conduct will formalise how organisations across Welsh public services govern the sharing of personal information, extending a long-standing voluntary framework into a recognised accountability mechanism approved by the Information Commissioner’s Office.

The Wales Accord on the Sharing of Personal Information, known as WASPI, has developed the code for organisations involved in health, education, social care, safeguarding, crime prevention, and other public services in Wales. The ICO approved it under Article 40 of the UK GDPR on 24 September 2026, with the public announcement following on 28 September.

The code requires participating organisations to use a standard information-sharing protocol template and introduces governance controls, quality assurance, accountability measures, monitoring, and regular review. Its purpose is to make the legal and organisational basis for sharing personal data more consistent across services that frequently need information to move between separate public bodies.

WASPI itself is not new. The framework has operated in Wales for more than two decades, and the ICO says more than 1,000 organisations are committed to its existing principles and standards. The change is the introduction of an approved code that provides a more formal route for members to demonstrate how those principles are applied.

The monitoring body that will oversee compliance with the approved code is still subject to ICO approval, so the governance regime should not yet be treated as fully operational in every respect. That distinction does not alter the code’s approval but it does affect how quickly its assurance framework can be implemented in practice.

Information sharing in public services sits between two categories of risk. Inadequate controls can expose sensitive personal data, create unclear accountability, or allow information to travel beyond its intended purpose. Excessively cautious or inconsistent interpretation can also prevent information from reaching professionals who legitimately need it for care, safeguarding, or service delivery.

A standardised protocol does not remove those judgements, but it can force them into a common process. Participating organisations have to identify why information is being shared, the governance basis for doing so, who is responsible, how arrangements are reviewed, and whether the controls continue to operate as intended.

That becomes increasingly important as public services rely on interconnected digital platforms and multi-agency delivery models. Data may pass between NHS bodies, councils, schools, social-care providers, policing organisations, and other institutions, while the technical systems supporting those exchanges are often operated by different teams and suppliers.

Data protection governance is therefore closely linked to cyber resilience. Organisations cannot apply meaningful access controls, retention rules, monitoring, or incident response to a data-sharing arrangement if ownership and authorised use are poorly defined. A breach involving shared information also becomes harder to manage when responsibility across participating bodies is ambiguous.

The ICO says the code provides a recognised method for demonstrating accountability and transparency. Approval does not guarantee that every participating organisation will handle every dataset correctly, nor does it replace the statutory obligations applying to individual controllers and processors. It creates a common governance structure against which those arrangements can be assessed.

For Welsh public services, the practical test will be whether the formal code preserves the operational benefits that made WASPI widely used while giving organisations a clearer evidential trail for how sensitive information moves. The framework is intended to make lawful sharing easier to demonstrate — and failures of governance easier to identify.

×