How Do NHS Sites Give Monitors EPR Access Without Breaching UK GDPR?

NHS sites give monitors access to the electronic patient record (EPR) without breaching UK GDPR by putting three permissions in place before the first login: a lawful basis for the processing, explicit consent that releases the record from the common law duty of confidentiality, and a named read-only account the trust itself issues, scopes and audits. Each comes from a different body of law, and a different person at the trust grants it.

This guide sits in our series on eSource in clinical trials. It covers what makes the access lawful, the models the MHRA recognises, the trust approval chain, what the Caldicott principles ask, how the access is audited, and where it fails.

Consent releases the record. The trust grants the account.

What Makes a Monitor’s Access to an NHS EPR Lawful?

Four requirements have to be satisfied at once. A site holding only the sponsor’s paperwork has an arrangement that fails an information governance review.

RequirementWhere it comes fromWhat satisfies it at an NHS site
A lawful basis for processingUK GDPRA task in the public interest for NHS organisations, and legitimate interests for commercial sponsors
Release from the duty of confidentialityThe common law duty of confidentialityExplicit participant consent, recorded in the information sheet and consent form
A duty to permit direct accessICH E6(R3), section 2.12.14The investigator makes requested trial-related records available for direct access to the monitor, auditor, ethics committee or regulatory authority
Contractual information governance termsThe clinical trial agreementThe sponsor’s obligations on training, device security, breach reporting and permitted locations

Consent does different work in the first two rows. The HRA guidance on consent in research states that consent is not the legal basis for processing personal data under UK GDPR in health and care research. It also states that consent is still needed for people outside the care team to access confidential patient information, which is the common law requirement a monitor clears.

Controllership stays split. The HRA states that the sponsor acts as the controller in relation to the research data and the care organisation acts as the controller in relation to the data provided for care purposes, so one set of information can have two controllers for two purposes. The trust keeps its EPR controller duties whatever the trial agreement says.

ICH E6(R3) ties the consent wording to the access. Section 2.8.10(o) requires the participant to be told that taking part allows direct access to source records, on the understanding that the confidentiality of their medical record will be safeguarded.

Which EPR Access Models Does the MHRA Recognise?

The MHRA recognises log-in access, guided access and upload to a portal, and treats printouts as a fallback. Its guidance on access to electronic health records by sponsor representatives states that log-in access requires far less investigator site personnel involvement during the review, so it is preferable.

Access modelHow the monitor reads the recordWhat the site has to provideWhere it falls short
Log-in access, on siteA named read-only account at the siteAn account, a role, a desk and an escortResearch space and staff time
Log-in access, remoteThe same account from the monitor’s own locationThe account, two-factor authentication and review windowsPermitted only from the UK, an EEA state or a state under a UK adequacy decision
Guided accessSite staff share a screen and navigateA delegated staff member throughoutSite effort runs through the visit, and the records opened are evidenced only where the site logs them
Upload to a portalThe site exports documents to a secure portalExport and upload effort for each participantDirect access only where it holds a complete, certified copy of the EHR system
PrintoutsPaper or PDF extracts handed over at the visitPrinting, checking and filingThe MHRA reports printouts arriving incomplete, with gaps where a report runs date to date
Five EPR access models for clinical trial monitors placed by investigator site effort and by whether each route counts as direct access under MHRA guidance

Two conditions apply to every log-in model. The guidance states that log-in access must not be provided where the monitor can edit, add, change or delete information. It also states that sharing user accounts and log-in information with another person is strictly forbidden.

The record a monitor reaches is the source only where the site has declared it as such. Our guide to which record is the source when data sits in both the EPR and the trial system covers that declaration.

How Does an NHS Trust Approve a Monitor’s Access?

Approval runs through eight steps, and the trust owns most of them.

  1. The clinical trial agreement sets the information governance terms, the sponsor’s training duty and the conditions of access.
  2. The trust’s research and development office confirms the study locally and records the agreed access arrangement.
  3. The site verifies the monitor’s identity when creating the read-only account, using government issued photographic identification that is documented rather than retained.
  4. A monitor who is not employed by an NHS organisation obtains a letter of access or an honorary research contract. The HRA research passport is the mechanism for non-NHS staff to obtain either one, and a person already employed by an NHS organisation needs neither.
  5. The Caldicott Guardian and the information governance team decide whether the disclosure meets the trust’s confidentiality standards.
  6. The Registration Authority issues the account. NHS England states that smartcards are issued only to individuals whose identity has been verified to national identity check standards, and that role-based access control restricts a user to the data items their role requires.
  7. The sponsor trains the monitor on the trust’s information governance obligations and on where a session may be opened.
  8. The site deactivates the account at close-out, or on the day the monitor leaves the study.

Six of those eight steps belong to the trust, which is why the timetable follows NHS research governance rather than the monitoring plan.

The chain produces documents for the site file. The letter of access, the access agreement, the identity verification record and the training certificate are filed in the investigator site file.

Also Read: How Should Monitors Do Remote Source Data Verification with eSource?

What Do the Caldicott Principles Require of an EPR Access Decision?

The Caldicott principles are eight principles published by the National Data Guardian and last updated in December 2020. Health service bodies in England handling confidential patient information appoint a Caldicott Guardian to apply them, under guidance issued in August 2021 using the statutory power in the Health and Social Care (National Data Guardian) Act 2018.

PrincipleThe question it puts to a monitor access request
1. Justify the purposeWhich study, sponsor and monitoring plan clause requires this access?
2. Use confidential information only when necessaryDoes verification of the trial data require sight of the record itself?
3. Use the minimum necessaryCan the account be limited to the participants the study covers?
4. Access on a strict need-to-know basisIs the account held by one named monitor, for one study, at one site, read-only?
5. Everyone aware of their responsibilitiesHas the monitor completed documented governance training before the first login?
6. Comply with the lawAre the lawful basis and the consent recorded and current?
8. Inform patients about how their information is usedDoes the participant information sheet state that sponsor and regulatory personnel can read the record?
The eight Caldicott principles turned into the questions an NHS trust answers on a monitor's request to access the electronic patient record

Principle 7 concerns the duty to share information for an individual’s own care, so it governs clinical use rather than a research disclosure. Each answer above is evidence the trust can produce later.

How Is a Monitor’s Access to the EPR Audited?

The trust audits the access on two levels: the account and the reading. Both produce evidence an inspector or a governance review can request.

  • The system logs user additions, deactivations and permission changes, which shows who held access on any past date.
  • Every access to patient data is traceable back to the smartcard holder, which attributes each read to one person.
  • The site runs a risk-based audit trail review of the monitor’s activity, which detects inappropriate activity and triggers corrective and preventive action.
  • An automatic time-out ends an inactive session, which closes a login left open on an unattended device.
  • Two-factor authentication applies to remote log-in, which ties a session to something the monitor holds.
  • The read-only role restricts printing, copying and downloading, which keeps the record inside the trust.
  • A scheduled account review identifies dormant logins, which stops access accumulating past the point of need.
Timeline of a monitor's EPR account from creation to deactivation, showing the log entry each event writes for the NHS trust's audit of access

A finding from that review runs through the site’s own quality process. A monitor who opened a record outside the study cohort produces a data breach assessment and a corrective action in the quality management system.

Also Read: What MHRA Expects from Electronic Source Systems Under the 2026 UK Regulations

Where Does EPR Access Break Down at NHS Sites?

Six failures account for most of the difficulty, and each is a condition set before the monitor arrives.

FailureWhat it looks likeCondition behind it
The EPR cannot restrict to trial participantsThe only account available reaches the whole wardPermissions are built around clinical roles. MHRA inspectors have reported a system that did not allow access limited to trial patients for external monitors
No audit trail to reviewThe trust cannot show which records were openedMHRA inspectors have reported records with no audit trail, or no ability to access it
Access granted to the sponsor rather than a personRead events attribute to an organisationProvisioning treated the monitoring team as one user
Printouts substituted for accessThe monitor verifies against paper extractsThe printout was never certified, so it stands as an uncontrolled copy
Access exercised outside the permitted territoryA monitor logs in from outside the agreed statesThe access agreement never named permitted locations
The account outlives the studyA login still works a year after close-outDeactivation depends on memory rather than a scheduled review

Consider a hypothetical respiratory study at an NHS trust. A quarterly account review finds the monitor’s remote read-only account still active eight months after the last participant completed. The access log shows four logins in that period, all against consented participants. The finding is the provisioning procedure rather than the monitor’s conduct, because nothing in the process closed the account when the study closed. The corrective action attaches deactivation to the close-out checklist.

An account nobody closed is an access nobody authorised.

Monitor access to an NHS EPR holds together where the lawful basis, the trust approval and the audit of the reading sit alongside the study record. AQ is launching eSource soon as part of the AQ platform, so the access a site grants and the source record a monitor reads are held on one footing. Book a live demo to see the AQ platform today.

Guide
By Ash Mahmud· · · Book a 30 min demo
In this guide
AM
Written by
Ash Mahmud
Co-founder, AQ Trials

Ash has spent over twenty years inside clinical research operations and technology, working alongside NHS Trusts, CROs, sponsors, and academic research organisations. He co-founded AQ Trials to give research teams one connected, inspection-ready operational record.

See the connected platform behind this guide

A 30-minute walkthrough built around your operational priorities — study execution, documentation, quality and pharmacy in one governed record.

Book a 30 min demo →
See the AQ Platform in action — a 30-minute walkthrough for teams like yoursBook a 30 min demo →
Free guides · PDF
Find the right guide for you

Pick a module, your organisation type, or both — we'll match the guides and email them to you.

Most popular guides
Explore
15+ guides

Free guides · PDF

Guides matched to you.

Written for first-in-human & Phase 1 sites

Inspection-ready checklists & templates

Aligned to MHRA, FDA & EU Annex 11