
Shutterstock/ Gajus. All rights reserved.Talking about confidentiality in medicine used to be easy. There was a patient; there was a doctor; there were other people. What the patient told the doctor in confidence could not be shared with other people, without either the permission of the patient or some clear legal obligation which overrode that patient’s wishes.
With the arrival of automatic data processing a new regime was overlaid on this traditional conception of medical confidentiality, ‘data protection’, but the model reinforced the central role of the consent of the ‘data subject’. Although consent could sometimes be inferred, or obtained in such a minimalist way that data subjects could almost consent unwittingly, in the case of sensitive data – such as medical information – explicit consent was necessary. There is a certain ritual element in the invocation of confidentiality and data protection and patient autonomy which barely reflects the reality.
The standard ethical argument for confidentiality and data protection via consent turns on personal autonomy. We start from the presumption that the person is an autonomous agent, with her own beliefs, wishes and interests. These are so central to the identity and dignity of the person that personal decision-making is at the heart of all regulation and governance.