A confidentiality release is more than just a signed form — it's the foundation of trust between professionals and their clients or patients. Whether you're a doctor protecting your patients' health data, a lawyer upholding attorney-client privilege, or a therapist keeping session notes — it's essential to know when and how to lawfully share sensitive information. In this article, we cover the duty of confidentiality, the exact elements every release must contain, and how to align your practices with the General Data Protection Regulation (GDPR) and other data protection requirements. By the end, you'll have a clear, practical guide to drafting airtight communications that respect privacy while meeting your legal and ethical obligations.
What Is a Confidentiality Release?
A confidentiality release (sometimes also called an authorization to disclose information) is a written document that allows a person to permit a professional — such as a doctor, lawyer, therapist, or priest — to share specific personal data with specific third parties. It clarifies:
- Who may receive the information
- What data may be shared
- Why the disclosure is necessary
- How long the release remains valid
When you put these boundaries in writing, both parties know their rights and obligations — which is essential for maintaining trust.
What Happens If This Duty Is Violated?
A breach of the duty of confidentiality can have serious consequences, both for the professional and for the affected person. It can lead to legal consequences, and trust in the profession can also be damaged. In some cases, a claim for damages may also be filed.
When Must Professionals Obtain a Release?
Professionals are generally bound by an absolute duty of confidentiality. Nevertheless, there are exceptions:
Legal Disputes
In court proceedings, insurance claims, or regulatory investigations, judges or opposing counsel may demand evidence. A signed release ensures that sensitive records (medical files, legal counsel's notes) can be lawfully disclosed without violating professional secrecy.
Risk Situations (Self-Endangerment, Public Safety)
If a client poses a threat to themselves or others, many jurisdictions (and codes of ethics) permit — and sometimes even require — breaking confidentiality to prevent harm. In this case, too, a release clarifies the scope of disclosure (for example, to emergency services or crisis intervention teams).
Key Components of an Effective Release
An airtight confidentiality release should include:
- Identification of the parties
- The person granting permission (e.g., "Patient: Maria Rossi")
- The recipient (e.g., "To: Dr. Luca Bianchi; Milan Court")
- Purpose of the disclosure
- State clearly why: "For use in ongoing court proceedings" or "To coordinate psychiatric care."
- State clearly why: "For use in ongoing court proceedings" or "To coordinate psychiatric care."
- Scope of the information
- Specify the categories: "Medical history from January 2022 to May 2025," "Billing records," or "Therapy session notes."
- Specify the categories: "Medical history from January 2022 to May 2025," "Billing records," or "Therapy session notes."
- Duration and revocation
- Set a validity period ("Valid until December 31, 2025")
- Explain how the person can revoke their consent at any time — a revocation has no effect on disclosures already made.
- Set a validity period ("Valid until December 31, 2025")
- Data security requirements
- Explain how the recipient must store and protect the data (e.g., encrypted transmission, storage under lock and key).
- Explain how the recipient must store and protect the data (e.g., encrypted transmission, storage under lock and key).
- Signatures and dates
- Signature and date of the release recipient
- Witness signature, if required by local law
Data Protection and GDPR
Under the GDPR, processing personal data requires a legal basis. A confidentiality release generally qualifies as explicit consent under Art. 6(1)(a) and, for health-related data, as consent to a special category of data under Art. 9(2)(a).
- Lawful basis: Consent must be given freely, explicitly, with full knowledge of the facts, and unambiguously.
- Data retention: Document the request and the retention period. Supervisory authorities expect clear records of when and why you disclosed data.
- Right to object: Data subjects can revoke their consent at any time. You must stop any further disclosure, but you're not required to reverse disclosures already completed.
- Cross-border transfers: If the recipient is located outside the EEA (e.g., a globally operating law firm), you must ensure you have appropriate safeguards in place (standard contractual clauses, binding corporate rules).
Best Practices and Practical Tips
- Use plain-language forms: Avoid legal jargon. A one-page summary helps people understand the form at a glance.
- Digital signatures: E-signature platforms simplify capture and audit trails.
- Train your team: All employees who work with releases should be familiar with data protection obligations and secure transmission procedures.
- Regular audits: Review release logs quarterly to confirm compliance and detect unauthorized disclosures.
Conclusion
A well-drafted confidentiality release combines professional ethics with legal requirements. It preserves trust by establishing transparent rules for when and how sensitive information may be shared. By aligning these releases with GDPR standards - explicit consent, secure storage, clear revocation options - you protect privacy while still meeting legitimate disclosure requirements.
FAQ
What is a confidentiality release, and when is it needed?
What is a confidentiality release, and when is it needed?
A confidentiality release is a written document with which a person allows members of professions bound by confidentiality (e.g., doctors, lawyers, or therapists) to share confidential information with specific third parties. It's needed when there's a legitimate interest in sharing the information — for example, when handing over medical records to insurers, in court proceedings, or when coordinating between treating professionals.
What key legal details must a valid confidentiality release contain?
What key legal details must a valid confidentiality release contain?
For the declaration to be valid, it must include clearly defined key points:
- Identity of the parties: Who is granting permission, and who is the specific recipient?
- Purpose & scope: Why is the data being shared, and which documents/periods does it cover?
- Duration & right of withdrawal: How long is the release valid, and how can it be revoked?
- Signature and date: Handwritten or legally valid digital signature.
How is the release from confidentiality obligations related to the GDPR?
How is the release from confidentiality obligations related to the GDPR?
From a data protection perspective, a release from confidentiality obligations generally corresponds to explicit consent under the GDPR (Art. 6(1)(a); for health data, Art. 9(2)(a) GDPR). To be GDPR-compliant, it must be given voluntarily, in an informed manner, and unambiguously. In addition, the consent must be verifiably documented.
Can a release from confidentiality, once granted, be reversed?
Can a release from confidentiality, once granted, be reversed?
Yes, data subjects have the right to revoke it at any time with effect for the future. As soon as the revocation is received, the professional may no longer disclose any further data to third parties. However, lawful disclosures made before the revocation remain unaffected.







