The Government Digital Service (GDS) agile delivery phase requirements
A summary of the GDS framework to provide direction on how data specifications will be assessed and published within the legal framework, including through mechanisms such as an Information Standards Notice (ISN) or Data Provision Notice (DPN).
The GOV.UK Service Manual describes agile delivery as a phased approach that helps teams understand user needs, test ideas, build workable services, and then run and improve them sustainably.
Each phase has a different purpose, but all are centred on user research, iteration, and evidence based decision making. This framework provides short summaries which are based on the GOV.UK Service Manual guidance for agile delivery and its phase specific pages.
This summary of the Government Service Standard includes specific guidance for teams developing data products and pipelines. Following this guidance will support the assessment and publication of data specifications for use in legal processing frameworks in health and social care, whether through Information Standards Notice (ISN), Data Provision Notice (DPN), or other relevant routes. These Service Standards are also linked to digital spend controls across government.
Discovery
Discovery is the phase designed to build a clear understanding of the problem before any solution is developed. It involves researching user needs, refining policy intent, assessing operational, legislative and technical constraints, and defining the problem's scope and potential value. Findings should provide enough evidence to support a decision on whether to proceed to alpha.
- confirm whether the data is already collected, or captured elsewhere or could be derived from an existing aggregate collection
- define the analytical user needs, commissioner requirements, and wider public health need
- assess the likely impact on patients and the public
- use this evidence to clarify the problem, scope, and value of the proposed collection
Initiate a Data Protection Impact Assessment (DPIA), or confirm whether one already exists by contacting the relevant information asset owner (IAO), information asset administrator, or information governance team.
Teams outside of NHS England, such as organisations seeking to collect data from the NHS should seek confirmation through the Information Governance Portal, as internal registers may not be accessible.
Do not proceed to alpha until the DPIA has been reviewed and any required actions or mitigations have been approved.
Alpha
Alpha is the phase in which potential solutions are developed and tested. Teams should rapidly prototype ideas, assess different options, and validate critical assumptions with users. The objective is to generate enough insight to make an informed decision on whether a solution is ready to move into beta.
- the data design and testing approach should be developed far enough to assess feasibility and risk
- define an initial data model, taking care to identify personal and special category data, including your performance framework and metrics
- prepare draft documentation for direction or legal basis for processing
- assess whether the attributes can be provisioned in draft within the canonical data model
- test whether the model can be provisioned with a defined number of local sites, using synthetic and/or test data
- set out the test strategy, including how migration will be handled where it forms part of the programme
- real data should not be used at this phase
Complete a DPIA, ensuring it references the relevant data specification.
If local sites are participating, consider local information governance requirements, data sharing agreements, and any joint controllership arrangements, particularly in federated platform environments.
Submit a direction or mandatory request (internal teams) or contact the Information Governance Portal before progressing further.
Beta
Beta is the stage at which the selected solution is developed into an operational service and validated with real users. Teams should refine the service through continuous testing and iteration, establish support and accessibility requirements, and confirm that it can perform reliably at scale. The phase should demonstrate readiness for live deployment.
- the focus should be on demonstrating that data can flow end to end through the pipeline and across any integration points, and that the resulting outputs meet analytical requirements
- for early beta, test the service with an initial set of pilot integration partners. For example, this could include at least 2 of 7 software suppliers, or a representative sample of NHS trusts from different regions
- where migration is required, run a closed test to validate how existing data will be presented, processed, and checked against defined user and validation requirements
- consider evaluating how you are doing against your performance metric framework
- for public beta, launch should be supported by evidence that data is flowing through the pipeline, even if some processing details are still being finalised while the data processing environment
- this maturity is usually demonstrated through an agreed common integration pattern, for example via publication through an Information Standards Notice (ISN)
Update and secure approval for the DPIA, ensuring it references the agreed data specification.
Confirm that the relevant Direction and any associated Data Provision Notice (DPN) clearly reference the specification.
Where data is processed in a non-standardised environment, an Information Standards Notice (ISN) should be put in place to support consistent implementation and compliance.
Live
Live is not the end of delivery, but the point at which the service is operated, maintained and continuously improved. Teams should support users effectively, monitor performance, maintain accessibility and service quality, and continue to iterate based on user research and operational data. The service should remain aligned to the wider end-to-end user journey, with ongoing improvements to address constraints, optimise performance and enhance the overall user experience.
- run and maintain the collection through regular assurance and audit .
- provide evidence of usage and uptake of this data, together with public and health and social care service provider feedback, to support the IAO’s justification for continuing the collection
Maintain the DPIA, Direction and Data Protection Notice, ensuring they remain aligned to the approved data specification.
Update NHS Standard Contract references where necessary to support implementation and uptake.
Ensure the selected data processing environment and integration pattern are clearly defined and communicated through the Information Standards Notice.
Last edited: 20 August 2026 3:38 pm