Data guardian criticises DeepMind data sharing with NHS
National Data Guardian writes to hospital over data sharing with Google-owned company


The legal justification used for sharing patient data from a London NHS hospital to Google-owned DeepMind wasn't valid, according to the National Data Guardian.
Health-data watchdog Dame Fiona Caldicott expressed her legal opinion of the controversial DeepMind data sharing deal in a letter to the head of the Royal Free NHS trust, after being asked for advice from the Information Commissioner, Elizabeth Denham.
The NHS trust teamed up with the deep-learning firm to trial a kidney app called Streams, which is designed to predict organ failure and avoid patient illness. As part of that, the trust shared 1.6 million patient records with the Google-owned British startup, a data-sharing move that was called "inexcusable" by academics who examined the deal.
Now, it appears our National Data Guardian agrees. Writing to Stephen Powis, medical director at the Royal Free NHS Trust, Caldicott particularly criticised the justification for the data sharing, saying it was implied that it was for patient care - but she noted that's not what the Streams trial was actually about.
"Taking into account what you have now clarified, it is my view and that of my panel that the purpose for the transfer of 1.6 million identifiable patient records to Google DeepMind was for the testing of the Streams application, and not for the provision of direct care to patients," Calidcott said in the letter, shared Hal Hodson, who initially revealed the data sharing agreement while a New Scientist reporter, and who also co-authored the aforementioned paper.
"Given that Streams was going through testing and therefore could not be relied upon for patient care, any role the application might have played in supporting the provision of direct care would have been limited and secondary to the purpose of the data transfer," she wrote. "My considered opinion therefore remains that it would not have been within the reasonable expectation of patients that their records would have been shared for this purpose."
Caldicott has shared that opinion with the Information Commissioner as part of the data watchdog's investigation.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Caldicott added that guidance would be "useful" to organisations looking to test such technologies with patient data, and stressed that her and her panel of experts "keenly appreciate the great benefits that new technologies such as Streams can offer to patients".
However, she stressed that misusing patient data could delay the use of such technologies. "As I know you also appreciate, wherever patient data is used, it is absolutely paramount that this is done in a transparent and secure manner, which helps to build public trust, otherwise the full benefits of such developments will not be realised, and indeed harm may be done."
DeepMind altered its data-sharing setup with the NHS after the initial round of complaints, and has since set up more trials.
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
NHS supplier hit with £3m fine for security failings that led to attack
News Advanced Computer Software Group lacked MFA, comprehensive vulnerability scanning and proper patch management
By Emma Woollacott
-
Cyber attack delayed cancer treatment at NHS hospital
News A cyber attack at Wirral University Teaching Hospital in 2024 delayed critical cancer treatment for patients, documents show.
By Nicole Kobie
-
Alder Hey Children’s Hospital confirms hackers gained access to patient data through digital gateway service
News Europe’s busiest children’s hospital confirmed attackers were able to steal data from a compromised digital gateway service
By Solomon Klappholz
-
Major incident declared as Merseyside hospitals hit by cyber attack
News The incident, which has led to cancelled appointments, is just the latest in a series of attacks on healthcare organizations
By Emma Woollacott
-
Thousands of procedures canceled at London hospitals as Qilin releases blood test data
News The attack on blood testing company Synnovis continues to affect patients, while the ransomware group follows through with its threats
By Emma Woollacott
-
Ransomware group threatens to publish 3TB of stolen NHS Scotland data after posting proof of attack
News NHS Dumfries and Galloway has confirmed some of the sensitive data stolen during the 15 March attack has been published by a known ransomware operator
By Solomon Klappholz
-
Attack on third-party software vendor disrupts NHS ambulance services
News The ambulance services serve more than 10 million people across the south of England
By Ross Kelly
-
NHS data leak raises ‘serious questions’ about Manchester University cyber attack
News NHS patient data used for research purposes is believed to have been compromised in the June attack
By Ross Kelly