(1 week, 1 day ago)
Lords Chamber
Baroness Gill (Lab)
My Lords, today I address a challenge that sits at the intersection of public service and my professional background, and I thank the noble Lord, Lord Patel, for this timely debate. Over a decade ago, I was working in the data analytics sector. It was an era when my colleagues and I routinely repeated a phrase that has now become a bit of a cliché: “Data is the new oil”. We were at the beginning of a digital bonanza, watching a frontier expand while Governments maintained a largely laissez-faire approach, long before modern privacy regulations were covered by the Data Protection Act and GDPR that we rely on today.
I raise this because the data landscape has evolved exponentially since my time in the industry. Today, the pressures to find solutions to chronic diseases are immense. While I deeply share the health professionals’ enthusiasm for laudable life-saving research, those of us with backgrounds in data know a quiet truth. In the rush to find health solutions, individual privacy can inadvertently be compromised if our security frameworks do not evolve as fast as the technology.
We had wake-up calls this April, and some noble Lords who spoke before me highlighted the case of rogue researchers at a partner institution in China who violated their contracts and attempted to list the data of 500,000 UK Biobank volunteers on Alibaba. It was a near miss for our research ecosystem. Thankfully, swift action prevented actual sales and the data itself lacked direct personal identifiers but, as your Lordships’ House knows, the methods of data manipulation have grown sophisticated—far beyond what we imagined a few years ago. The rise of advanced artificial intelligence has fundamentally changed the game.
Today, deidentifying data is no longer a permanent shield. With modern AI algorithms, bad actors can cross-reference anonymised health files with external commercial datasets to reidentify individuals with terrifying ease and accuracy. If the public begin to fear that AI will be used to turn their altruism into exposed personal medical records, public trust will evaporate. We cannot let that happen. I urge the Minister to secure the system so tightly that public trust remains unbreakable. I urge a shift away from data extraction entirely, moving instead towards trusted research environments and requiring external commercial players to run their AI analytics inside a secure government-hosted cloud, where they can query the data but never download or export raw files.