Nottingham Forest owner sues Crystal Palace over ‘gun banner’
by: Adham Harker
August 13, 2026
Apr 24, 2026 | By: Adham Harker
Medical data is – rightly – subject to more rigorous data processing requirements than more mundane data. This week, UK Biobank self-reported to “the government” (as reported widely in the press) over the discovery of 500,000 participant’s medical research data for sale on Alibaba, it quickly became big news.
Biobank collects medical data from hundreds of thousands of volunteers so that patterns of illness/disease can be mapped against metrics including age, gender, lifestyle habits, and socio-economic status (amongst many other things). It is a repository of sorts, enabling ground-breaking research around the world.
The data Biobank collects is ‘de-identified’, so that names, addresses, and full dates of birth are stripped from it, leaving only the underlying metrics and data concerning illnesses (etc.) in it. Despite being ‘de-identified’ (or ‘anonymised’ as some have reported), the data can still be ‘personal data’ within the meaning of the UK GDPR – the test is whether the data relates to a person who is identified or identifiable, and given the extent of the data concerned, some people would likely be identifiable from it. It is presumably for this reason that Biobank self-reported to the Information Commissioner’s Office.
That was plainly a necessary first step, but Biobank then had to decide how to handle the fallout from this embarrassing episode. Crisis management and organisations’ responses to dealing with these types of issues vary greatly. Some – such as Home Depot following its 2014 payment processing breach – took the contrite approach, apologising for the issue and promising (and visibly implementing) immediate overhauls of processes and systems. Others, such as Uber after its 2016 cyber-attack, gambled on a cover up, paying the hackers to try to hide the breach: it ended up paying a $148m fine to US regulators.
Biobank has gone on the offensive, identifying three research institutes to which the data had been transferred legitimately as part of its research projects, and describing them as “rogue researchers”. The obvious inference is that Biobank says that these rogue researchers have sold or were attempting to sell the data. It has also announced that the institutions’ access to research data will be strictly limited and monitored going forward.
Approaching the breach in this way seems to have satisfied many of Biobank’s volunteer data donors, with several statements being made in support of Biobank’s work.
Articles are intended as an introduction to the topic and do not constitute legal advice
by: Tom Double
August 11, 2026
by: Hermione Hill
August 9, 2026
by: Tom Double
August 7, 2026