Responding to a mass data breach

Apr 24, 2026 | By: Adham Harker

 

Medical data is – rightly – subject to more rigorous data processing requirements than more mundane data.  This week, UK Biobank self-reported to “the government” (as reported widely in the press) over the discovery of 500,000 participant’s medical research data for sale on Alibaba, it quickly became big news.

Biobank collects medical data from hundreds of thousands of volunteers so that patterns of illness/disease can be mapped against metrics including age, gender, lifestyle habits, and socio-economic status (amongst many other things).  It is a repository of sorts, enabling ground-breaking research around the world.

The data Biobank collects is ‘de-identified’, so that names, addresses, and full dates of birth are stripped from it, leaving only the underlying metrics and data concerning illnesses (etc.) in it.  Despite being ‘de-identified’ (or ‘anonymised’ as some have reported), the data can still be ‘personal data’ within the meaning of the UK GDPR – the test is whether the data relates to a person who is identified or identifiable, and given the extent of the data concerned, some people would likely be identifiable from it.  It is presumably for this reason that Biobank self-reported to the Information Commissioner’s Office.

That was plainly a necessary first step, but Biobank then had to decide how to handle the fallout from this embarrassing episode.  Crisis management and organisations’ responses to dealing with these types of issues vary greatly.  Some – such as Home Depot following its 2014 payment processing breach – took the contrite approach, apologising for the issue and promising (and visibly implementing) immediate overhauls of processes and systems.  Others, such as Uber after its 2016 cyber-attack, gambled on a cover up, paying the hackers to try to hide the breach: it ended up paying a $148m fine to US regulators.

Biobank has gone on the offensive, identifying three research institutes to which the data had been transferred legitimately as part of its research projects, and describing them as “rogue researchers”.  The obvious inference is that Biobank says that these rogue researchers have sold or were attempting to sell the data.  It has also announced that the institutions’ access to research data will be strictly limited and monitored going forward.

Approaching the breach in this way seems to have satisfied many of Biobank’s volunteer data donors, with several statements being made in support of Biobank’s work.

Share this:
Adham Harker Arrow

Adham Harker

Senior Associate (solicitor)

Request a consultation

Call 020 7183 8950 or send us a message

Privacy data

Recent Reported Cases

Legal Disclaimer

Articles are intended as an introduction to the topic and do not constitute legal advice