> 1) We do not know––and have no power to find out––what Google and DeepMind are really doing with NHS patient data, nor the extent of Royal Free’s meaningful control over what Google and DeepMind are doing;
> 2) Any assurances about use of the dataset come from public relations statements, rather than independent oversight or legally binding documents;
> 3) The amount of data transferred is far in excess of the requirements of those publicly stated needs, but not in excess of the information sharing agreement and broader memorandum of understanding governing the deal, both of which were kept private for many months;
> 4) The data transfer was done without consulting relevant regulatory bodies, with only one superficial assessment of server security, combined with a post-hoc and inadequate privacy impact assessment;
> 5) None of the millions of identified individuals in the dataset were either informed of the impending transfer to DeepMind, nor asked for their consent;
> 6) The transfer relies on an argument that DeepMind is in a “direct care” relationship with each patient that has been admitted to Royal Free constituent hospitals, even though DeepMind is developing an app that will only conceivably be used in the treatment of one sixth of those individuals; and
> 7) More than 12 months into the deal being made, no regulator had issued any comment or pushback.
Quite a few of these strike me as rather absurd, but I don't know the regulatory environment in the UK.
In a "that can't possibly be true" sense? Well, yeah, that's kind of the point...
1-3 seem like the sorts of things that even the least privacy-sensitive person can agree are troublesome.
If Google is willing to give anyone who signs a set of modest legal agreements carte blanc unaudited access to data stored on their servers, I'll begin to even remotely consider entertaining the claim that 1-3 aren't important.
5 in particular is blatantly illegal in the UK unless DeepMind is providing direct care. They claim apps == care (IMO absurd).
6 should just straight up be illegal.
3. If you want to learn new insights, you — by definition — need to include data that a priori don't seem directly related. This point even notes that the data was technically and legally well-scoped.
5. Sounds like they were within the terms of the existing data privacy agreements given 6. Again, I don't know UK privacy laws.
6. My impression from the paper is that they're not only trying to manage AKI but also improve the detection of it. Ok, sure, they're not going to improve detection in deceased or transferred patients. Those probably should have been minimized.
I'm not opposed to that in general, but there really ought to be 1) an opt-in or at least a well-advertised opt-out mechanism; and 2) an independent audit of how data is used.
FWIW I think this was a healthy push-back against "just trust us" and hope the result is a cleaner template for future similar projects.