L

Lord Markham (Con)

Speaking in the House of Lords on 28 April 2026

Debate

UK Biobank Data

Contribution

My Lords, I thank the Minister for the Statement. This is clearly a serious incident that goes to the heart of public trust in one of our most important research assets. I pay tribute to the hundreds of thousands of volunteers whose data underpins the success of the UK Biobank and the breakthrough it has enabled. It is right that swift action has been taken to remove the listings and suspend access. It is also right to involve the Information Commissioner’s Office. However, the central issue before us is not just what has happened but what it reveals about our capacity to defend ourselves against cyber attacks. First, on enforcement and accountability, we are told that the institutions involved have been banned. That is, of course, welcome, but it is sufficient? Were contractual terms breached in relation to data of this sensitivity? There must be clarity about deterrence and whether further sanctions, legal or financial, are available and will be pursued. Without that, I fear that we risk sending the wrong signal. This incident also seems to highlight deeper weaknesses in our wider infrastructure. We continue to have a system that relies heavily on trust and contractual compliance, but without robust technical safeguards to prevent misuse; it is not enough simply to tell users not to download data—we must design systems so that they cannot do so inappropriately. This is a design issue as much as a behavioural one. From my time as Health Minister, I am aware that NHS databanks do not allow the downloading of data on to third-party servers. The data remains on our servers in a sectioned-off area to allow the customers to analyse and manipulate the data but not download it, so these types of breaches cannot take place. There is a strong case for a clear step-by-step plan from UK Biobank, setting out exactly how data access will be reformed, including the technical controls that will be put in place, binding commitments to ensure that this cannot happen again, and the stopping of the ability to download the data directly. In addition, there is a strong case for reviewing the data storage and retention policies of all our health bodies. During the cyber attack on the London blood testing organisation in 2024, I was amazed that the names of the people being tested were given to the companies, along with the samples, for them to perform the test results. They did not need to have those names at all; all they needed to have was a unique reference number, so that data did not need ever to be out there in the first place. What surprised me even further was to find out that this same company had data for individuals going back five, 10 or 15 years, and did not seem to have any deletion policies in place to make sure that the data was not even there to be hacked in the first place. As the Minister responsible at the time, I proposed a review of the data storage and retention policies of all the NHS bodies and their associated contractual parties, but this was just before the election, so I am not aware whether or not that review took place in the end. I would be grateful, therefore, if the Minister could update us on whether this did in fact happen. I turn to the point raised in Committee on the cyber security and resilience Bill currently going through the other place. The Conservatives tabled an amendment which would have required the Secretary of State to maintain a register of hostile actors targeting critical sectors, including health. Regrettably, that amendment was not accepted. In light of this incident, I ask the Minister whether the Government will now revisit that decision. If not, will he at least consider how we strengthen our understanding and monitoring of potential threats in this space? While we must not lose sight of the immense value of UK Biobank, maintaining public confidence will be essential. That confidence depends on not only the integrity of the data but the strength of the safeguards around it. As the cyber security and resilience Bill comes to our House, we must make sure that we learn the lessons from this deeply regrettable breach. Indeed, a good test we must apply to the Bill is: if it had already been enacted, would the breach have happened in this case? This is a moment not just for a response, but for reform. I look forward to the Minister’s reply.

More from Lord Markham (Con)

Other recent Hansard contributions by the same speaker.

About Hansard

Hansard is the official verbatim record of proceedings in the UK Parliament. Every word spoken in the Commons and Lords is recorded and published — this page is a single contribution from that record.

Partner sites