Following a recent data incident, UK Biobank will adopt new security guidelines to better protect participant data, based on guidance by an independent Oversight Committee.
In April 2026, UK Biobank, which maintains a database of genomic and health data from over 500,000 participants, found that deidentified patient-level data exported from its Research Analysis Platform was being offered for sale on Chinese ecommerce websites (see BioNews 1336). The listings were removed following a collaboration between UK Biobank and the British and Chinese governments, and access to the biobank's data was paused. Now, after a full investigation by the Oversight Committee, a report has been published which details nine recommendations for better data security, and quicker reporting and responding to incidents. UK Biobank has pledged to implement all of these recommendations.
'We are determined that the organisation learns and fully takes on board the lessons from this incident,' wrote Bernard Taylor, chair of the Oversight Committee, in a letter introducing the report. 'Participants' continuing trust and confidence in UK Biobank is vital to our mission of supporting health-related research that makes a difference and must be maintained.'
The report recommends establishing a standing committee to attend to any future incidents within 24 hours, and creating a dedicated security team within UK Biobank. In parallel, the organisation is advised to conduct an external security review of all its systems, and an end-to-end review of its access policies.
The guidance also recommends implementing tighter controls to automatically prevent all future downloads of participant-level data from the Research Analysis Platform, and the removal of UK Biobank data already exported by researchers across the world. A significant number of research groups currently hold patient-level data obtained before UK Biobank transitioned to a platform-only model in 2024, under which scientists were instructed to conduct their analyses directly on the Research Analysis Platform, without exporting data.
Alongside the Oversight Committee report, the UK Government has published its own new guidance entitled Safeguarding UK Human Genomic Data. That guidance focuses on the 'Five Safes' framework for sensitive research data, which was originally developed by the Office for National Statistics.
Dr Matt Westmore, chief executive of the Health Research Authority, commented on the government's new guidance: 'Protecting data and maintaining the trust that participants place in its appropriate use, is essential. This new guidance is an important step in strengthening confidence in how human genomic data is accessed, safeguarded and used for research and innovation.'
UK Biobank has announced that 'work is already underway' to implement the new recommendations. Its Research Analysis Platform, paused since April 2026, will have a phased reopening from September 2026.


