This is a joint statement made with the Department for Science, Innovation and Technology.
Human genomic data drives medical and scientific breakthroughs that benefit people by helping to identify some of the underlying factors in who will develop diseases and how they progress, leading to the development of new treatments. It also contributes significantly to global scientific benefit and economic growth. The UK is a global leader in human genomic data, due to the scale, richness and diversity of its datasets.
However, we also know that human genomic data, if shared without due care, has the potential to present national, economic and biological security risks to the UK. The UK Government are committed to keeping human genomic data safe. Keeping human genomic data secure is also important in maintaining the trust of the public in how their health data is used, even more so when people have voluntarily shared their genomic data for research studies. While there are clear legislative requirements and regulatory frameworks that help protect people’s health data, there is no clear statement of the Government’s expectations regarding how human genomic data should be made available for research.
Therefore, over the last 12 months, we have been considering how to protect people’s privacy and security, while continuing to make human genomic data available for legitimate research. Today we are publishing new guidance for UK Government funded major holders of human genomic data that make data available to external users. This applies to Genomics England, Our Future Health, UK Biobank and NIHR BioResource. It sets out recommendations on how these bodies can make data available in a way that manages the benefits of global access and use of human genomic data, while managing security risks.
The guidance is in three parts:
The first part uses the Office for National Statistics’ “Five Safes” framework, which is widely regarded as best practice in protecting data when making it available to users.
The second part sets out a framework to support major holders of human genomic data when considering whether to make data available to users outside of the UK.
The third part sets out the expectations on protective security and the measures that holders should have in place to manage insider risk and protect their physical environment.
The guidance makes clear recommendations for how major holders of human genomic data should make data available using the Five Safes framework: safe settings, safe data, safe people, safe projects and safe outputs. It recommends that:
Human genomic data should be made available through one or more secure data environments, which have an appropriately robust “airlock” in place—the airlock places controls on the data and tools that are allowed into or out of an SDE.