Two pieces. One claim.
The consent architecture beneath NHS genomic data does not give citizens standing over their own data. These are the arguments for why that matters, and what architecture would change it.
Access Is Not Sovereignty
Patient standing in the age of the Single Patient Record
The National Health Service holds more genomic data per capita than any health system in the world. It has spent twenty-five years building the infrastructure to collect it, analyse it, and use it to understand disease. The results are real. The 100,000 Genomes Project produced findings that changed clinical practice. Genomics England sequences cancer genomes at a scale that would have been unimaginable a decade ago. The argument for collecting genomic data at NHS scale is not fraudulent. The science is genuine.
What is also genuine is the extraction architecture that the science sits inside.
Patients contribute their genomic data to NHS systems under a consent model they did not design, governed by a boundary they do not control, for purposes they cannot fully audit. Genomic data has extraordinary commercial value. When that value is realised, the benefit flows to the institution, the research buyer, and the platform operator. The patient receives a letter thanking them for their contribution to medical science.
This is not a claim about malicious intent. It is a claim about structural design. The architecture was built for extraction, not for sovereignty. The question the NHS has been asking is: how do we collect more data, more efficiently, for more research? The question it has not been asking is: what standing does the patient have over what happens to their data once it leaves their hands?
Those are different questions. The difference is what this paper is about.
Political theory has a name for what’s missing, and naming it forecloses the obvious response to this paper. Most data rights arguments are arguments about interference: stop the misuse, and freedom is restored. There is an older, harder claim — traced by the political theorist Ben Rogers, reviewing Stuart White’s 2025 study The Wealth of Freedom: Radical Republican Political Economy in the Times Literary Supplement on 17 April 2026, back through four centuries of English republican thought to the Putney Debates above. Freedom is not the absence of interference. It is the absence of what Rogers calls “subjection”: power an institution holds over you that it could exercise at will, whether or not it ever does.
This is why the obvious fix does not work. Move the servers to Britain. Put the contract under British law. Remove the CLOUD Act exposure entirely. None of that gives the patient standing. A perfectly sovereign NHS infrastructure still leaves the patient with no lever over their own data. The interference is removed. The domination remains.
The consent model and its failure
The national data opt-out, introduced in May 2018, is the mechanism by which a patient in England can prevent their confidential patient information being used for purposes beyond their individual care. Research, planning, secondary analysis. All of it can be opted out of with a single choice, stored against the patient’s NHS number on the Spine.
One binary setting. In or out of secondary use. No granularity within that choice. No purpose-specific selection. No condition-specific carve-out. No time limit. The patient decides once and the decision covers everything defined by the NHS as secondary use.
Direct care is exempt. A clinician cannot be prevented from accessing a patient’s record during an episode of treatment. This is legitimate and necessary. Clinical care cannot wait for a consent decision at every touchpoint.
The exemption is where the architecture fails.
The boundary between direct care and secondary use determines whether the opt-out applies at all, and that boundary is defined and applied by the institution processing the data, not by the patient. The patient set a preference. The institution decides what that preference applies to.
The NHS FDP’s own documentation makes the phenomenon visible. Classification moves in fluid response to institutional need. Practitioners working within NHS data governance have described this as the lava lamp problem. Aggregate cardiovascular risk analysis and population-level planning look like secondary use at system level. They get reclassified as direct care at the point where individual re-identification becomes possible and clinical intervention is contemplated. The opt-out no longer applies. Nothing changed in the patient’s consent position. The institution changed the label.
The NHS Federated Data Platform’s overarching DPIA makes this legible in writing. Supply chain management, described in the document as “getting the best value for the NHS,” is listed as one of five FDP use cases. The same document classifies all identifiable data processing within the platform as being for direct care purposes only. The national data opt-out therefore does not apply to a use case that has nothing to do with treating an identified patient. The National Data Guardian accepted this classification. In June 2026, the NDG confirmed in a published statement that the FDP “is currently used solely to support care delivery” and therefore the national data opt-out does not apply. The same month, it emerged that the NDG had not been informed that external contractors, including Palantir, had been granted access to identifiable patient data, a disclosure made only after parliamentary and press scrutiny. The classification the opt-out depends on was accepted without full knowledge of who held the data.
The Caldicott definition of direct care is explicit: direct care is clinical activity concerned with the prevention, investigation and treatment of illness of an identified individual.
Procurement optimisation is not that.
The opt-out is structurally insufficient wherever an institution has an incentive to classify secondary use as direct care. The patient has a binary choice. The institution controls what that choice applies to. A preference whose application is controlled by the party with the most to gain from narrowing it is not meaningfully a preference.
The FDP is not an isolated case. The same structural problem operates inside the NHS genomic testing pathway itself, through a different mechanism.
The national data opt-out applies to confidential patient information held in NHS records. It does not, and was never designed to, apply to data contributed to the National Genomic Research Library. The NGRL is a different system entirely, run by a different organisation, governed by the NHS Genomic Medicine Service’s own Record of Discussion form completed specifically at the point of whole genome sequencing. A patient who exercises the national opt-out has reasonably protected their NHS records from secondary use. If they are later offered whole genome sequencing, the question of whether their genome enters the National Genomic Research Library is asked and answered separately, on infrastructure the national opt-out was never built to reach.
This is not classification drift. It is a parallel architecture. The patient made an active choice. The choice was honoured in the NHS records system. The second system was never subject to it.
Once a patient’s genomic data has been contributed to the NGRL, they cannot remove it. They can stop future use of their data. They cannot withdraw data already contributed. An active opt-out exercised after the fact does not undo what the Library already holds.
Three mechanisms. One outcome. The patient’s consent preference does not protect them. The institution reclassifies secondary use as direct care and the opt-out becomes inapplicable. The patient exercises the national opt-out, correctly protecting their NHS records, and later finds that whole genome sequencing asks an entirely separate question on a system the opt-out was never designed to reach. The patient discovers this and tries to withdraw from the National Genomic Research Library and finds they can stop the future but not recover the past.
This is the consent model the NHS is about to extend to a Single Patient Record.
The structural convergence
The King’s Speech of 13 May 2026 announced legislation for a Single Patient Record. Every patient’s medical records in one place, accessible to the patient via the NHS App by default by 2028. A legislative duty on every health and care provider to make the information they record available to the patient.
This is framed as patient empowerment. Patients will be able to see their records. They will not hold them. The record lives in NHS-held infrastructure. There is no consent architecture beneath the Single Patient Record. The patient gains a view. They do not gain standing.
The Single Patient Record is built for one kind of data: episodic, institutionally authored, accumulated one encounter at a time. A genome is not that kind of record. Nobody authors a genome. It exists, complete, from the moment a person is conceived, and a genomic test does not create that fact. It transcribes it. The data is not a record of an event in a patient’s healthcare history. It is closer to a complete copy of a biological whole that predates any healthcare history the patient will ever have.
Fit for the Future: Ten-Year Health Plan for England sets out an ambition for the Single Patient Record to directly incorporate genomic data over the coming decade, as part of a wider ambition for genomics to inform up to half of all patient interactions by 2035. Folding a transcription of a biological whole into a record built for institutionally authored clinical entries does not simply add a data type to an existing system. It extends the SPR’s institutional-authorship logic to the one kind of health data where that claim has no basis at all.
The same legislation abolished Healthwatch England and all 150-plus local Healthwatches. Patient advocacy becomes internal to the commissioning body. The Patient Safety Commissioner is being transferred into the MHRA under the same legislation. The most credible independent patient safety voice in England is being absorbed into the body hosting AI governance.
The MHRA Commission’s Technology Working Group is chaired by the DeepMind Professor of Machine Learning at the University of Cambridge. Its membership includes Palantir, Google, Google DeepMind, Microsoft, Apple, Accenture, Deloitte, Epic, IBM, Isomorphic Labs, and General Catalyst. There is no patient organisation in the Technology Working Group. Nobody in that room has a commercial interest in raising the question of what standing a patient has over their data once it enters a system.
The same plan states an ambition to make genomic capture universal at the point of birth. Left as it stands, standing is not merely absent for the current generation of patients. It is designed out of the system for the next one, before that generation can hold an opinion on the matter.
What absence of standing has already cost
The risk this convergence describes is not hypothetical. The NHS’s own record contains a repeated, formally documented pattern: citizens and families with no structural lever over decisions being made about them, and harm that followed from the absence of one.
Martha Mills died in August 2021, aged thirteen, at King’s College Hospital, London. Her family raised repeated concerns about her deteriorating condition. Those concerns were not acted upon. A 2023 coroner’s inquest found that Martha would probably have survived had she been transferred to intensive care sooner. Martha’s Rule — giving patients, families and carers direct access to an independent rapid clinical review, twenty-four hours a day — was rolled out across NHS acute trusts in England from April 2024. By April 2026, more than 14,600 calls had been made to Martha’s Rule helplines, and 2,720 had required a change in treatment. Martha’s Rule is the NHS’s own acknowledgement that the prior structural relationship was insufficient. It is the republican standing argument, already accepted inside the NHS, for one category of decision.
The Independent Medicines and Medical Devices Safety Review, chaired by Baroness Julia Cumberlege and published in July 2020 as First Do No Harm, found that legitimate concerns raised by patients — overwhelmingly women — had gone unheard for decades, in some cases for forty years, and described a healthcare system as “disjointed, siloed, unresponsive and defensive.”
The 2013 Francis Report into Mid Staffordshire NHS Foundation Trust found systemic failure to provide acceptable standards of care, in which the concerns of patients and families were routinely not listened to and management targets took precedence over patient welfare. It made 290 recommendations.
The Independent Maternity Review into Nottingham University Hospitals NHS Trust, led by Donna Ockenden and published on 24 June 2026, examined approximately 2,500 family cases spanning thirteen years. It found systemic governance failures known to Trust leadership since at least 2010, senior managers who downgraded serious failings for a decade to avoid external scrutiny, and 256 additional neonatal deaths the Trust had not declared. Women were not listened to when they reported feeling unwell.
These four reviews span eight years, four different clinical domains, and four different institutions. They share one structural feature. Citizens and families who raised concerns had no lever within the system to compel a response, and the institution’s own judgement about whether to act was the only judgement that counted. Each review concluded, in its own terms, that this was the failure to fix.
Genomic data sits inside the same institutional structure these reviews describe. It is more permanent than a clinical observation, more revealing than a single hospital record, and harder to govern. These reviews are not a reason to expect NHS genomic data governance to fail in the same way. They are a reason not to build an architecture that depends on it not happening again.
The question nobody is asking
The communities with the most scientifically valuable genomic data are not the communities benefiting most from the science derived from it. The NHS Race and Health Observatory’s June 2024 report reviewed 143 studies covering over 64 million participants and found ethnic minority participants at approximately 6.56% of total participant populations. It identified structural racism as “entrenched” in NHS genomics services and concluded that the over-representation of European-ancestry populations “has resulted in misdiagnoses, poor understanding of conditions, and inconsistent delivery of care.”
Increasing participation without sovereignty infrastructure does not address this. A consent campaign that signs up more people from underrepresented communities to a binary opt-out model governed by an institutionally-controlled boundary does not protect them. It expands the extraction surface.
The argument for genomic data sovereignty is not that the current government will misuse it. It is that the architecture should be the same whether the government is benign or not. In July 2025, the US Centers for Medicare and Medicaid Services granted Immigration and Customs Enforcement access to Medicaid enrolment data — administrative health records including home addresses and ethnic backgrounds — to identify and locate individuals from specific communities. Genomic data carries orders of magnitude more inferential power: ancestry, family structure, phenotypic predisposition. The infrastructure for total genomic insight, once assembled, does not become less powerful when political conditions change. Patient-held cryptographic sovereignty costs nothing if the state remains trustworthy. It is irreplaceable if it does not. This is an engineering argument, not a political one.
The unanswered question
UK GDPR does not apply after death. The legal basis for subject access rights, the right to erasure, the right to restriction of processing — all of these cease at the moment of the patient’s death. NHS policy maintains that the national data opt-out should be respected posthumously, but the GDPR rights that underpin its enforceability do not survive death. That is the difference between a preference an institution is asked to respect and one it is legally required to honour.
Genomic data shared by a parent has direct implications for children who were never party to the consent decision, because they were minors, or because they had not yet been born. The National Genomic Research Library’s existing deceased-relatives provision is the nearest existing precedent, and shows the NHS has already recognised that genomic data outlives the person it describes. It does not let the person decide for themselves, in advance, rather than leaving the decision to whichever relative is asked afterwards.
The World Health Organisation’s 2024 Guidance on Human Genome Data Collection, Access, Use and Sharing identifies posthumous consent as a structural obligation on any governance framework for genomic data. The NHS has built a process for deciding about the dead. No UK framework has built a process for the dead to have decided.
What sovereignty infrastructure changes
The national data opt-out cannot be fixed by improving the opt-out. The binary choice is not the problem. The institutionally-controlled boundary is. A better-designed binary choice applied against a boundary the institution controls is still a boundary the institution controls.
Sovereignty infrastructure begins from a different premise. The patient defines the terms. The institution comes to the patient on those terms, or receives no access. This is not an opt-out. It is the inversion of the opt-out model.
The consent architecture is multi-market. A patient can hold simultaneously: consent granted to a rare disease charity for a specific research question; consent granted to a named clinical team for direct care; consent withheld from commercial AI training; consent for pharmacogenomic research time-limited to two years. These are separate, independent decisions. They do not conflict. They do not require a phone call to change.
The consent architecture is multi-time. Consent decisions are not point-in-time. They can be updated, narrowed, extended, or revoked as circumstances change. When a use case transitions, moving from population research toward direct clinical relevance for that patient or their family, the architecture creates a new consent moment rather than allowing institutional reclassification to silently dissolve an existing preference. The patient retains standing at every transition point.
This is the lava lamp solution. The boundary does not move under institutional control because there is no institutional boundary. There are patient-defined terms, and there is access or there is not.
Patient consent as the foundation beneath institutional governance. This architecture is not a challenge to the Five Safes framework. It is its necessary foundation. Five Safes governs how approved researchers access data from approved settings for approved projects. It presupposes that the data was appropriately collected and consented. Patient-held cryptographic consent is what makes that presupposition true rather than assumed. These are not alternatives. They are sequential.
The legal argument, and its limit. Under UK GDPR, a data controller determines the purposes and means of processing personal data. The standard model places the NHS, or a contracted platform operator, as controller, and the patient as data subject. Because Vitanium’s architecture is structured so that the platform cannot read genomic content without the citizen’s active cryptographic participation — the genome never leaves the Trusted Execution Environment in plaintext, and Vitanium processes consent events and encrypted payloads, not genomic content itself — there is a substantive argument that the citizen, not the platform, is the controller of their own genomic data. This argument has not been tested with the Information Commissioner’s Office. A Data Protection Impact Assessment and formal legal review are required before it can be treated as a settled compliance position rather than an architectural trajectory.
The patient does not need to understand the architecture to be protected by it — they do not need to know what a Trusted Execution Environment is, any more than they need to understand TCP/IP to send an email. What the architecture does require of them is narrower, and unavoidable: that they know they hold the key, that they will be asked before access is granted, and that nothing happens to their data without that answer. That is not a comprehension burden the architecture imposes on the patient. It is the patient’s standing, made functional.
The conditions for the Commission’s own success
The MHRA Commission has stated three goals: patient confidence in AI-enabled care, safe deployment of AI in clinical settings, and equitable benefit from AI-driven health improvements.
Each of those goals has a consent architecture dependency that the Commission’s current scope does not address. Not because the Commission is wrong about its mandate. Because the consent question is upstream of every goal it is trying to achieve.
Patient confidence in AI-enabled care cannot be built on a unified patient record with no consent architecture beneath it and no independent patient voice in the governance of how that record is used.
Safe deployment of AI in clinical settings requires knowing that the data on which AI systems are trained was obtained with consent that is specific, informed, and enforceable. A data corpus assembled through classification drift is not a consent-grounded corpus. An AI system trained on it is not consent-grounded.
Equitable benefit from AI-driven health improvements requires that the communities contributing the most unique genomic data receive benefit rather than exposure. Increasing participation without sovereignty infrastructure accelerates exposure.
Three additions to the Commission’s framework would make its own stated goals achievable. A consent architecture beneath the data platform, implemented consistently with GA4GH’s Data Use Ontology. A testamentary consent standard, so that genomic consent can survive the patient’s death on terms the patient set in life. Independent patient representation in the technical governance of NHS data infrastructure — not internal to the commissioning body, but with standing in the room where the technical decisions are made.
Access to a record is not sovereignty over it. Seeing your data is not the same as controlling what happens to it. The Single Patient Record will give patients a view they have never had before. That is genuinely valuable. It is also, on its own, insufficient.
The Commission’s goals are the right goals. The architecture that achieves them does not yet exist in the NHS. The Commission reporting this summer is the moment to require it. That moment does not wait.
