POLICY LANDSCAPE

United Kingdom — Policy Landscape

Five frameworks shaping data, AI and evidence governance in the United Kingdom, from UK GDPR and the Data (Use and Access) Act to NHS Secure Data Environments and MHRA guidance.

UK GDPR and Data Protection Act 2018
In force UK GDPR; Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025 Reviewed 14 September 2026

The UK GDPR and Data Protection Act 2018 remain the principal frameworks governing personal data processing in the United Kingdom.

They establish requirements concerning lawful processing, accountability, security, individual rights and the handling of special-category information such as health and genetic data.

Why it matters for provenance

Organisations increasingly need to demonstrate not only that personal information was lawfully accessed but also what was subsequently done with it.

Evidence systems should therefore preserve relevant processing context without unnecessarily duplicating or exposing the protected information itself.

Data (Use and Access) Act 2025
In force — provisions being commenced Data (Use and Access) Act 2025; Royal Assent 19 June 2025 Reviewed 14 September 2026

The Act introduces reforms across data protection, digital verification services and Smart Data, while retaining the UK GDPR and Data Protection Act rather than replacing them.

Provisions are being brought into force in stages through commencement regulations, so the applicable position depends on the date in question. The provisions most relevant to research — including the meaning of research and statistical purposes, consent to processing for scientific research, and the associated safeguards — were commenced on 5 February 2026.

Why it matters for provenance

The direction of UK policy is towards making data easier to use while retaining mechanisms for trust and accountability.

That increases the importance of distinguishing permission to use data from the later question of how evidence derived from those data can be demonstrated and verified.

NHS Secure Data Environments
Policy framework — implementation continues NHS England Secure Data Environment policy guidelines Reviewed 14 September 2026

Secure Data Environments are intended to become the default means through which NHS health and social-care data are accessed for research and analysis in England.

The policy is based upon controlled access rather than routine dissemination of sensitive datasets, and is built on the Five Safes framework. Twelve policy guidelines were published in September 2022 and have since been supplemented by a data access policy update. Output checking is a required part of operating an SDE, and NHS England operates a Safe Output Service through which approved outputs leave the environment.

Why it matters for provenance

Secure Data Environments protect access to source information extremely well.

The provenance challenge arises when an authorised analytical output leaves that environment. An approved result may later appear in a paper, model, regulatory submission or further analysis.

The Safe Output Service establishes that an output was checked before release. Evidence governance asks a further question: what minimum information about the authorised source, permit and analytical process should travel with that output afterwards. This is a particularly strong use case for privacy-preserving evidence provenance, and it is structurally the same problem the EHDS will create at European scale.

MHRA Guidance on GxP Data Integrity
Guidance MHRA GxP Data Integrity Guidance and Definitions Reviewed 14 September 2026

MHRA’s GxP data-integrity guidance, Revision 1 of March 2018, applies across areas including good laboratory, clinical, manufacturing, distribution and pharmacovigilance practice.

It sets expectations around compliant data-governance systems and reflects the importance regulators place on trustworthy, complete and reliable records throughout the pharmaceutical lifecycle.

Why it matters for provenance

GxP data integrity is one of the clearest regulatory examples of why evidence must be attributable, traceable and reconstructable.

The BioChain’s evidence-governance proposition does not replace established GxP controls. It addresses the additional problem that appears when evidence leaves one controlled system and subsequently becomes dependent upon records or transformations in another.

UK Regulation of AI in Healthcare
Regulatory framework under development National Commission into the Regulation of AI in Healthcare, recommendations published 10 September 2026; MHRA AI Airlock Reviewed 14 September 2026

The UK’s approach to healthcare AI continues to develop through the MHRA and the wider health system. The MHRA’s AI Airlock regulatory sandbox has tested real AI-as-a-Medical-Device technologies and the regulatory challenges they raise.

The National Commission into the Regulation of AI in Healthcare, established by the MHRA in September 2025 and chaired by Professor Alastair Denniston with Professor Henrietta Hughes, published its recommendations on 10 September 2026. They address accountability and liability, transparency, organisational governance, workforce training and system-wide assurance.

The MHRA and Government have said they will respond formally in due course. This entry will be updated when that response is published.

Why it matters for provenance

Healthcare AI introduces a particularly difficult evidence problem because models may change, interact with external datasets, generate probabilistic outputs and contribute to decisions alongside clinicians and other systems.

A robust evidence chain may therefore need to preserve information about model identity, version, intended use, significant inputs and outputs, validation context and human intervention.

Without that history, a later reviewer may be able to see the clinical decision without being able to reconstruct the computational evidence that informed it. The Commission’s emphasis on accountability and system-wide assurance makes that reconstruction question more pressing, not less.

Questions & Answers

Has the Data (Use and Access) Act replaced UK GDPR?

No. It introduces reforms to data protection, digital verification services and Smart Data while retaining the UK GDPR and Data Protection Act 2018 rather than replacing them. Provisions are commencing in stages.

What happens to an approved output once it leaves an NHS Secure Data Environment?

The Safe Output Service confirms it was checked before release. What it does not establish is what minimum information about the authorised source, permit and analytical process travels with that output afterwards — which is exactly the evidence-governance question this page is tracking.

Does MHRA GxP guidance cover evidence that moves between organisations?

It sets strong expectations for data integrity within a controlled system. It does not address what happens when evidence leaves one controlled system and becomes dependent on records or transformations in another — the gap our evidence-governance work is aimed at.

Is there a UK framework specifically for AI in healthcare yet?

Not a finalised one. The National Commission into the Regulation of AI in Healthcare published recommendations on 10 September 2026; MHRA and Government have said they will respond formally in due course.

← Back to the Policy & Regulatory Landscape overview