Privacy-Enhancing Technologies and Privacy-By-Design for Medical AI
This paper examines how privacy-enhancing technologies such as synthetic data, federated learning and ‘Secure Data Environments’ can be integrated into artificial intelligence ( AI ) development processes to uphold key data protection principles in the UK GDPR , like storage limitation, data minimisation, purpose limitation, security, and fairness. The analysis highlights how privacy-enhancing technologies offer benefits beyond anonymisation by embedding privacy-by-design values to support responsible innovation and protect sensitive patient data throughout the design, training, and validation of medical AI systems. The paper uses the 2015 DeepMind and Royal Free case as a practical study to realise the practical and legal benefits of privacy-enhancing technologies in medical AI development, particularly involving public-private collaborations. While grounded in the UK context, the findings have broader relevance to the European Union and other international jurisdictions grappling with tensions between data protection and AI development in the healthcare context.