You can skip reading the article, as it does not list any "errors" that have happened. It merely questions whether the agreement under which the data is shared has adequate protections.
Indeed. The paper itself details seven "transgressions:" > 1) We do not know––and have no power to find out––what Google and DeepMind are really doing with NHS patient data, nor the extent of Royal Free’s meaningful control over what Google and DeepMind are doing; > 2) Any assurances about use of the dataset come from public relations statements, rather than independent oversight or legally binding documents; > 3) Th…
In a "that can't possibly be true" sense? Well, yeah, that's kind of the point...
1-3 seem like the sorts of things that even the least privacy-sensitive person can agree are troublesome.
If Google is willing to give anyone who signs a set of modest legal agreements carte blanc unaudited access to data stored on their servers, I'll begin to even remotely consider entertaining the claim that 1-3 aren't important.
5 in particular is blatantly illegal in the UK unless DeepMind is providing direct care. They claim apps == care (IMO absurd).
6 should just straight up be illegal.