Never mind the usefulness of contact tracing. The issue here is that Google and Apple clearly said "Thou shalt not create logs of user locations". NHS (i.e. government) first said "OK", but then tried to sneak in user location logging as part of an update. To which Google and Apple said "hard NO". Which is the correct response to privacy-violating function creep.
I think there's a big difference between some tech company secretly logging user locations for their nefarious, privacy-violating money-making ends, and a national health system working to allow life to return to normal for millions of it's citizens whist trying to prevent hundreds of thousands of deaths in the midst of a worldwide pandemic. I think Apple/Google should put a little bit more effort into this -- this s…
Apple and Google then proved that effective contact tracing was possible without building a centralized location repository and offered a toolkit based on that approach. The next iteration - ground-up rewrite, really - of the NHS app then used that toolkit, and functioned just fine.
Data minimisation / parsimony of collection is one of the principles enshrined in UK data protection law. It's common sense, too. One cannot leak or misuse data one doesn't collect. Since the NHS app worked just fine without uploading location history to a central repository, it follows that the reason for wanting to do this anyway was unrelated to the app's ostensible purpose.
Plenty of venues and shops make it a condition of entry now to scan their QR code into the NHS app. Not scanning the code, or not having the app installed means no entry to shops and (takeaway) restaurants. The thing is becoming compulsory by the back door. A choice not to install or use it no longer exists. This is worrying in its own right, but it is also a very good reason to insist that its data collection and use are limited to what is strictly necessary for the app to function.