Earlier quoted context omitted.
According to them, they got approval for doing that: > The alternative was to upload it to the cloud using tools such as Google Storage and use BigQuery to extract data from it. As PA has an existing relationship with Google, we pursued this route (with appropriate approval). This showed that it is possible to get even sensitive data in the cloud and apply proper safeguards.
And what "appropriate approval" was that, exactly? In general, exporting personal data outside of the EEA requires the explicit notification of the data subject under UK data protection law (among other consequences of the first Principle[1]). Moreover, the rules for even processing sensitive personal information, which includes health-related information, are significantly stronger than the general case. They should…
I don't think the duty on a company is all that strong - the data has to stay in Europe, on a properly protected computer. Providing you needed a password or equivalent secret to get to the data they are probably okay legally.
Given the NHS is planning to sell poorly anonymized patient records at 10'000 for $10 imminently, I think we are complaining about the wrong problem.