Author: Toon Segers, Director National Security, Roseman Labs
I have read a lot of data sharing proposals, and most of them propose something along the lines of: put everything in one place, and protect it with access controls and fair-use policies. But we're reaching a wider consensus that that doesn't always hold up in practice. Fragmented information has real costs, so bringing data together all in the same place seems like a logical conclusion. But does the problem actually require one place, or is it just the way it's always been done?
New data sharing plans for UK Policing
Privacy International recently posted about the UK's plans for a National Data Integration and Exploitation Service [1], a system meant to connect data across more than 50 law enforcement agencies, the Home Office, the Ministry of Justice and others. Their main concern was how these organisations can enforce proportionality at that scale; a measure that "sets purpose, scope, means and duration of data processing", balancing the use of the data against the objectives an initiative sets out to achieve [2].
Data protection needs more than policy guarantees
Privacy International build on Computer Weekly's reporting [3] on Bedfordshire Police's own risk assessment, which flags a medium risk that personal data will be processed beyond what's proportionate or necessary. In plain terms, people’s data can be used for non-approved purposes. It’s recognition that even when built carefully, pooling leads to consequences that cannot be mitigated through policy or promises. It's a useful window into where these conversations in UK policing are heading, and it's not a UK-specific issue. Every country running multiple police forces and justice bodies from separate systems runs into the same wall.
The National Data and Analytics Office describes the goal as a "single version of the truth". You can argue that multiple agencies working from one accurate, shared picture instead of six partial ones is a good goal. Where I'd push back is the assumption that a single version of the truth requires a single version or centralisation of the data.
Alternatives to data centralisation
Ongoing research into this exact question, led by LSE Innovation and UNICRI, describes the alternative as a ‘Civil Public Safety Platform’ [4] for multi-agency governance, rather than one central database. Local collaborations form around a specific security problem, each running joint analysis within its own boundaries, and connect to each other only where the problem itself crosses sectors or borders. No single system ends up holding everyone's data to make that connection work.
It's already the shape of several initiatives running in the Netherlands, in cybersecurity, financial crime and countering organised crime, where agencies get a shared, trusted picture without any of them exposing their underlying records to the others.
A shared truth should be upheld by more than one custodian.
If NDIES or anyone in UK policing is thinking through what a shared national picture looks like (without a shared national database) and wants to see how that holds up in practice, I'd be happy to share more about the cases already active, or connect them to peers in Dutch agencies where they are building these systems.
[1] Privacy International https://www.linkedin.com/posts/privacy-international_inside-police-plans-to-share-intelligence-activity-7490071829059977216-mEg-/
[2] EDPS Guidelines on assessing the proportionality of measures that limit the
fundamental rights to privacy and to the protection of personal data 19-02-25_proportionality_guidelines_en.pdf
[3] Computer weekly Inside police plans to share intelligence and crime data across the UK | Computer Weekly
[4] LSE and UNICRI series Reimagining policing
Generate new insights on sensitive data with Roseman Labs’ secure Multi-Party Computation technology. Want to find out how your organization can do that? Contact us using the form below.
Newsroom
Recent Posts
Book a demo
Enter your details and we'll be in touch to book a free, no-obligation demo with you.
You'll leave with an understanding of:
- How you can apply new capabilities to workflows for faster insights
- How connected intelligence helps to prioritise and address urgent data challenges
- How encrypted computing resolves data sharing restrictions
Read more about our commitment to privacy in our Privacy Policy.