Finding 1) Data plays differentiated roles across neurotechnology business models, with distinct implications for governance, value creation and risk.
Neurotechnology companies operate through a wide range of business models, including research tools, algorithm and analytics services, clinical technologies, wellbeing solutions, and data platforms. This diversity shapes how neurodata are collected, processed, shared, and monetised, and therefore informs the privacy risks and safeguards that must be considered in a privacy assessment.
Some companies market hardware‑centric research tools, generating revenue through device sales and software licences while giving customers full control over the neurodata they collect. Others operate algorithm- and analytics-driven models, licensing proprietary algorithms or building large‑scale neurodata infrastructures to support cognitive AI and advanced human-computer interaction. Companies providing clinical devices and services rely on neurodata to enable diagnosis, therapy optimisation, and closed‑loop neuromodulation.
Organisations focused on wellbeing, neurostimulation, and recovery prediction operate through business to business (B2B) or business to business to consumer (B2B2C) models, creating value through device usage fees, enterprise subscriptions, and performance‑enhancement services. The sample in this study also includes a non‑profit research organisation applying an open‑science model as well as companies whose business models are still evolving (e.g. from device‑based to data‑platform models).
The role of data in company value propositions also differs. Neurodata supports clinical decision‑making and therapy optimisation; trains and validates algorithms; provides evidence for regulatory submissions and longitudinal analytics; and enables personalised, user‑centred insights in wellbeing and performance‑enhancement settings. Each of these uses raises distinct governance and privacy considerations, including anonymisation, consent management, inference risks, re‑identification concerns, and long‑term data retention obligations.
These business model differences translate into distinct privacy and governance implications:
Neurotechnology models involve different data purposes, types of collectors, user interactions, and multi‑party processing arrangements. Research tools, analytics services, clinical devices, wellbeing programmes, and data‑platform models each raise unique legal and operational questions regarding legal bases for each data use, retention periods, consent pathways, and legitimacy of sharing data with partners;
Companies face governance challenges in B2B2C models. Several companies reported concerns about downstream control of forbidden data uses, particularly their limited influence over how partner organisations use, combine, or contextualise neurodata. This creates uncertainty around compliance, user transparency, and the risk of unintended secondary uses (e.g., when neurodata collected from patients or consumers while providing them a service, is used by one of the entities for another purpose, without the individual’s knowledge and consent);
A single privacy model is not feasible. Because neurodata plays different roles across the neurotechnology lifecycle, companies stressed that one‑size‑fits‑all privacy protections do not work. Governance approaches should reflect the sensitivity, regulatory classification, and risk profile of each application and each entity participating in the processing of neurodata;
Different data uses require different legal bases and safeguards. Neurodata used for clinical decision‑making, algorithm training, evidence generation, and user insights each require an appropriate legal basis, specific safeguards, and clear allocation of responsibilities. Companies highlighted the need for explicit purpose mapping and precise determination of legal roles (controller, processor, joint controller) in line with the purpose limitation principle.
Finding 2) Use purposes of neurotechnologies influence regulatory and data protection risk assessments
A data protection impact assessment would need to consider the use purpose context in which neurodata are created, collected and processed, the risk level of the data when collected through invasive or non-invasive devices (invasive collection produces higher level of data quality and accuracy with more processing potential), the modulation performed, and the inferences derived. This assessment will influence the privacy safeguards to be employed.
Regulatory oversight on medical devices already depends on criteria including intended use purpose, degree of invasiveness, and associated risks. The UK’s RHC Neurotechnology Taxonomy illustrates this by noting that categorisation begins with determining whether a technology is invasive and whether it directly modulates neural activity, as these characteristics guide the policy approach (Regulatory Horizons Council, 2022[28]).
Recent taxonomies therefore emphasise classification based on primary intended use - therapeutic, assistive, preventive, enhancing, diagnostic, or research-driven - alongside distinctions related to invasiveness, modulation capability, and data sensitivity (Robinson et al., 2024[29]). As neurotechnologies diversify, use purpose categories have become essential for interpreting regulatory implications, ethical risks, and technological requirements both from the perspective of medical device regulation and for the implementation of data protection regulation. Table 3.1. provides regulatory pathways and ethical issues across a range of neurotechnology device use purposes, aligned with the devices represented in the study sample.