NHS England has conceded that a data-protection document misdescribed who can access identifiable patient records, obscuring that Palantir staff can view identifiable data inside part of the Federated Data Platform. The National Data Guardian flagged it; NHS England apologised for the ‘error’. The substance underneath — a contractor able to see identifiable records — is what critics have objected to since the £330M contract.
NHS England has admitted that an official data-protection document misdescribed who can see patients’ identifiable records — obscuring the fact that staff at Palantir, the US data-analytics firm, can access identifiable patient information inside part of the health service’s Federated Data Platform.
NHS England has admitted that an official data-protection document misdescribed who can see patients’ identifiable records — obscuring the fact that staff at Palantir, the US data-analytics firm, can access identifiable patient information inside part of the health service’s Federated Data Platform. The admission, reported by The Register and The Next Web, follows scrutiny from the National Data Guardian and reopens a long-running fight over how much of England’s most sensitive data a private contractor should be able to touch.
What the paperwork got wrong
When the National Data Guardian reviewed the Data Protection Impact Assessment (DPIA) for the platform, the document stated that access to identifiable patient information would be limited to NHS staff with a legitimate need. That turned out not to be the full picture. Media reporting, later confirmed by the programme team, established that some external supplier staff — including at Palantir — can also access identifiable patient information within the platform’s National Data Integration Tenant, for specific technical purposes and under NHS direction.
NHS England has conceded the mistake. “We recognise that the DPIA contained an error in how it described supplier access to data, so we are correcting that error, and we apologise for any confusion this has caused,” it said. An apology for a paperwork “error” is one thing; the substance underneath — that a contractor can see identifiable records at all — is what critics have objected to from the start.
Why this contract is contentious
Palantir won a £330 million contract to build the Federated Data Platform in 2023, after earlier picking up COVID-era work — some £60 million of it — without competition. The company’s roots in defence and intelligence analytics have made privacy campaigners uneasy about handing it a central role in NHS data infrastructure. The core promise of the platform was that it would let different parts of the health service share and analyse data more effectively while keeping identifiable information tightly controlled. A DPIA that understated who could see that information cuts directly against that promise.
The trust problem
The technical detail here matters less than the pattern it fits. Patients are asked to trust that their most sensitive information — diagnoses, treatments, histories — is governed by clear, accurate rules about who can access it. When the governing document turns out to be wrong about exactly that, the damage isn’t only to one assessment; it’s to the credibility of the whole assurance regime. “Trust us, the paperwork is watertight” is a hard sell once the paperwork has been publicly corrected.
For a programme whose entire value depends on public willingness to let data be pooled and analysed, that erosion of confidence is the real cost. Data-sharing in healthcare can genuinely save lives; it also only works if people believe the controls are real. Every disclosure like this one makes the next data-sharing initiative — however well-intentioned — harder to get consent for.
What to watch
The National Data Guardian has been seeking clarification on exactly what access exists and under what safeguards, and the corrected DPIA will be scrutinised closely. The broader question outlasts this single document: as public health systems lean on private analytics firms to modernise, who is genuinely accountable when the description of who-can-see-what turns out to be inaccurate — and what does it take to earn back the trust that makes the whole enterprise possible?
Sources: The Register; The Next Web.