NHS England Faces Backlash Over Palantir’s Access to Patient Data
NHS England confirmed Palantir staff can access identifiable patient data via a new admin role.
Why it matters: This access breaches prior assurances limiting data to NHS staff and threatens public trust in healthcare data privacy and transparency. Legal compliance and vendor oversight in health data handling come under urgent review.
- NHS England awarded Palantir a £330 million contract in 2023 for the Federated Data Platform (FDP).
- In May 2026, NHS England confirmed Palantir staff have 'admin' access to identifiable patient data in the FDP.
- National Data Guardian Dr. Nicola Byrne is investigating contractor access to patient data, citing prior assurances limiting access to NHS staff.
- Amnesty International UK and MPs have criticized the partnership, urging the government to reconsider Palantir’s role due to privacy and human rights concerns.
In 2023, NHS England awarded Palantir Technologies a £330 million contract to create the Federated Data Platform (FDP), designed to integrate NHS patient data for improved healthcare outcomes. However, recent disclosures have sparked controversy and scrutiny regarding data privacy and transparency.
As of May 2026, NHS England acknowledged that Palantir staff have been granted a new 'admin' role within the National Data Integration Tenant (NDIT), enabling access to identifiable patient data. This contradicts earlier assurances given to the National Data Guardian for Health and Social Care, Dr. Nicola Byrne, who was told that only NHS staff with a 'legitimate need' would have such access.
Dr. Byrne has initiated an investigation into this external contractor access, emphasizing the importance of clear, accurate, and consistent communication regarding data access policies. She stated, "We need to be confident that the positions presented to us are accurate, consistent, and clearly reflected in public-facing transparency materials."
The development has alarmed privacy advocates and lawmakers alike. Martin Wrigley, a Liberal Democrat member of the Commons technology select committee, criticized the oversight, stating, "This somewhat cavalier attitude to data security demonstrated how this whole project does not have security by design at its heart. The public will be rightfully concerned that data privacy is not the first concern."
Amnesty International UK has also condemned Palantir's involvement, highlighting the company’s controversial background and calling for the UK government to terminate its contract. Their statement underscored concerns over human rights, arguing Palantir "has no business anywhere near patient data." Tom Hegarty, Head of Communications at Foxglove, echoed these sentiments, saying, "NHS patients never consented to have their data accessed by a company like Palantir whose record is in targeting people, not caring for them... The government should... cut Palantir out of our NHS once and for all."
Further compounding the issue, the UK's statistical regulator has pressured NHS England to ensure any public claims about the FDP’s effectiveness are communicated with appropriate caveats, underscoring the need for transparency and accuracy in public reporting.
The controversy highlights urgent questions around vendor transparency, patient consent, and legal compliance in managing sensitive health data within the NHS ecosystem.
By the numbers:
- £330 million — value of Palantir’s contract for the NHS Federated Data Platform
- 2023 — year Palantir was awarded the FDP contract
- May 2026 — when NHS England confirmed Palantir staff’s admin access to patient data
What's next: Dr. Nicola Byrne’s ongoing investigation will likely influence future governance and access policies for contractor data handling within NHS England.