NHS: Palantir

(asked on 16th June 2026) - View Source

Question to the Department of Health and Social Care:

To ask His Majesty's Government, further to the Written Answer by Baroness Merron on 16 June (HL696), whether the access of Palantir contractors to identifiable patient data was always part of the operational arrangements; and why the National Data Guardian was left unaware of this arrangement until it was exposed by external pressure.


Answered by
Baroness Merron Portrait
Baroness Merron
Parliamentary Under-Secretary (Department of Health and Social Care)
This question was answered on 6th July 2026

The National Data Guardian (NDG) highlighted that the published Data Protection Impact Assessment (DPIA) for the National Data Integration Tenant (NDIT) was not fully reflective of current access arrangements, including limited administrative access by supplier staff.

Access by supplier staff has been part of the operational model for the NHS Federated Data Platform (NHS FDP) where necessary to support, maintain and assure the system. This access is strictly controlled, limited, and subject to contractual, technical and organisational safeguards.

The DPIA did include information on supplier data processing obligations and considered the risks associated with access to data. However, it was not sufficiently explicit about the nature and extent of limited administrative access by supplier staff. NHS England recognised this and has taken steps to improve transparency in how these arrangements are described. NHS England has also set out in its public communications that suppliers act only under the instructions of National Health Service organisations.

Whilst there is no statutory requirement for NHS England to notify the NDG of specific access arrangements to NDIT, NHS England engages regularly with the NDG through established governance routes as part of routine oversight of the NHS FDP Programme. This matter was discussed at the Data Transformation Check and Challenge Group; the NDG subsequently wrote to NHS England and has received an update in response. NHS England has also published an updated Privacy Notice on the NHS website in an online-only format.

NHS England acts as the data controller for the NHS FDP at the national level, including NDIT. NHS organisations using the platform act as data controllers for their own data and use of the system. Access to data is strictly controlled; any access by external contractors is limited, role-based and time-bound, requires appropriate security clearance and senior approval, and is fully logged and auditable. Data remains under the control of NHS organisations, and suppliers act only under the instruction of those organisations.

NHS England and the Department will continue to engage with the NDG through established governance routes on this matter.

Reticulating Splines