NHS England has apologised after admitting authorised engineers from Palantir and other suppliers can access identifiable patient data in the Federated Data Platform's National Data Integration Tenant, contradicting an earlier DPIA claim that only NHS staff could do so. NHS England says access (three Palantir admins and 33 other supplier engineers) is time-limited, need-based and strictly for platform support, and suppliers are forbidden from using the data for their own purposes. The correction exposes a transparency gap in key documents and has renewed calls to consider a contract break clause due in February 2027.
NHS Apologises After Revealing Supplier Engineers (Including Palantir) Can Access Identifiable Patient Data via FDP

NHS England has apologised after confirming that authorised engineers from Palantir and other technology suppliers can access identifiable patient information within the Federated Data Platform's (FDP) National Data Integration Tenant. This admission contradicts an earlier statement in the programme's Data Protection Impact Assessment (DPIA), which said only NHS England employees could directly access identifiable data. NHS England says it did, however, correctly state on its website that supplier access could be granted on a limited, as-required basis.
The organisation says three Palantir engineers currently hold administrative-level access to the National Data Integration Tenant, while a further 33 engineers from various suppliers have more restricted, project-specific permissions. NHS England emphasises these privileges are granted only for operational need, are time-limited, and intended solely to support the development, maintenance and safe operation of the platform.
Governance and safeguards: NHS England has stressed supplier staff are prohibited from using identifiable patient information for their own purposes and that identifiable data is not accessed routinely. The department describes these controls as tightly governed and says the disclosure does not, on its own, indicate that patient data has been misused.
Transparency Gap
Critically, the DPIA — the NHS's primary transparency document for the FDP — did not accurately reflect the supplier access arrangements. While large, complex data platforms commonly require controlled supplier access for maintenance, troubleshooting and product development, accurate public-facing documentation is essential to maintain trust and accountability.
Wider Debate and Pressure
The revelation comes amid growing scrutiny of the public sector's reliance on a small number of multinational technology firms. Palantir's role in the FDP has attracted particular attention after officials re-qualified statistics that had been used to claim operational efficiency gains, concluding those figures were not causally linked to the platform.
Public pressure has renewed calls for NHS England to consider a contract break clause in the FDP deal that becomes available in February 2027. A related precedent exists: France's domestic intelligence service ended its relationship with Palantir in favour of a domestic alternative, citing concerns about "strategic dependency." Although that decision related to national security rather than healthcare, it illustrates how political and public scrutiny can influence supplier relationships.
What Needs To Change
Going forward, NHS England must ensure all FDP documentation — including DPIAs, transparency materials and supplier contracts — consistently reflects who can access identifiable data, under what conditions, and how responsibilities are divided between the NHS, Palantir and other delivery partners. For suppliers involved in national health infrastructure, the episode is a reminder that data protection assessments and public-facing transparency materials are as crucial as delivery milestones.
These corrective steps are administratively achievable, but implementation will occur in a constrained fiscal and political environment in which the NHS competes for attention and funding with defence, economic growth initiatives and other public services.
Originally published by Medical Device Network, a GlobalData brand.
Help us improve.

































