A statutory privacy document wrongly said only NHS staff could see identifiable patient data. The operator has now apologised and disclosed the supplier engineers with access.
The statutory document the law requires the NHS to publish, telling the public who can see their medical records, was wrong. NHS England has apologised and admitted that its own privacy assessment for the Federated Data Platform, the NHS's central patient data infrastructure, incorrectly stated only its own staff could access directly identifiable records.
In practice, three Palantir engineers currently hold administrative-level access to the platform's National Data Integration Tenant, the part of the FDP where identifiable records sit. Admin-level access means those engineers can see and manage directly identifiable data, including named patients, NHS numbers, and real medical histories, not just work on anonymised or aggregated material. A further 33 engineers from a range of suppliers hold more limited project-specific access for tasks assigned by NHS England, including writing code and assuring new products. None of this was reflected in the original Data Protection Impact Assessment.
The correction followed a letter from the National Data Guardian, Dr Nicola Byrne, the independent statutory adviser on data in health and adult social care, who was asked to clarify whether external contractor staff could see patient information. Her office treated the original assessment as a breach of the no-surprises principle: the public should not learn, after the fact, who has been able to see their records. NHS England's position is that the access is controlled, time-limited, based on operational need, and granted only with government security clearance and director-level sign-off. Patient data is not, NHS England says, routinely accessed by supplier engineers.
That description is not the one in the original DPIA, which is the legally required privacy assessment that public services handling sensitive personal data must publish. DPIAs are not press releases. They are the public's window onto how a system handles identifiable data, and they carry statutory weight. The error is procedural, not just presentational. The platform, as ministers have previously said, is intended to be more secure than the legacy systems it replaces. The DPIA was meant to make that security legible. It did not.
The correction changes the picture of who has been operating the platform while the public was being told otherwise. The 36 engineers are a snapshot, as NHS England says the number fluctuates, but the structural fact is the one that matters: a private US supplier has held admin-level access to a system containing the medical records of named patients, while the published transparency document said only the operator's own staff could see that data. Palantir won the £330 million (approximately $420 million at recent exchange rates) FDP contract in 2023, after earlier £60 million (approximately $76 million) COVID-era contracts awarded without competition.
The parliamentary backdrop makes the disclosure failure harder to dismiss. The Science, Innovation and Technology Committee has already named Palantir as the most concerning example of a US firm with a significant role in the UK public sector, and recommended that the company should not play such a role. The committee's position is political, not technical, and Dr Byrne herself frames the issue as political rather than purely operational.
The practical test the National Data Guardian applies is whether confidence in the system erodes when the public is told one thing and the document says another. Dr Byrne continues to support the FDP's ambition, but warned that confidence erodes quickly when the no-surprises principle is breached. The corrective step of revising the DPIA, and apologising is what the regime was designed to produce. NHS England describes the 36 engineers as the operating reality and has not committed to a different model. The next DPIA revision, when it lands, is the document to watch.