The Data Protection Impact Assessment for NHS England's £330M (~$420M) Palantir built Federated Data Platform inaccurately described who could view identifiable records, breaching the UK Caldicott Principles governing patient confidentiality (the
The UK's National Data Guardian has formally censured NHS England over its Data Protection Impact Assessment (DPIA) for the £330 million (about $420 million) Palantir-built Federated Data Platform, saying the document inaccurately described who could view identifiable patient records (The Register).
Dr Nicola Byrne, the independent statutory officer who oversees the Caldicott Principles governing patient confidentiality, said the DPIA failed to disclose that Palantir staff can view identifiable data inside the platform's National Data Integration Tenant for specific technical purposes. NHS England first confirmed that access regime in May 2026, months after the original DPIA was published.
In her 28 July statement, Byrne warned the discrepancy shows how quickly public confidence erodes when the Caldicott "no surprises" rule is not upheld. She also said her office cannot independently verify NHS England's claim that the supplier's access is "technically necessary."
NHS England acknowledged the error and committed to implementing the NDG's recommendations in full, including working with the Information Commissioner's Office.
Sam Smith, coordinator at patient-data group medConfidential, called the issue a culture problem rather than a typo, alleging a "culture of fear" around the platform. Palantir was awarded the contract in 2023, after earlier £60 million (about $76 million) in COVID-era deals without competition.