Summary
- NHS England has acknowledged that an FDP-related DPIA inaccurately described supplier access to identifiable patient data.
- Three Palantir engineers have administrative-level access to the National Data Integration Tenant for technical support.
- The National Data Guardian says the programme must be treated as a trust project, not simply a technical one.
NHS England has acknowledged that a data protection document for part of the Federated Data Platform inaccurately described supplier access to identifiable patient information, renewing scrutiny of one of the health service’s most sensitive digital programmes.
The issue concerns the National Data Integration Tenant, a component of the NHS FDP used to collect, organise, and prepare data, including some identifiable datasets. NHS England said the published Data Protection Impact Assessment referred to only NHS England staff having access to directly identifiable patient data within NDIT, when some suppliers working for NHS England also have controlled access.
“We recognise that the DPIA contained an error in how it described supplier access to data so we are correcting that error, and we apologise for any confusion this has caused,” NHS England said.
The organisation said three engineers working for Palantir provide technical support services and currently have administrative-level access to NDIT. Their role includes back-office support, platform-wide settings, platform security, and configuration. A further 33 engineers from a range of suppliers had more limited project-specific access as of 15 June 2026.
NHS England says supplier access is time-limited, role-based, purpose-specific, governed by contract and data protection law, subject to security clearance, monitored, audited, and reviewed. It also says patient data is not routinely accessed, although engineers operating under NHS England’s instruction could access identifiable and de-identified patient data for specific technical support.
The National Data Guardian said NHS England’s response confirmed that some external supplier staff can access identifiable patient information for specific technical purposes, under NHS England’s direction. It also noted that, as an independent body not involved in operating the platform, it could not independently verify whether that access is technically necessary.
The corrected document matters because the FDP has always carried a public trust burden. The platform is intended to support operational services across the NHS, including virtual wards, cancer waiting times, planning, and joined-up care. Those benefits depend on large-scale data movement, supplier systems, and operational access models that must be explained with precision.
Dr Nicola Byrne’s office was blunt about the programme’s foundations. “At its core, our advice will continue to be grounded in a central lesson from the history of NHS data and technology programmes: for any data project to succeed and deliver value, both through improved care and a more sustainable NHS, it must first and foremost be recognised and approached as a ‘trust project’, not simply a technical one.”
That sentence captures the problem NHS England now has to manage. Access controls may be in place, and supplier support may be operationally necessary, but confidence weakens when formal documents do not match the real system. Public sector technology programmes cannot rely on technical governance alone; documentation, accountability, and plain explanations are part of the infrastructure.




