Home » UK » MPs Warn of ‘Dangerous’ NHS Data Access Granted to Palantir
A nurse on an emergency ward wearing dark blue scrubs stands looking at computer screens and taking notes.

MPs Warn of ‘Dangerous’ NHS Data Access Granted to Palantir

The decision by NHS England to grant the US tech company Palantir access to identifiable patient information has ignited fierce criticism from MPs and privacy advocates. Experts warn this move risks public trust and raises serious concerns about the safeguarding of sensitive health data amid efforts to deploy artificial intelligence (AI) to improve healthcare delivery.

A nurse on an emergency ward wearing dark blue scrubs stands looking at computer screens and taking notes.
NHS England said it had ‘strict policies in place for managing access to patient data’. Photograph: David Levene/The Guardian

What Happened: Palantir’s Controversial Data Access

In recent weeks, NHS England permitted Palantir staff and other contractors to access patient data before it was pseudonymised—meaning the data still contained identifiable personal information. This unprecedented access was revealed in an internal NHS briefing obtained by the Financial Times, which admitted the move could trigger a “risk of loss of public confidence.”

The briefing disclosed that Palantir would receive “unlimited access to non-NHSE staff” to parts of the NHS’s federated data platform (FDP)—a centralised system holding vast quantities of patient data. Palantir secured a £330 million contract to develop this platform, integrating fragmented health datasets and deploying AI to enhance treatment efficiency.

Palantir’s involvement has faced long-standing opposition. Campaigners and some MPs highlight the company’s controversial history, including its support for US immigration enforcement and military contracts, as incompatible with managing sensitive NHS data.

Rachael Maskell stands in front of a stone rampart at a castle in York. She wears a pale cream jacket and has long fair hair, tied back. The sky is blue behind her.
Rachael Maskell, the Labour MP for York Central, asked the government ‘to get a grip on this project before it is too late’. Photograph: Richard Saker/The Guardian

Why It Matters: Privacy Risks and Public Trust

The Patients Association voiced alarm that patients had not been consulted on this significant expansion of data access. CEO Rachel Power emphasized patients’ demand for “transparency, clear boundaries around access to their data, and to be consulted when changes to those agreements are proposed.”

Despite NHS England’s assurances that personal data would remain protected and within NHS control, the reality is complex. External contractors like Palantir engineers reportedly found the process of obtaining individual permissions to access datasets cumbersome, leading to broader access approvals. Although all access was logged and Palantir denied any unauthorized removal of data, critics argue these safeguards fall short of protecting patient privacy.

MP Rachael Maskell, a former NHS worker leading parliamentary opposition, condemned the development: “As Palantir get their claws deeper into our NHS data we can see how it is opening it up to greater private interest. This is a dangerous development and I ask the government to get a grip on this project before it is too late.”

Martin Wrigley, a Liberal Democrat member of the Commons technology select committee, criticized the NHS’s approach as “cavalier,” warning it showed a lack of “security by design.” He stressed that the public’s concern over data privacy is entirely justified.

Palantir’s Role and Wider Public Sector Expansion

Palantir insists it functions only as a “data processor,” not a “data controller,” meaning its software processes data strictly according to NHS instructions. The company asserts that “using the data for anything else would not only be illegal but technically impossible due to granular access controls overseen by the NHS.”

Nevertheless, Palantir’s expanding footprint across the UK public sector faces strong resistance. Recent reporting revealed the company is close to securing a contract with the Metropolitan Police to deploy AI in criminal intelligence analysis, a move opposed by many citizens and MPs.

Polling indicates over two-thirds of the UK public harbor concerns about Palantir’s increasing public contracts, with 40% distrusting the firm not to access NHS patient data improperly. Advocacy groups like Foxglove highlight Palantir’s troubling track record, arguing that NHS patients never consented to their data being handled by a company linked to surveillance and enforcement rather than healthcare.

NHS England’s Response and Safeguards

A spokesperson for NHS England clarified that access to identifiable patient data would be tightly controlled, limited to a small number of individuals working on the data platform, all holding government security clearances. The NHS employs strict policies and regularly audits data access to ensure compliance. Any external user must be approved at a senior director level or above.

While these measures offer some reassurance, the controversy underscores the tension between harnessing AI’s potential to improve healthcare and protecting patient privacy in an era of increasing data centralization.

Looking Ahead: Balancing Innovation with Privacy

The NHS’s ambitious plan to use AI for better healthcare outcomes depends on accessing vast amounts of data. However, the Palantir case highlights the urgent need for transparent governance, robust security frameworks, and meaningful patient engagement to maintain public trust.

As data-driven technology becomes central to modern health services, policymakers must navigate the fine line between innovation and privacy protection. The backlash against Palantir’s expanded data access serves as a cautionary tale: technological progress cannot come at the expense of patient confidentiality and public confidence.

For now, the government faces mounting pressure to reassess its relationship with Palantir and ensure that NHS data remains safeguarded by design—not just in policy statements.

Scroll to Top