Tuesday, 18 August 2026 · Europe
EUR/USD 1.159 EUR/GBP 0.855 EUR/CHF 0.9389 EUR/PLN 4.306 All rates →
Sign in · Join
EUROPES The European Report
European Edition Tuesday, 18 August 2026
LATEST
Tech & Startups

NHS England admits concealing Palantir staff access to patient records

NHS England admits concealing Palantir staff access to patient records

NHS England has admitted a data protection document failed to disclose that Palantir staff can view identifiable patient records, intensifying European scrutiny over the US firm's public sector contracts.

NHS England has conceded that a key data protection document failed to disclose that staff at the US analytics firm Palantir can view identifiable patient records. The concession follows a formal inquiry from the National Data Guardian, the statutory office advising the health service on confidentiality.

The health service apologized for the omission in its Data Protection Impact Assessment. “We recognise that the DPIA contained an error in how it described supplier access to data, so we are correcting that error, and we apologise for any confusion this has caused,” the organization stated.

This access occurs within the National Data Integration Tenant of the new Federated Data Platform. NHS England maintains that Palantir personnel only reach this information for specific technical purposes and under direct health service supervision.

National Data Guardian Nicola Byrne expressed skepticism about taking these assurances on trust. “As an independent body not involved in the platform’s operation, we are not in a position to independently verify that assessment,” she noted in an updated statement.

The controversy centers on the Caldicott Principles, which have dictated patient confidentiality since the 1990s. Byrne warned that the documentation failure “has shown how quickly confidence erodes if the ‘no surprises’ principle is not upheld when it comes to who can access people’s data, and why.”

Campaigners argue the issue reflects deeper institutional problems rather than a simple clerical mistake. Sam Smith, coordinator at medConfidential, stated that “NHS England claims it was little more than a typo, but this is the result of punishing their expert staff away from speaking truth to leadership.”

Smith dismissed the official explanation and pointed to broader systemic issues within the organization. He described the situation as “another example of the culture of fear that NHS England has cultivated around the platform.”

This domestic dispute highlights a broader divergence in how European nations handle American tech giants in critical infrastructure. While France is replacing Palantir with domestic alternatives and both Paris and Berlin back a sovereign European solution, London continues to rely on the US contractor.

Palantir secured a £330m contract to build this specific platform in 2023, following £60m in pandemic-era awards granted without competitive bidding. The system is designed to integrate information across the health service and reduce treatment backlogs.

NHS England has pledged to implement the National Data Guardian’s recommendations completely. However, the incident leaves lingering questions about transparency as European governments increasingly debate data sovereignty and the role of foreign technology firms in public services.

More from Tech & Startups