Government news, all in one place

National Data Guardian statement on NHS Federated Data Platform data access, in response to the Not With My NHS Data campaign

Tuesday, 28 July 2026
09:39
press_release
National Data Guardian statement on NHS Federated Data Platform data access, in response to the Not With My NHS Data campaign
Response to concerns from the Not With My NHS Data campaign about access to patient data by external contractors in the NHS Federated Data Platform National Data Integration Tenant.

Many members of the public have contacted the Office of the National Data Guardian (NDG) through the Not With My NHS Data campaign to raise their concerns about external contractors having access to identifiable patient information in the NHS Federated Data Platform (NHS FDP) and its associated National Data Integration Tenant (NDIT).

Public trust is essential to the use of health and care data, and it is right that people ask questions about how their information is used. Whilst we welcome this engagement, we are not able to engage with each enquiry individually due to the volume of correspondence received. We hope, however, that this statement provides a clear response to the main concerns we understand people are raising.

The National Data Guardian’s role

To explain our role, the National Data Guardian is an independent statutory office holder, established to provide advice and challenge to the health and care system in England on how health and adult social care data is used. We want to ensure that all data use is safe and appropriate, so that health and care professionals and the public can trust how data is being handled and used. We are not a regulator and do not have investigatory or enforcement powers. You can find more about what we do on our website.

Our involvement with the NHS FDP programme

Since the early stages of the NHS FDP programme, we have provided ongoing advice to the Department of Health and Social Care (DHSC) and NHS England (NHSE).

Ahead of the platform’s procurement, the NDG, Dr Nicola Byrne, wrote a blog clearly setting out the key considerations she regards as fundamental to securing public trust.

Our subsequent involvement has primarily been through participation in three independent advisory groups, where our advice is always underpinned by the Caldicott Principles, including the need to ensure data access is on a strict need-to-know basis, and that patients must be kept appropriately informed about how their data is used.

The minutes of these meetings are published by NHSE here:

It has been our experience that points of concern or challenge that we have raised with the programme have been taken seriously, and we have found a clear commitment amongst individuals within NHS England to using data responsibly, with the aim of both improving patient care and strengthening the sustainability of the NHS.

Concerns about external contractors having access to identifiable patient information

In providing advice on the programme’s information governance, we, alongside the Information Commissioner’s Office, reviewed the programme’s Data Protection Impact Assessment (DPIA). A DPIA sets out how data will be used, who can access it, and the safeguards in place to protect it. It is also used to identify and assess privacy risks and ensure appropriate controls are in place, particularly where sensitive data is involved.

The DPIA we reviewed stated that access to identifiable patient information would be limited to NHS staff with a legitimate need. However, since then, recent media reporting, and subsequent confirmation from the programme team, indicate that some external contractor staff also have access to identifiable patient information within the National Data Integration Tenant (NDIT) environment. We were not aware of this. We have therefore written to the programme to seek clarification on this inconsistency.

We need to be confident that the positions presented to us are accurate, consistent, and clearly reflected in public-facing transparency materials. We have also emphasised the need for timely engagement with the NDG whenever significant programme decisions change in ways that may affect public trust, as in this case.

Next steps

  • We will await assurance from NHS England that the inconsistency identified has been clearly explained and that any necessary changes to transparency documentation and public communications have been made
  • We will continue to scrutinise, advise and challenge the NHS FDP programme through the relevant independent advisory groups
  • We will update this page once NHS England has responded to our request for further information

We are grateful to everyone who has written to us. Addressing these concerns is essential, as public and professional trust is fundamental to delivering the ambition of better joined-up data to improve care and deliver value for the NHS.

Update to NDG statement 28 July 2026

On 3 June 2026, following our request for clarification about contractor access to patient data in the NDIT, we said we would update this statement once NHS England had clearly explained the discrepancy and confirmed that any necessary changes to documentation and public communications would be made.

NHS England has now published a response addressing these matters:

Response to the National Data Guardian’s request for clarification around the Data Protection Impact Assessment for the National Data Integration Tenant which is part of the NHS Federated Data Platform

It confirms that some external supplier staff supporting the platform can access identifiable patient information for specific technical purposes, under its direction. NHS England states that this access is technically necessary. As an independent body not involved in the platform’s operation we are not in a position to independently verify that assessment.

NHS England has also acknowledged that the original data protection impact assessment that we reviewed did not accurately reflect the operational arrangements in place. It has accepted that this was an error, for which it has apologised, and committed to correcting it.

Public trust and confidence

There has been much interest in this statement. The intensity of interest and strength of public feeling on this issue appear to reflect not only how deeply many people care about the use of their data, and its confidentiality, but also continuing concern amongst some about Palantir’s role in the NHS. This topic has always been to some extent political. As such, people have a range of views. And public, professional and media scrutiny has only increased over time. This means that accuracy and transparency must remain central priorities for the NHS FDP programme. This incident has shown how quickly confidence erodes if the “no surprises” principle (Caldicott Principle 8) is not upheld when it comes to who can access people’s data, and why.

NDG’s continued involvement in the programme

We continue to strongly support the programme’s ambition. Improving data infrastructure to provide staff with better tools to access, use and act on information has the potential to improve the quality, safety and coordination of patient care, and, ultimately, the sustainability of the NHS. This aligns closely with one of our strategic objectives, namely, to support the use of data for public benefit. We do not want to see that opportunity missed.

We will therefore continue to engage with the programme in our independent advisory role, providing advice on its documentation, transparency materials and other outputs where appropriate, as well as on the programme more broadly, including through our participation in the relevant independent advisory groups. We will continue to provide challenge where necessary, and advocate for practices that build and maintain public and professional trust in support of the shared ambition to use data more effectively to improve care.

At its core, our advice will continue to be grounded in a central lesson from the history of NHS data and technology programmes: for any data project to succeed and deliver value, both through improved care and a more sustainable NHS, it must first and foremost be recognised and approached as a ‘trust project’, not simply a technical one. The technology matters, but experience has shown that public confidence, transparency and accountability are what determine whether a programme ultimately succeeds.

A note on our previous statement for transparency

We removed the section discussing the National Data Opt-out and its relationship to the NHS FDP more broadly. Having reviewed the statement, we concluded that this discussion was outside the scope of the specific issue being addressed, namely contractor access to the NDIT, and may have caused confusion. The statement has therefore been revised to focus solely on the matter under consideration.

Share this article: Twitter Email

Share This


Enjoyed this? Why not share it with others if you've found it useful by using one of the tools below: