A health-justice campaign has urged NHS organisations to reject the Federated Data Platform delivered by a Palantir-led consortium, warning that the system could make future cross-government use of health data easier. The warning is about capability and future policy change; it is not evidence that immigration authorities currently have access to the platform.

Palantir and NHS England reject the suggestion that the supplier can repurpose patient information. NHS England says the NHS remains in control of the data, while Palantir told the Guardian that using it in the way described by campaigners would be illegal and breach its contract.

The dispute is therefore not resolved by treating either future misuse or present safety as self-evident. It turns on what the platform contains, who controls each instance, how access is authorised and whether safeguards would withstand a change in law or government policy.

What the Federated Data Platform Does

The NHS awarded the contract in November 2023 to a consortium led by Palantir. NHS England values it at up to £330 million over seven years and says it covers as many as 240 NHS organisations. The initial commitment is three years, with options to extend.

The platform sits above existing systems and connects information used for direct care and service planning. NHS England lists waiting-list management, theatre scheduling, discharge coordination and referral validation among its current uses.

Identifiable information can be held within a trust's local instance for direct care. NHS England says each trust or integrated care board controls its own instance and decides who has access. Data used at integrated-care-board or national level for planning is described as de-identified or aggregated rather than a national collection of named patient records.

Medact's Warning Is About Future Repurposing

Medact's March 2026 briefing argues that Palantir's software is designed to connect and analyse multiple datasets and can interoperate with the company's other products. The charity says that technical capacity could make it easier for a current or future government to seek access for policing or immigration enforcement.

The report links that concern to Palantir's work for US Immigration and Customs Enforcement and to proposals in UK politics for wider data sharing between public bodies. It recommends that trusts and integrated care boards decline the platform and ask NHS England to terminate the contract.

At the time of the briefing, local adoption was not mandatory. Medact cited Greater Manchester's decision to defer adoption after the integrated care board concluded that its local capability was stronger and that the platform presented value-for-money and public-trust concerns.

Current Controls Do Not Support a Claim of Existing Enforcement Access

NHS England's FAQ, updated in April 2026, says neither immigration status nor residency status forms part of the platform's current products or its health-record data. It says any future proposal to add such information would have to pass information-governance and lawfulness assessments.

The NHS also says Palantir is a processor acting only on NHS instructions, not a data controller. The contract bars the company from commercialising NHS data, using it to train its own AI models or accessing and sharing it for its own purposes. Access is role-based, logged and auditable, and data is encrypted in transit and at rest.

Those controls directly contradict claims that Palantir already holds an unrestricted grip on a central database or that the platform now links health records to the Home Office. They do not make future misuse impossible. Laws can change, authorised purposes can expand and governance can fail, which is why the quality and visibility of oversight matter.

Public Trust Requires Testable Safeguards

The NHS should publish enough operational evidence to let patients and local boards test its assurances. That includes product-level privacy notices, data-protection impact assessments, categories of authorised users, audit findings, access violations, contract changes and exit tests showing that data and services can be migrated away from a supplier.

Campaigners should be equally precise about the status of their claims. A documented technical possibility, a proposed political policy and an existing data flow are different things. Conflating them can weaken a legitimate warning by presenting a feared scenario as a completed act.

The hard question is not whether one company can be trusted forever; no health-data system should depend on that promise. The question is whether purpose limits, local control, audit trails and legal barriers are strong enough to expose and stop misuse by any supplier or government. NHS England's current rules answer part of that test. Only continuing disclosure, independent scrutiny and enforceable limits can answer the rest.