Palantir: Contracts
The question
To ask the Secretary of State for Health and Social Care, what contractual restrictions apply to the movement or reuse of NHS patient data processed through Palantir; whether those contractual restrictions have been independently reviewed to assess their effectiveness; and what mechanisms are in place to monitor compliance with contractual safeguards.
Answered by Preet Kaur Gill
The NHS Federated Data Platform (NHS FDP) safely connects information from different systems across the National Health Service into a single, secure environment. This allows staff to co-ordinate care better to improve outcomes for patients.
The NHS FDP is delivering for the NHS, helping people get the care they need quicker and more efficiently. Since March 2024, more than 100,000 additional patients have been supported to undergo procedures in theatres partly by increasing theatre utilisation. Nearly 94,000 people have been supported on their cancer journey, with 7% seeing a reduction in the time it took to diagnose their cancer. There has been a 14% decrease in delays discharging patients staying in hospital for more than seven days, freeing up beds for those who need them most. NHS England publishes quarterly information on the benefits realised from the FDP, which is available at the following link:
As of the end of May 2026, 170 trusts have signed up for the NHS FDP, including the Mid Yorkshire Teaching NHS Trust.
The NHS FDP, built on the Foundry platform, is designed around open standards to ensure seamless interoperability across both code and data. Further information can be found at the following link:
https://www.palantir.com/docs/foundry/architecture-center/interoperability
From a technical standpoint, each Palantir Foundry tenant operates as a fully independent environment. Interoperability between separate tenants is intentionally disabled by default as part of the platform’s design.
No NHS FDP product makes use of a Gotham platform. There are no products that make use of interoperability between Palantir platforms used by different public bodies within the NHS FDP. The data in the NHS FDP can only be used for a health and care purpose and cannot be shared with another platform for any other use.
Information to support patients to understand how the software works and the ways in which it supports better care while protecting patient privacy is available at the following link:
https://www.patients-association.org.uk/News/patient-data-in-the-nhs
Under the contractual arrangements for the NHS FDP, Palantir Technologies UK Ltd acts as a data processor on behalf of NHS England, which is the data controller. Contractual restrictions on the movement and reuse of NHS patient data processed through the NHS FDP are set out in the Data Processing Agreements and associated Data Processing Annexes.
These agreements place strict limitations on processing, including that the processor cannot determine the purposes or means of processing and may only process data for the specific purposes agreed with NHS England. Processing outside of those agreed purposes, including any unauthorised movement or reuse of data, is not permitted under the contractual and data protection arrangements in place.
As with any data field, if there was a future request for a product to include this data it would be subject to NHS England Information Governance processes including a thorough assessment to ensure that the processing of this data was lawful.
Any sharing or transfer of data is subject to defined governance processes and must be explicitly authorised by NHS England, with an appropriate legal basis and supporting documentation where required.
Compliance with contractual safeguards is supported through a combination of technical and organisational controls, including role based and purpose-based access controls, audit logging, and monitoring of system access and activity. These are complemented by formal governance processes, including Data Protection Impact Assessments and oversight by relevant information governance bodies, to ensure that data is processed in line with legal and contractual requirements. The contractual and governance framework for the NHS FDP has been subject to appropriate internal and external scrutiny.
Together, these safeguards ensure that patient data processed within the NHS FDP cannot be transferred to other platforms or systems except where explicitly authorised by NHS England in line with the applicable legal and governance requirements.
Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →