NHSE's DPIA failed to show FDP supplier access, NDG warns against loss of trust

Published: 28/07/2026
| UK Government

National Data Guardian (NDG) Dr Nicola Byrne has issued an update to her statement on 3 June concerning reports that external contractors are accessing identifiable patient information within the National Data Integration Tenant (NDIT), a secure environment inside the NHS Federated Data Platform (FDP) provided by Palantir. The update follows requests for clarification after NHS England (NHSE) acknowledged discrepancies between operational reality and its public communications.

NHSE confirmed that certain external supplier staff supporting the platform can access identifiable patient data for specific technical purposes under its direct instruction. It admitted that its original data protection impact assessment (DPIA) failed to accurately reflect these operational arrangements, acknowledged the error, and apologised. While NHSE maintains that contractor access is technically necessary, the NDG noted it cannot independently verify that assessment.

Dr Byrne highlighted that the incident demonstrates how rapidly trust erodes when transparency is compromised. While continuing to support the ambition of improving NHS data infrastructure to enhance patient care, the NDG stressed that data projects must be approached as trust initiatives rather than purely technical ones. Dr Byrne went on to clarify that the NDG will continue in its independent advisory role to ensure public and professional confidence is upheld. 


Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.

Read Full Story

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.