44,000 Challenge NHS Use Of Their Health Records
More than 44,000 people have filed legal objections asking NHS England to stop its Federated Data Platform handling their health records, turning concerns about supplier Palantir into a test of patient rights, public trust and accountability.
What Are Patients Objecting To?
The objections, coordinated by not-for-profit campaign organisation 38 Degrees, ask NHS England to stop sharing, storing or using the individuals’ personal information through the platform. Participants have also requested restrictions on processing while their objections are considered.
Their concerns centre on Palantir, the US data software company (co-founded by Peter Thiel) leading the consortium supplying the system. Campaigners oppose its involvement because of its work with the Israeli military and US immigration enforcement, arguing that those relationships undermine confidence in the handling of confidential NHS information.
These objections reflect concerns about the NHS’s choice of supplier and whether patients can trust it with their information, but don’t show that their records have been shared with those organisations.
What Does The Platform Do?
The Federated Data Platform, or FDP, brings together information held in separate NHS systems so staff can coordinate work such as scheduling operations, managing waiting lists and arranging hospital discharges.
For example, knowing that a patient is ready to leave hospital is more useful when staff can also see whether the necessary follow-up arrangements are in place. Connecting that information could reduce delays without requiring teams to repeatedly telephone colleagues or reconcile separate spreadsheets.
The platform has national and local versions, with participating NHS organisations responsible for the data they process. NHS England says suppliers act under NHS instructions and cannot use the information for their own purposes, including developing their own AI models. Its published contract explanation also requires data to be stored, processed and accessed within the UK.
Can Patients Have Their Data Removed?
The campaign to stop the Federated Data Platform from handling UK health records relies on Article 21 of the UK General Data Protection Regulation, which allows people to object to certain uses of their personal information, including processing based on public tasks or legitimate interests.
However, this isn’t an unconditional right to withdraw information from any system. To do so, individuals need to explain reasons relating to their particular circumstances, and an organisation can even continue processing if it demonstrates compelling legitimate grounds overriding their interests, rights and freedoms.
The Information Commissioner’s Office (ICO) says organisations must normally respond within one calendar month and explain any refusal, including how the individual can complain. A related right allows people to request restrictions while the organisation considers whether its grounds override their objection.
Submitting an objection means the NHS must consider the request, but it doesn’t mean the person’s data has already been excluded from the platform.
What Does The Campaign Expect?
38 Degrees acknowledges that the action may not secure the result participants request, stating in its published guidance, “We actually think it’s more likely that they will reject it!”
The organisation also says that even rejected requests would help show the strength of opposition to Palantir’s involvement. However, its campaign only targets NHS England’s national version of the platform, so even if a request is accepted, local NHS organisations could still use the person’s information in their own versions.
Patients who also want to limit the use of their confidential health information for purposes beyond their own care, such as research and planning, would need to consider the separate National Data Opt-Out. Taking part in the campaign doesn’t register that choice.
Why Is The Timing Important?
The objections add pressure ahead of a 2027 break point in the contract, awarded in November 2023 with provision for up to £330 million of investment over seven years. Two parliamentary committees have urged the government to seek an alternative.
The dispute also concerns whether the platform delivers enough value to justify its cost. Although participating NHS trusts have reported improvements, NHS England acknowledges that its figures don’t show how much was due to the platform and how much may have resulted from other changes.
That leaves ministers assessing performance and transition costs as well as public confidence, with benefits needing stronger support than an improvement observed after software was introduced.
What Does This Mean For Your Business?
For businesses handling sensitive information, the story shows why choosing a technology supplier involves more than checking security features and contractual terms. Customers may also question the supplier’s wider activities and whether they feel comfortable with its involvement. Explaining who controls information, who can access it and what uses are prohibited should form part of introducing a service, rather than becoming an urgent exercise after objections arrive.
Organisations also need a workable process for recognising and responding to data protection requests. Staff should know where to direct an objection, while those responsible need enough information about their systems and suppliers to assess it properly. Promising privacy rights means little if the business cannot identify where someone’s data is held or implement an appropriate restriction.
The wider lesson here is that legal compliance and public confidence need continuing attention. A system may offer useful operational improvements while still facing reasonable questions about evidence, oversight and supplier choice. Businesses will be better placed if they can demonstrate benefits, explain decisions clearly and retain credible alternatives when a technology relationship no longer meets their needs.



