Recent media coverage of the NHS Federated Data Platform often ends with a comforting footnote: there’s little chance Palantir could be forced to hand over patient data because the NHS remains the data controller and supplier staff are not allowed to browse records for secondary purposes.
This confuses two different legal systems.
UK GDPR processing rules govern accountability within the UK. They decide who is responsible for purpose, lawfulness and security. They don’t decide what a US court order can do. The US CLOUD Act does. It can compel any US-incorporated company to produce data in its possession, even when that data sits on servers outside the United States.
And data in its possession is data it can read. NHS England has confirmed that some Palantir staff can access identifiable patient data. A federal warrant served on Palantir Technologies Inc does not stop at a clause saying its engineers aren’t supposed to browse.
Palantir have access
A small number of Palantir staff have admin access to the National Data Integration Tenant, part of the Federated Data Platform. Others have more limited, project-specific access and can see identifiable patient data when providing technical support. NHS England has said the access is time-limited, purpose-specific and audited, and that patient data is not routinely viewed. Those controls matter. They do not erase the point: some Palantir staff can see identifiable data in clear text, and that creates CLOUD Act exposure.
Where company staff can access the data, the argument that the company has control for CLOUD Act purposes is real. Contractual permissions and UK processor status are important for UK compliance. They do not provide a shield against US legal process.
Any demand under the CLOUD Act would be fought, if at all, in a US court between Palantir and the US government. UK courts would not decide the validity of the warrant. Under the US–UK agreement there is a route to challenge disclosure and the UK government can be notified. That process still sits inside the US system.
One has to ask what a company that depends so heavily on US defence and federal contracts would actually do under pressure.
None of this proves that identifiable NHS records are being handed over, or that Palantir is rewriting code to exfiltrate data. The claim is narrower and more solid. Public reassurance that rests only on “the NHS is the controller” and “engineers must not browse” is incomplete. Once technical access is conceded, CLOUD Act exposure follows.
A UK contractual permission does not override a US subpoena.