Sana Ali is a GP Registrar in North London, and Academic Clinical Fellow at University College London
Patient confidentiality is hardwired into all doctors as a fundamental ethical value at medical school. As we become GPs, this once exam-topic-exercise transforms into a genuine desire to protect our patients and their information. We hear people when they are at their most vulnerable, and they trust us with their most intimate stories. These are stories that we capture and translate into medical records in order to provide the best care possible. For most of us, data stewardship has meant recording patients’ information faithfully, sharing nothing without consent, and trusting that the legal and technical frameworks around NHS data would do the rest. However, a series of significant changes in the way NHS data is governed could make us question whether that trust is still warranted: an increasing reliance on foreign technologies over which UK law has limited reach, and a proposed shift in control over patient records from clinicians to politicians.
Who currently controls patient data in GP practices?
Under current UK law, each individual GP practice is the data controller for the records it holds on its registered patients. GP Partners decide how and what data is shared, and bear ultimate legal accountability. Where they agree to share data with ICBs or other organisations, they set the terms of this through Data Sharing Agreements (DSAs). Data processors — IT suppliers, cloud providers, analytics platforms — handle the data on the practice’s behalf, and are legally obliged to act only under the controller’s instructions. Understanding this framework matters, because it is precisely this chain of accountability that is now under pressure.
Reliance on foreign technologies: a threat to digital and data sovereignty
In the UK, there is increasing dependence on foreign technologies that serve as our data processors. Over 2 million NHS staff email inboxes run on Microsoft, with the NHS directory synced to Microsoft’s Azure cloud platform.1 EMIS, the clinical records system used by the majority of NHS GP practices, has recently been acquired by TPG, a US private equity firm.2
These companies are subject to the legal frameworks of the countries in which they are based, irrespective of the location of the servers that store the data. Under the US CLOUD Act, US-based companies can be required to provide data to US authorities even if that data is stored in the UK.3 Several other countries have similar legislation. In other words: NHS data stored in a UK data centre run by foreign companies is not fully under UK legal protection.
When the US imposed sanctions on the International Criminal Court in 2025, the ICC prosecutor lost access to his Microsoft email account overnight…
The risks are not only legal. When the US imposed sanctions on the International Criminal Court (ICC) in 2025, the ICC prosecutor lost access to his Microsoft email account overnight4 – a reminder that foreign technology dependency can become a vulnerability when political priorities shift. The cross-party Parliamentary committee on Science, Innovation and Technology, warned in June that the UK would be “at the mercy” of foreign actors “that do not share our strategic interests” and called for in-house replacements or alternative UK-based providers.5
The Federated Data Platform: sovereignty under pressure
In 2023, NHS England awarded Palantir Technologies a contract for £330million to build and run the Federated Data Platform (FDP) – software connecting data held separately across NHS Trusts and ICBs for planning and operational purposes.6 This partnership with NHS England has been criticised by the BMA, Amnesty International, and the Science and Technology Select Committee.5
Palantir Technologies, originally part-funded by the venture capital arm of the US Central Intelligence Agency,7 is a US tech giant used widely by government agencies for surveillance, intelligence and military purposes. Its founders have been candid about their worldviews: one has described the NHS as making people sick,8 and another has stated the company “is here to disrupt… and when it’s necessary, scare our enemies and, on occasion, kill them.”9 In the US, Palantir has helped the immigration enforcement agency, ICE, identify and detain those it deems illegal immigrants through an app pulling in the healthcare data of millions of Americans.10 It has also supplied technology to the Israeli military — a partnership that contributed to a 2025 UN special rapporteur report accusing Palantir, amongst several other companies, of having “…profited…from genocide”.11
As a US company, Palantir is subject to the CLOUD Act — meaning US authorities could compel access to NHS data it holds. Beyond the legal framework, the ICC case illustrates the practical risks of losing critical infrastructure when political priorities change abroad. Palantir’s own statements compound this concern in terms of politics at home. The Observer reported that Louis Mosley, head of Palantir UK said that if a future Reform UK government had a “clear public mandate” to share health data for mass deportation, the company would comply.9 The sovereignty risks are made significantly easier to exploit by the interoperability of Palantir’s platforms. Drag and drop’ between their health and defence systems is technically straightforward — something MP Martin Wrigley described as ‘profoundly worrying’ during the Science Committee’s meeting.12
Such risks are compounded by a governance framework that provides insufficient protection. The NHS’s own FAQs acknowledge that including immigration data could be a future possibility, subject only to an internal governance assessment.13 And where firmer protections exist, they have not always held. NHS England stated that GP data would not be part of the national platform, and would only be shared on the local FDP if agreed by GP practices through DSAs.6 However, according to health justice charity Medact, analysts at some ICBs say they are being instructed to load GP data onto local FDP instances without practices’ explicit consent, exploiting vague wording in existing agreements.14 In one documented case, Matthew Swindells — former deputy chief executive of NHS England, and at the time joint chair of four major North West London NHS Trusts — urged colleagues to add GP data onto the FDP while simultaneously being paid to advise Palantir.15 If existing protections can be circumvented in this way, the case for stronger democratic oversight of how NHS data is governed becomes harder to ignore.
The Single Patient Record: shifting data stewardship from clinicians to politicians
As well as increasing dependence on foreign data processors, new legislation is proposing a fundamental change in who controls patient data within the UK.
In May 2026, the Health Bill proposed the development of the Single Patient Record (SPR). Unlike the FDP, which is a back-end operational tool connecting data for service planning and resource allocation, the SPR would give both clinicians and patients a single view of a patient’s complete health history, including GP records, hospital notes, mental health and social care information.16 Unifying records for direct care can be invaluable — we all remember that midnight scramble in A&E trying to piece together a patient’s history from incomplete notes. However, the SPR comes with significant governance changes. GPs and NHS Trusts will retain controllership over patient data in their own systems, but will be required to share this onto the SPR,16 at which point the Department of Health and Social Care and the Health Secretary (personally) become the data controllers.17 For GPs, this means identifiable records created in confidence— including mental health history, sexual health, safeguarding concerns — will flow into a record controlled by a politician rather than a clinician. Not complying could result in financial penalties, which in their written evidence to the Public Bill Committee, the BMA warned could put GPs “in the difficult position of balancing their professional obligations to safeguard patient confidentiality against statutory requirements to share data.”18
Unifying records for direct care can be invaluable — we all remember that midnight scramble in A&E trying to piece together a patient’s history from incomplete notes.
This tension is heightened by another provision in the Health Bill. Clause 47 removes the common law duty of confidentiality for data shared through the SPR.17 By contrast with UK GDPR, the common law duty of confidentiality gives healthcare data a special status reflecting the sensitivity of of information that patients share in healthcare settings. The government’s explanatory notes state this is limited to, “circumstances involving direct care,” but the BMA argues this limitation “only exists within the explanatory notes, which do not have legal force”.18
Equally concerning is the concentration of power. Data is increasingly valuable — both commercially and politically. Unlike a GP practice or NHS Trust, the Health Secretary is a political appointee who changes with elections and reshuffles. Centralising controllership at that level — over the combined primary and secondary care records of every person in England — places an extraordinary amount of power in a single set of hands. This includes the power to choose which company would run the SPR and to decide whether to take the advice of the Select Committee and develop a UK-run platform, or to once again outsource to a US company. When asked if Palantir could be given the SPR contract, then Health Secretary James Murray would not rule this out.19
Because the SPR is classified as direct care rather than secondary use, no existing opt-out mechanism applies to it. NHS England’s own FAQ acknowledges they are still “working through whether — and if so, how — a person can object” to having their data included — leaving patients with no guaranteed right to refuse.20 This would give the Health Secretary and DHSC absolute control over sharing data with anyone they deem appropriate, as long as it is “a proportionate means of achieving a legitimate aim.”21
These governance concerns are reflected in public attitudes. The Health Foundation found that 68% of the public trust GP practices with their data, 61% trust national NHS organisations, and only 33% trust national government.22 The SPR, as currently proposed, would transfer control to the least trusted of these three.
What we, as GPs, can do
Patients disclose personal and sensitive information to GPs because they trust us to protect it. Historically, we have been able to honour that belief without thinking too hard about data governance and infrastructure. That is no longer enough.
The changes described in this article are happening now, in legislation currently passing through Parliament, in contracts already signed, and in decisions being made about platforms not yet built.
The changes described in this article are happening now, in legislation currently passing through Parliament, in contracts already signed, and in decisions being made about platforms not yet built. Most GPs know little about them, not through indifference, but because data governance is easy to deprioritise when the patient in front of us needs our attention. And yet it is precisely because of the patient in front of us that it matters.
There are things we can do. Understanding how our current and future DSAs work is the first step – reading them closely, querying unclear language, consulting our IG leads before signing, and asking for evidence they are being adhered to. A second step is engaging with consultations on the Health Bill, specifically over the SPR. NHS England is running engagement sessions with GPs this summer.20 Parliament is still scrutinising the Bill. The governance detail — opt-outs, access controls, platform provider — will be determined through secondary legislation not yet consulted on. These are not closed questions, and GP voices carry weight in answering them.
With respect to the FDP, practices can write to their ICBs to make clear that existing data sharing agreements do not extend to the FDP or its associated products without explicit consent. ICBs themselves can be encouraged to follow Greater Manchester’s lead and formally decline adoption of the FDP, thereby adding to collective pressure on a contract whose future is not yet settled.
Data sovereignty and control is not just a technical concern we can afford to leave to information governance leads, but also a clinical one. The trust that our patients place in us extends, whether they know it or not, to the infrastructure we use to hold their stories. We should have a working understanding of what that infrastructure is. We should know who our data infrastructure answers to, and whether it deserves the trust we are asking of our patients.
Deputy Editor’s note: see also https://bjgplife.com/confidentiality-privacy-and-general-practice-gpdpr-and-the-brave-new-world-of-big-data/
References
- Trotman A. NHS moves millions of mailboxes to Microsoft’s Azure cloud, giving staff access to the latest digital tools and services that support modern ways of working [Internet]. Microsoft UK News Centre; 2021 Feb 2 [cited 2026 Jul 16]. Available from: https://ukstories.microsoft.com/features/nhs-moves-millions-of-mailboxes-to-microsofts-azure-cloud-giving-staff-access-to-the-latest-digital-tools-and-services-that-support-modern-ways-of-working/
- Sollof J. GP IT supplier Optum acquired by US equity firm TPG [Internet]. Digital Health; 2026 May 11 [cited 2026 Jul 16]. Available from: https://www.digitalhealth.net/2026/05/gp-it-supplier-optum-acquired-by-us-equity-firm-tpg/
- Clarifying Lawful Overseas Use of Data Act (CLOUD Act). 18 U.S. Code § 2713 — Required preservation and disclosure of communications and records [Internet]. Cornell Law School Legal Information Institute; 2018 [cited 2026 Jul 16]. Available from: https://www.law.cornell.edu/uscode/text/18/2713
- Quell M. Trump’s sanctions on ICC’s chief prosecutor have halted tribunal’s work, officials and lawyers say [Internet]. Associated Press/PBS NewsHour; 2025 May 15 [cited 2026 Jul 16]. Available from: https://www.pbs.org/newshour/world/trumps-sanctions-on-iccs-chief-prosecutor-have-halted-tribunals-work-officials-and-lawyers-say
- Science, Innovation and Technology Committee. Rewiring the state: Delivering digital government. First Report of Session 2026-2027, HC 61 [Internet]. London: House of Commons; 2026 Jun 3 [cited 2026 Jun 30]. Available from: https://committees.parliament.uk/publications/53352/documents/298462/default/
- Tang M. Federated Data Platform update [Internet]. NHS England; 2023 Dec [cited 2026 Jun 27]. Available from: https://www.england.nhs.uk/long-read/federated-data-platform-update/
- Medact. Briefing: Concerns Regarding Palantir Technologies and NHS Data Systems [Internet]. London: Medact; 2026 Mar [cited 2026 Jun 24]. Available from: https://www.medact.org/2026/resources/briefings/briefing-palantir-fdp/
- Milmo D. Palantir’s Peter Thiel: NHS is a natural target for outspoken tech billionaire [Internet]. The Guardian; 2023 Nov 21 [cited 2026 Jun 27]. Available from: https://www.theguardian.com/technology/2023/nov/21/palantir-peter-thiel-nhs-natural-target-outspoken-tech-billionaire
- Sylvester R. Inside Palantir’s growing grip on UK public services [Internet]. The Observer; 2026 Mar [cited 2026 Jun 27]. Available from: https://observer.co.uk/news/national/article/how-tech-giant-palantir-was-recruited-by-the-police-nhs-and-military
- Taylor L. ICE and Palantir: US agents using health data to hunt “illegal immigrants”. BMJ. 2026 Jan 27;392:s168. doi:10.1136/bmj.s168. PubMed PMID: 41592818.
- Albanese F. From economy of occupation to economy of genocide. Report of the Special Rapporteur on the situation of human rights in the Palestinian territories occupied since 1967 [Internet]. Geneva: United Nations Human Rights Council; 2025 Jul 2 [cited 2026 Jun 30]. Report No.: A/HRC/59/23. Available from: https://docs.un.org/en/A/HRC/59/23
- Science, Innovation and Technology Committee. Oral evidence: Rewiring the State: Delivering Digital Government, HC 61 [Internet]. London: UK Parliament; 2025 Jul 8 [cited 2026 Jul 22]. Available from: https://committees.parliament.uk/oralevidence/16290/html/
- NHS England. Frequently asked questions (FAQs) — NHS Federated Data Platform [Internet]. NHS England; 2026 [cited 2026 Jun 30]. Available from: https://www.england.nhs.uk/digitaltechnology/nhs-federated-data-platform/fdp-faqs/
- Medact. Rapid Response: GP data and the Federated Data Platform in England [Internet]. London: Medact; 2026 May [cited 2026 Jun 24]. Available from: https://www.medact.org/2026/blogs/response-gp-data-fdp-palantir/
- Hughes L. NHS official pushed to add patient data to Palantir platform while also advising company. Financial Times. 2026 Mar 5.
- Armstrong S. Single patient record: Alarm raised over ministerial power grab of health data with potential fines for non-compliers. BMJ. 2026 May 21;393. doi:10.1136/bmj-2026-235862. PubMed PMID: 42167777.
- House of Commons. Health Bill — Explanatory Notes. HC Bill 009, Session 2026-27 [Internet]. London: The Stationery Office; 2026 May 14 [cited 2026 Jul 15]. Available from: https://publications.parliament.uk/pa/bills/cbill/59-02/0009/en/260009en.pdf
- British Medical Association. Written evidence submitted by the BMA to the Public Bill Committee on the Health Bill [Internet]. London: BMA; 2026 Jun [cited 2026 Jul 21]. Available from: https://bills.parliament.uk/publications/66820/documents/8457
- Iacobucci G. Single patient record: A&E impact claims are labelled “drop in the ocean” as Murray refuses to rule out Palantir involvement. BMJ. 2026 Jun 2;393. doi:10.1136/bmj-2026-020086. PubMed PMID: 42229973.
- NHS England. Single Patient Record — your health at your fingertips [Internet]. NHS England; 2026 [cited 2026 Jul 16]. Available from: https://www.england.nhs.uk/digitaltechnology/the-single-patient-record/
- Health Bill. HC Bill 009, Session 2026-27, Schedule 7, clause 11, s.261(2)(g) and (j) [Internet]. London: The Stationery Office; 2026 [cited 2026 Jul 22]. Available from: https://publications.parliament.uk/pa/bills/cbill/59-02/0131/260131.pdf
- Lawrence A. Four questions for the single patient record [Internet]. The Health Foundation; 2026 May 27 [cited 2026 Jun 24]. Available from: https://www.health.org.uk/features-and-opinion/blogs/four-questions-for-the-single-patient-record
Featured image: Photo by Kevin Ku on Unsplash