In October 2024 the Secretary of State for Health announced the Single Patient Record would be owned by the patient and shared across the system. The framing was written into the NHS 10 Year Health Plan in July 2025. Eight months later, internal NHS England committee minutes obtained under Freedom of Information confirmed the patient is not the data controller, and is not going to be. The same department is publishing both sentences, and they describe two different worlds.
For any board chair or non-executive sitting near a health, social care, or commercial NHS supplier seat, this is the gap to read. Not the press releases. The minutes.
The legal architecture is doing the work, not the messaging
Under UK GDPR, the data controller determines the purposes and means of processing. The controller carries the accountability. The controller is the entity the Information Commissioner writes to when something goes wrong. NHS England, soon to be absorbed into the Department of Health and Social Care, has taken the data controller role for the Single Patient Record. Palantir, as the Federated Data Platform technology supplier, is formally a data processor.
The minutes acknowledge in plain English the awkwardness of this. Patients would expect to own their records. How this is to be achieved requires further thought. The phrase is doing an enormous amount of work for a governance regime which has already made its decision. The patient is not the controller. The wording around ownership is, in legal terms, presentational.
This is not a Palantir story. The same architecture would apply to any supplier in the same role. The point sits higher up the stack. The narrative being told to the public and the governance regime being built behind it are not the same artefact.
Last week made the gap concrete
NHS England has now granted Palantir and other external contractor staff new admin roles on the Federated Data Platform, with broad access to identifiable patient data inside the National Data Integration Tenant. The previous case-by-case Controlled Data Access approval process has been set aside for this category of user. The minister responsible at the time told MPs the NHS retains full control as data controller over how data is used and who has access. The statement is accurate within UK GDPR. It also tells you what the patient role in the decision is, which is none.
This is not the first warning. In March 2024 NHS England received King's Counsel advice on the FDP's privacy-enhancing technology, finding it lacked a lawful basis to process personal confidential data and concluding all patients would have to be offered an opt-out under section 251 of the National Health Service Act 2006 absent a solution. No new direction was sought from Parliament. No public explanation was given. Eighteen months later, the access regime has been expanded rather than the legal foundation rebuilt.
The relevant test for a board is not whether the supplier behaved properly. The supplier operates within the regime the controller specifies. The test is whether the controller acted in line with the messaging the same department put into a national plan ten months ago. The honest answer is no. The decision did not require patient notification, patient consent, or any opt-in window.
What the patient holds today, and what would change if the rhetoric were real
What patients have today is the National Data Opt-Out, introduced in 2018, which the government has decided does not apply to the most sensitive stage of FDP processing. The petition response triggered by 28,000 signatories says the opt-out does not apply to the National Data Integration Tenant because NHS England is legally required, under a direction from the Secretary of State, to process the data to create national insights and dashboards. The legal authority cited on NHS England's own NDIT privacy notice is section 254 of the Health and Social Care Act 2012. The published scope of the directions issued under it covers de-identified data. The NDIT processes data while it is still identifiable. Conservative MP Julian Smith raised the point in the 16 April Westminster Hall debate. The relevant direction has not been published, named, or scrutinised.
If the patient were the lead data controller in any meaningful sense, you would expect three things. Patients would specify which downstream processors are permitted, by name. Patients would withdraw consent from a named processor without losing access to care. Access expansions of the kind granted last week would require patient notification with a defined opt-out window before they took effect. None of these are present. The architecture is not built to deliver what the rhetoric promises, and there is no evidence of an intent to rebuild it.
Why this is a board question, not a clinical one
For the typical reader of this piece, the relevant question is not whether the FDP is the right platform, or whether Palantir is the right supplier. Both are downstream of the controllership decision. The relevant question is whether your organisation, your trust, your investee, your client, or your appointing committee is taking the patient ownership messaging at face value while sitting alongside a governance regime built on a different premise.
Three concrete implications. The first is reputational. The Good Law Project Say No to Palantir campaign has 50,000 patients writing to local trust boards. The British Medical Association voted at its June 2025 Annual Representative Meeting to oppose the rollout, and in February 2026 went further, advising members to limit non-clinical use of the FDP. The gap between the messaging and the governance is being mapped in public by organised parties. Boards relying on the public narrative will find themselves accountable for the governance reality with no time to adjust the position.
The second is contractual, and it cuts both ways. Suppliers in this ecosystem are working under data sharing agreements where the controller obligations sit with NHS England. If the controllership question becomes contested in court or in regulatory action, those agreements will be rewritten in haste. Anyone with a current commercial position predicated on the existing arrangement should understand the position is not stable. At the same time, NHS England has commissioned Imperial College Projects to evaluate the FDP under a £700,000, three-year contract running to 2029. You do not commission a three-year evaluation of a system you are planning to dismantle. The system is being treated as permanent infrastructure while the underlying governance question is unresolved.
The third is the one I will sit with longest. Public sector AI procurement is being conducted on a story about patient empowerment which the procuring organisation has, in its own minutes, declined to underwrite. The same story is being repeated in board papers, in supplier pitches, and in commissioning decisions across the system. The story is not the contract. The contract is the controllership. Boards which understand the difference will read the next twelve months in a different light from boards which do not.
The Single Patient Record will be a significant artefact in NHS history. It is being built on a governance arrangement in plain tension with how it is being described in public. The documents to read are the minutes, not the announcements.