More Than 44,000 People Object to NHS Data Use. What Are Your Rights?
IT Club — Powered by Altitude IT (opens in a new tab)

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
A reported campaign of more than 44,000 objections has raised questions about NHS health records, contractor access and data rights. This guide explains what is known, how consent differs from other legal grounds and what organisations should make clear in privacy notices.
The Guardian reported on 30 September 2026 that more than 44,000 people had lodged objections to NHS England processing their information through its Federated Data Platform (FDP). The campaign was coordinated by 38 Degrees and focused on the platform and Palantir’s role in supplying its technology.
That figure is a reported campaign count, not an independently audited NHS total. The objections are not a court case or a ruling that the NHS has acted unlawfully. They do, however, raise a practical question for anyone whose information is held by a large organisation: what is being used, by whom and on what grounds?
What is the NHS platform?
NHS England describes the FDP as technology that helps connect operational information—for example, information used to coordinate care and manage services. The platform does not make the NHS a single controller for every record or every purpose: NHS organisations remain responsible for the data they control and for deciding how it is used.
The access question is more specific than “Can a supplier see NHS data?” The National Data Guardian reported that an earlier impact assessment said only NHS staff would access information in the National Data Integration Tenant. NHS England later confirmed that external contractors can also access identifiable information for defined technical purposes. NHS England says this access is technically necessary and that suppliers cannot use the information for their own purposes. The National Data Guardian said it could not independently verify the technical-necessity claim.
That is different from saying every supplier employee can browse every patient record. It is also different from saying contractors never have access. A useful explanation should name the purpose, the access controls and the role of any supplier—and correct a privacy assessment when the real arrangement changes.
Consent is not the only legal basis
Health information is special-category personal data, so organisations generally need both a lawful basis under Article 6 of UK GDPR and a separate condition under Article 9. Consent is one possible route, but it is not the only one. Public authorities and healthcare providers may rely on other legal grounds where the law permits them and the required safeguards are met.
The exact basis depends on the controller and the purpose. A platform can support several activities, and the legal reasoning for one use should not be assumed to cover every other use. NHS England’s description of the FDP is not a substitute for checking the privacy information for the particular service or organisation handling a record.
Which rights can people use?
People can ask an organisation to explain its processing and may have rights to access information, correct inaccurate details, restrict certain processing or complain to the Information Commissioner’s Office. The right to object is conditional: it applies in specified circumstances, including some processing based on public task or legitimate interests. Where it applies, an organisation may still be able to continue if it can show sufficiently strong grounds. It is not a universal veto over every use of health data.
The NHS National Data Opt-Out is a separate service for deciding whether confidential patient information is used for healthcare research and planning where the policy applies. It should not be presented as the same thing as an Article 21 objection to a particular processing activity. If you are unsure, check the current NHS guidance and ask the relevant controller what purpose and legal basis it relies on.
What a clear privacy notice should say
The same principles apply to a clinic, charity, employer or small business. A notice that only says “we may share your data with trusted partners” leaves people guessing. Explain the real arrangement in plain English and keep the notice aligned with how staff and suppliers actually work.
- Who controls the information and how to contact them.
- The specific purposes, data types and legal basis; for sensitive information, the relevant additional condition.
- Which staff, processors or contractors may access it, for what tasks and under what safeguards.
- How long the information is kept and whether it is shared with other organisations.
- Which rights apply, how to exercise them and how to raise a concern.
For organisations, the practical lesson is not to promise “no third-party access” if a supplier’s support team can handle identifiable information. Map the access, check contracts and permissions, review the impact assessment when arrangements change, and answer objections through a documented process. ICO guidance on these rights is currently under review following legislative changes, so check the latest version before relying on it.
Sources and further reading
The Guardian: report on the 44,000 objections →
NHS England: Federated Data Platform overview →
Plain-English Takeaway
Holding personal information does not give an organisation permission to use it for any purpose. Identify the purpose, legal basis, special-category condition, access arrangements and rights that apply—and make the privacy notice match what happens in practice.
Related Articles
A Customer Has Asked for All Their Data — What Do You Do?
A customer asks what personal data you hold, says they never agreed to marketing and wants everything deleted. This practical UK guide explains what a small business should do first — without treating one email as one simple request.
Read articleAI Privacy Is Becoming a Competitive Advantage
The business AI question is changing from 'Can it do this?' to 'What happens to the data it needs?' This independent UK guide explains training defaults, retention, residency, connectors, account types, shadow AI and the controls that make useful adoption possible.
Read articleWhen Data Protection Training Fails: Lessons from the Metropolitan Police
The ICO’s findings show why a policy and a training record matter only when staff know how to handle real information safely.
Read articleNeed help putting this into practice?
IT Club helps you understand the technology. If you need implementation, support or consultancy, the teams behind IT Club can help.
Altitude IT (opens in a new tab) — IT support, cyber security, Microsoft 365 and technology operations.
Altitude AI (opens in a new tab) — AI discovery, automation, governance and implementation.