The Direction that does't exist
My petition closed yesterday. 33,182 of you signed it. Truly appriciate everyone who signed and shared. This is what asking the question revealed
In December 2025 I started a parliamentary petition. It asked for two things a clear national opt-out for NHS data processed in the Federated Data Platform (FDP) and the National Data Integration Tenant (NDIT), and a full public consultation before any further expansion of these systems.
It closed yesterday, 14 July, with 33,182 signatures. Source: Petition 752855
We didn’t reach the 100,000 needed for a parliamentary debate. But the petition did something else. It forced the government to put its justification in writing and then, over five months, that justification fell apart on the official record every time somebody asked to see the paperwork.
This is the chronology. Every step is a public document. Check every one.
First, what these systems are
The NDIT is NHS England’s platform for collecting national health and care data — the pipe through which hospitals and trusts submit the data they are required to send. NHS England’s own privacy notice for the NDIT confirms what goes in: patient data in identifiable form — the notice lists the categories — before pseudonymisation takes place. The same notice confirms that the de-identification step is carried out by IQVIA, a US-listed commercial health data analytics company, acting as a data processor.
Source: NDIT product privacy notice, NHS England Source (IQVIA’s £28m NHS-PET de-identification contract): Contract award notice
Once de-identified, the data is routed to the FDP the national data platform built on Palantir Foundry,
Source: Hansard, Secretary of State statement on the FDP contract award, 21 November 2023
The National Data Opt-Out (NDOO) is the mechanism that is supposed to let you refuse the use of your confidential patient information for purposes beyond your own care. The question my petition asked, in effect, was simple why doesn’t it apply here?
6 February 2026 — the answer to 33,177 people: a direction
The government responded to the petition on 6 February. Here is the key passage, verbatim:
“The NDOO does not apply to NDIT processing because NHS England is legally required, under a direction from the Secretary of State for Health and Social Care, to process this data to create national insights and dashboards. There is, therefore, no specific opt-out for the NDIT, or plans to introduce one, as the data processing occurs under a legal requirement.”
Source: Government response, Petition 752855
Read that mechanism carefully. The Secretary of State directed NHS England to collect the data. That self-created legal requirement is then the stated reason why no opt-out is needed. The government made it mandatory, then cited the fact that it is mandatory as the justification for removing the right to refuse.
The response did not name the direction. It did not date it. It did not link to it.
Hold that.
16 April 2026 — asked in Parliament to name it
On 16 April, in a Westminster Hall debate on the Federated Data Platform, Iqbal Mohamed, the independent MP, pressed the government on the legal direction being used to remove the opt-out.
The minister Dr Zubir Ahmed, then Parliamentary Under-Secretary of State for Health Innovation and Safety did not name it. Source: Hansard, Westminster Hall, 16 April 2026
28 April 2026 — asked about the direction, the minister answers for a different system
Twelve days later, answering Written Question 128022, the same minister stated in writing that the opt-out does not apply to the FDP “not because of a direction.”
Source: WPQ 128022, answered 28 April 2026 by Dr Zubir Ahmed
Watch what happened there. The February claim a direction was made about the NDIT: the collection layer, the part that holds your data while it is still identifiable. The April answer addresses the FDP: the downstream analysis platform, which receives data after pseudonymisation. Asked about the legal instrument, the Department answered for the system the direction claim was never about. The NDIT the system it was about went unaddressed. It stayed unaddressed for two more months.
On 12 May, Dr Ahmed resigned as a minister in protest at the party leadership following the Scottish Parliament elections, not over anything in this story the timing is coincidental, and it should be stated plainly so nobody assumes otherwise. His successor on this portfolio is Preet Kaur Gill. Source: Digital Health News, 13 May 2026
25 June 2026 — asked for the name and date. The answer: it doesn’t exist.
Through Iqbal Mohamed’s office, a written question was tabled asking the Department, in terms, to name the specific legal direction under section 254 of the Health and Social Care Act 2012 that disapplies the National Data Opt-Out for NDIT processing by name and date.
The answer, from Preet Kaur Gill, 25 June 2026, first sentence:
“There is no direction made under section 254 of the Health and Social Care Act 2012 that disapplies the National Data Opt-out for the National Data Integration Tenant.”
Source: UIN 9251
Let me be precise here, because precision is the whole point. The February response said a direction requires the processing. The June answer says no direction disapplies the opt-out. A careful reader could argue those are technically different sentences. Here is why that defence does not survive contact with the question the question asked the Department to name the direction, by name and date. If a direction requiring NDIT processing existed, the complete answer was its name, its date, and any technical clarification the Department wished to add. Instead the Department named nothing and moved to a different justification entirely: that no confidential patient information is processed by any product in the National Instance of the FDP to which the opt-out would apply, and that confidential patient information in Local Instances is used only for direct care. Source: UIN 9251
So the position offered to 33,177 petition signatories in February a legal instrument removes your opt-out became, when the instrument was requested no such instrument; the opt-out simply has nothing to bite on, because once your data is pseudonymised it is no longer “confidential patient information.”
The justification changed shape when someone asked for the paperwork. That is the story.
The same fortnight, in the Department’s own words: the data arrives identifiable
Because here is what the definitional argument has to survive. A companion question (UIN 9252, referencing that April answer) asked for the legal basis for processing identifiable data before pseudonymisation. The answer, same day, same minister, confirms the premise: NHS England’s legal basis for “the processing of identifiable data prior to pseudonymisation” is derived from its statutory functions and UK data protection law — Article 6(1)(e) UK GDPR, and, quote, “in some cases, Article 6(1)(c) also applies where processing is necessary for compliance with a legal obligation, such as where data is collected under a Direction.” Source: UIN 9252
A Direction. Capital D. Unnamed. In an answer published a fortnight after the Department said no relevant direction exists.
The same answer states that the identifiable-stage processing is undertaken in accordance with the legal framework “and is set out in the applicable Data Protection Impact Assessments.” Note where the safeguard lives: in DPIAs. Keep that thought this investigation has spent eighteen months cataloguing NHS data systems where the DPIA was never done, never updated, or never published.
And a third question (UIN 9253) asked whether NHS England received legal advice in 2024 that aspects of the FDP lacked a legal basis — something NHS England’s own lawyers were reported to have flagged to the programme in March 2024. The answer denies a claim that was not made “At no point has NHS England’s legal advice been that the NHS FDP lacks a legal basis” (aspects became the whole platform) — and then, two sentences later, confirms the mechanism: legal advice “has informed the development and refinement of specific aspects of the NHS FDP to ensure that appropriate legal bases and safeguards are in place.” Source: UIN 9253 Source (the 2024 legal advice reporting): The Register, 5 September 2024
You do not refine specific aspects of a platform to ensure a legal basis is in place if the advice was that every aspect already had one.
And one detail closes the loop. The Register’s reporting was specific about which aspect the March 2024 legal advice found lacked a legal footing: the privacy-enhancing technology the de-identification layer, provided by IQVIA. The Department’s answer to UIN 9252 names that same technology, “NHS Privacy-Enhancing Technology,” as the mechanism by which data is de-identified for downstream use. The component their own lawyers questioned is the component now presented as the safeguard.
One more thing the “products” wording has to survive
The June defence is drafted with care: no confidential patient information is processed by a product in the National Instance. But NHS England’s own governance record shows the platform has not only hosted finished products. Minutes of the FDP Check and Challenge Group from October 2024 document an incubation programme — products being built and developed on the platform itself confirmed in an FOI response from Northumbria Healthcare NHS Foundation Trust (reference FOI 10599). A product roadmap requested in October 2024 has never been published. Guidance on who owns the intellectual property in incubation-phase products remains unresolved. Source: [FDP Check and Challenge Group minutes, October 2024 and FOI 10599, Northumbria Healthcare NHS FT
I am not claiming confidential patient information was used in incubation — no document in my possession says that. I am pointing at the gap between the assurance and the activity: a promise scoped to “products” says nothing about what data is used while products are becoming products. That is now a question on the list.
Meanwhile, on NHS England’s website: they updated the notice — and kept the direction
Here is where the timeline folds in on itself.
On 3 June, the National Data Guardian published a statement responding to the Not With My NHS Data campaign. The DPIA the NDG had reviewed said access to identifiable patient information would be limited to NHS staff with a legitimate need. Media reporting, then confirmation from the programme itself, established that external contractor staff also have access to identifiable patient information within the NDIT. The NDG’s words: “We were not aware of this.” Source: National Data Guardian statement, 3 June 2026
NHS England’s published response admits that three Palantir engineers hold administrative-level access to the NDIT and could access identifiable patient data for technical support — and states: “Alongside correcting the DPIA, we have updated the NDIT privacy notice.” Source: NHS England response to the NDG
That update to the privacy notice is dated 16 June 2026 — five days after the written questions in this piece were tabled, nine days before the Department told Parliament no direction exists. I make no claim about what prompted the update; the NDG correction exercise is the documented context. What matters is what survived it. The revised notice live as I write this still says the opt-out does not apply “because NHS England is required by law under the Legal Direction to process the data to create the dashboards.” Source: NDIT product privacy notice
Someone opened that document in June. Someone revised it. And someone left “the Legal Direction” capital L, capital D, still unnamed as the stated reason 33,177 people cannot opt out, nine days before the Department told Parliament that no direction disapplying the opt-out for NDIT exists.
And here is the shape of the gap, precisely. The individual data collections flowing into the NDIT each cite their own Secretary of State direction — NHS England’s published list of NDIT data sets states, collection by collection, that each “is collected under a legal direction from the Secretary of State”: the community services flows, Hospital Episode Statistics, the NHS App data under the NHS App Directions 2023, and the rest. Directions written for the old world of separate systems, each authorising its own pipe. Source: Data sets processed in the NDIT, NHS England
What does not exist is a direction for the tenant itself the platform that pools them all. The closest thing to a platform-level instrument, the NHS England De-Identified Data Analytics and Publication Directions 2023, is scoped, per its own published summary, to the governance of the ongoing processing of de-identified data and a framework for future analysis, linkage and de-identification. Yet the petition response spoke of “a direction” — singular — requiring NDIT processing, and the privacy notice, revised in June, still invokes “the Legal Direction” — definite article, as if a single instrument for this system exists. Asked to name it, the Department confirmed what the definite article was concealing: there isn’t one. The plumbing is authorised piecemeal; the consolidation is not. The NDIT’s DPIA page, meanwhile, currently carries a banner: “This DPIA is under review and will be updated shortly.” Source: NHS England De-Identified Data Analytics and Publication Directions 2023 Source: NDIT DPIA publication page
The chronology, in one place
6 February 2026 — Government to 33,177 petitioners: no opt-out, because of “a direction from the Secretary of State.” Unnamed. (Petition 752855)
16 April 2026 — Asked in Parliament to name the direction. No answer. (Hansard, Westminster Hall)
28 April 2026 — The then-minister, in writing, answers for the FDP — “not because of a direction” — leaving the NDIT, the system the direction claim was made about, unaddressed. (WPQ 128022)
3 June 2026 — The National Data Guardian, on contractor access to identifiable data in NDIT: “We were not aware of this.” (NDG statement)
11 June 2026 — Written questions tabled asking for the direction’s name and date.
16 June 2026 — The NDIT privacy notice is updated. “The Legal Direction” wording stays in. (NDIT privacy notice)
25 June 2026 — Asked for the name and date: “There is no direction made under section 254... that disapplies the National Data Opt-out” for NDIT. (UIN 9251)
25 June 2026, same day — The lawful basis for identifiable-stage processing includes cases “where data is collected under a Direction.” (UIN 9252)
Today — The revised notice, live, still cites “the Legal Direction.”
Two ministers. A direction, then an answer about a different system, then no direction. A privacy notice revised mid-sequence with the unnamed direction left standing. Zero named directions.
I am not telling you what this means. I map the gaps, and this is a gap in the legal foundations of a system that collects the identifiable health data of everyone in England, with no opt-out, on the stated authority of a document that the Department, asked directly, could not name.
What happens now
The petition is closed. The question is not.
Three things worth banking from the February response before it disappears down the memory hole. First, its claim that the overarching FDP DPIA “underwent extensive external review (including by the ICO and NDG)” — an assurance for which no review outputs, minutes, or record of resulting changes have ever been published. Second, its written commitment that NHS England will consult patient groups, the National Data Guardian and the ICO “before any other Use Cases are agreed” — that is the test to apply to every future expansion of this platform, in their own words. Third, its promise that “the use of patient data within the NHS FDP will always respect the NDOO.” Source: Government response, Petition 752855
The follow-up questions are already drafted:
I’ll publish the answers when they come. Every document in this piece is public.
— Gemma Smith, The Scouse Oracle

Thank you Scouse for this thorough report. Suspiciously slippery snakes🐍. I want to how far Tony Blair's tendrils are in this 🤔🧐