Data Protection & Health Governance  ·  3 August 2026

Not a Registered Party

How Manx Care's own Freedom of Information response names the route patient data reaches Palantir's NHS platform, then declines to assess it.
By Alan Wright  ·  The Haunted Lighthouse Limited  ·  Peel, Isle of Man

On 16 June 2026, Manx Care answered a Freedom of Information request (ref 5519529) asking whether it shares data with the NHS Federated Data Platform, whether it has assessed the risk of Palantir Technologies holding a contract on systems that touch Manx patient data, and which third parties can see that data before it is anonymised.

The answer to the registration question was straightforward: Manx Care is not a registered party to the Federated Data Platform. The answer to everything that follows from that is where the letter becomes interesting.


The hedge

Two of the six answers carry an identical qualifier. On the Federated Data Platform: "we would not have control of Manx patient data that is captured through any agreements with our UK Trusts who may be registered with the FDP." On the Secondary Uses Service: the same sentence, almost word for word.

Manx Care wrote its own exposure into the file. It just left the pathway unnamed.

Disclaiming "control" over what happens to data after a referral is not a defence. Manx Care remains the controller for the referral itself: the act of sending identifiable patient data to an organisation it knows operates inside a platform built by a company whose NHS contract has drawn sustained parliamentary and professional criticism. A controller does not discharge its obligations by pointing at where the data goes next.


The "may be" resolved

It is not hypothetical. Manx Care's long-standing arrangement for specialist referral care runs through Liverpool University Hospitals NHS Foundation Trust (LUFT), the trust that also, as of this year, runs the collaborative procurement selecting the supplier for the Manx Care Record, the single patient record intended to replace up to sixteen existing systems across the Island's hospitals, GPs, community and mental health services.

LUFT appears, by name, on NHS England's own published list of organisations signed up to the Federated Data Platform.

So the "UK Trust who may be registered with the FDP" is not an abstract category Manx Care declined to specify. It is a named, checkable, single institution: the same one now choosing what happens to the record that will eventually hold every Manx resident's unified medical history.


The question that wasn't answered

Question six asked directly: has Manx Care conducted a Data Protection Impact Assessment in relation to patient data flows to NHS England systems where Palantir Technologies UK holds a platform contract?

The answer given: "As above, Manx Care is not a registered party to the Federated Data Platform."

That is not an answer to question six. It is the answer to question one, repeated. Question six was never about registration. It was about whether the risk created by the referral pathway, the one Manx Care's own letter had already conceded exists two paragraphs earlier, had been assessed. The letter does not say a DPIA was done. It does not say one wasn't. It restates a fact about a different question and lets the reader assume the restatement covers the gap.

It doesn't. A DPIA on Manx Care's own registration status would be trivial, since there is nothing to assess if Manx Care never joined the platform directly. A DPIA on data leaving the Island via referral, arriving at a trust that operates its own Federated Data Platform tenancy, and potentially sitting inside Palantir Foundry once it lands there, is a different and considerably harder exercise. Nothing in the letter indicates that exercise has been done.

The threshold is not discretionary. Article 35(3)(b) of the GDPR, applied to the Isle of Man in full by the Data Protection (Application of GDPR) Order 2018, makes a DPIA mandatory for processing on a large scale of special category data. Health data is special category data by definition. A referral pathway that routinely sends identifiable patient records to an FDP-registered trust is large-scale, systematic processing of exactly that category, not a marginal or occasional case that might fall under the general 35(1) threshold instead. The letter does not address 35(3)(b). It does not need to reach for a broader risk test to establish that an assessment was owed here; the specific, mandatory limb already applies on the facts Manx Care itself supplied.


Who's actually choosing

The same trust sits on both sides of this. LUFT receives Manx patients under a referral relationship Manx Care itself flagged as outside its control. LUFT is also running the procurement that will select the commercial platform underpinning the Manx Care Record, with Manx Care joining as a rider on that trust's competition rather than running its own.

Nothing in the public record on either project, the FOI response or the Manx Care Record announcements, connects these two facts. The institution named as the source of Manx Care's own admitted data exposure is the same institution now picking the vendor for the Island's next decade of patient data infrastructure, and no one has been asked whether that matters.


A second data point

A separate FOI (ref 5657797), answered a month later on 16 July, asked what governance work had been done on the four winners of the 2026 Innovation Challenge, three weeks after their public announcement at Comis Hotel. Manx Care's answer: it holds no Data Protection Impact Assessments, clinical safety reviews, information governance assessments, or data sharing agreements for any of the four platforms, because no contracts have been awarded and no pilots have started.

Different mechanism, same shape. In one case, governance lags months behind a public announcement because nothing has formally begun. In the other, governance was never triggered because the referral relationship generating the exposure was never treated as the kind of decision that requires it.


The pattern

None of this requires a hidden scandal to be worth stating plainly. Manx Care's letter answers the letter of each question asked, and nothing here alleges concealment. But answering a different, easier question while appearing to answer the one that was asked is a standard bureaucratic evasion, not an oversight, and it should be named as one. Manx Care correctly identified its own exposure to a controversial US-owned data platform in writing, in the same letter that avoided the single question that would establish whether that exposure had ever been assessed, on a threshold its own applied law makes mandatory rather than discretionary.

That is not concealment. It is a gap nobody has been forced to close, because nobody has yet asked the right follow-up question out loud, in public, on the record, and pointed at the specific clause that makes the answer owed.

Now someone has.


Cross-reference: Where's the DPIA?


Questions about this analysis, or interested in working with The Haunted Lighthouse?
contact@haunted.lighthouse.co.im

The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy—with particular focus on Isle of Man jurisdiction and Crown Dependency issues.

Support independent analysis. Subscribe directly—or scan on your phone.

Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.