Disabled Australians' Private Data May Have Flowed Into Palantir's Systems Through Fraud Investigation Program
Personal records belonging to NDIS participants were potentially shared with the controversial US analytics company as part of a government anti-fraud operation, Guardian Australia has revealed.

Key points
- Personal data belonging to National Disability Insurance Scheme (NDIS) participants may have been fed into Palantir's analytics platform without participants' knowledge.
- The Australian Criminal Intelligence Commission (ACIC), which has legal access to NDIS data, used Palantir software as part of a multi-agency fraud investigation taskforce.
- Calls to ban Palantir from Australian government contracts began in May 2025, after the company published a document that one UK politician described as the "ramblings of a supervillain".
- The NDIS supports around 650,000 Australians living with permanent disability, making the potential data exposure significant in scale.
Private information held by Australia's National Disability Insurance Scheme, which funds support services for hundreds of thousands of Australians living with permanent disability, may have been processed inside software built by Palantir Technologies, a US data analytics company already drawing government scrutiny in several countries.
Guardian Australia first reported the arrangement. At its centre is the Australian Criminal Intelligence Commission, a federal body with lawful access to NDIS records, which joined a multi-agency taskforce investigating fraud against the scheme. That taskforce used Palantir's platform, which is software that pulls large volumes of data from different sources and searches it for patterns, to look for suspicious patterns in the data.
Who is Palantir, and why is it controversial?
Palantir is a well-funded American company founded in 2003 that sells data-analysis tools to governments and large corporations. Its software is used by intelligence services, police forces and health agencies in multiple countries.
The controversy sharpened in May 2025, when Palantir published a document, sometimes described as a manifesto, that drew sharp criticism. One UK Member of Parliament called it the "ramblings of a supervillain." Critics said the document implied some cultures are inferior to others. Since then, voices inside the Australian government have called for Palantir to be removed from public-sector contracts entirely.
What information may have been shared, and with whom?
The NDIS holds sensitive personal details: medical diagnoses, care needs, financial circumstances, and contact information for some of the country's most vulnerable people. The ACIC, as a law-enforcement body, has access to that data for legitimate investigative purposes.
The concern here is not that fraud was being investigated. It is that doing so may have routed private disability records through a third-party commercial platform, Palantir, without participants knowing their information had moved outside the agencies they deal with directly.
Neither the ACIC nor the NDIS Agency has confirmed precisely which data fields were shared or how many participants are affected.
Should NDIS participants be worried?
There is no indication, at this stage, that data was stolen or misused by outside criminals. The risk identified so far is one of governance: sensitive records may have been shared with a private company in ways that participants did not expect and were not told about.
If you or a family member receives NDIS support, you are entitled to ask the NDIS Agency what data it holds about you and who it has been shared with. Australia's Privacy Act gives individuals that right. Watching for unusual contact, such as unsolicited calls or emails claiming to be from the NDIS, is sensible precaution regardless.
| Key fact | Detail |
|---|---|
| Scheme affected | National Disability Insurance Scheme (NDIS) |
| Federal body involved | Australian Criminal Intelligence Commission (ACIC) |
| Platform used | Palantir Technologies analytics software |
| Purpose | Multi-agency fraud investigation taskforce |
| Controversy started | May 2025 |
| Approximate NDIS participants | 650,000 Australians |
The broader question now before Australian policymakers is whether law-enforcement data-sharing arrangements need stronger rules about which commercial vendors can touch sensitive government records, and what participants must be told.


