NDIS participant data used to fight fraud sparks privacy fears
Concerns Emerge Over NDIS Participant Data Sharing with Palantir Software
Your NDIS Data and the Fraud Taskforce
Personal information belonging to National Disability Insurance Scheme (NDIS) participants may have found its way into analytics software operated by the controversial company Palantir. This data sharing reportedly occurred as part of a large-scale, multi-agency program designed to investigate fraud within government services.
While the National Disability Insurance Agency (NDIA) initially denied directly using Palantir’s software, recent information indicates that NDIS data is being shared with the Australian Criminal Intelligence Commission (ACIC). The ACIC, in turn, utilises Palantir as a key tool within the Fraud Fusion Taskforce, a collaborative effort involving 25 government agencies focused on detecting and preventing fraud.
Who is Palantir, and Why is it Controversial?
A Software Company Under Scrutiny
Palantir is a data analytics software company co-founded by US billionaire Peter Thiel. Its software is designed to map connections between people and analyse vast amounts of data, helping organisations identify patterns and solve complex problems.
However, the company has faced significant controversy. In May, a manifesto released by Palantir drew criticism for implying some cultures are inferior, leading a UK Member of Parliament to describe it as “the ramblings of a supervillain.”
These controversies have led to calls for the Australian government to ban the use of Palantir’s software. Recently, the supermarket giant Coles announced it would not extend its contract with Palantir beyond 2027, having previously used the software for rostering, store operations, and supply chain planning.
Understanding the Fraud Fusion Taskforce
The Fraud Fusion Taskforce was established in 2022 and is jointly led by the NDIA and Services Australia. Its primary goal is to investigate and combat fraud across various government programs.
Central to this effort is the Fraud Fusion Centre, managed by the ACIC. This centre collects “large volumes of information, data and intelligence” from participating agencies, pooling resources that could be relevant to the taskforce’s work.
The ACIC has paid millions in contracts to Palantir over recent years. Its capabilities within the taskforce include advanced data analysis, identifying behavioural and financial patterns, and data-matching across the extensive databases held by the various government agencies involved.
How NDIS Information Flows
Despite the NDIA’s earlier denial of direct Palantir use, the agency has confirmed it shares NDIS participant information with the Fraud Fusion Taskforce partners.
According to an NDIA spokesperson, this information is shared “on a restricted basis where potential criminal conduct is suspected to protect participants from fraud.”
A spokesperson for the ACIC confirmed that it uses “a suite of analytical tools and capabilities” for its operations. They added that taskforce-related data is collected and stored consistent with restrictions agreed upon with the agency providing the data, which is responsible for outlining any usage, handling, and disclosure limitations.
Concerns for Privacy and Dignity
The potential for NDIS participant data to be ingested by Palantir’s systems has raised significant privacy concerns among disability advocates and digital rights experts.
A data scientist and researcher, Gabrielle Josling, who submitted several freedom of information (FoI) requests to agencies within the taskforce, sought records of data being fed into Palantir’s software. An FoI officer indicated reluctance to process the request, stating that “the process for ingesting one FFC (Fraud Fusion Centre) dataset into Palantir generates an amount of documents that… would likely not be manageable.” This suggests a substantial volume of data is being processed.
Tom Sulston, head of policy at Digital Rights Watch, expressed deep concern, stating that “People using NDIS deserve the dignity of not being treated like criminals simply for accessing the services that they need to live a full life.” He described the creation of such large aggregated datasets as “fundamentally de-humanising,” especially when aimed at people with disabilities who often already face indignities.
Greens Senator David Shoebridge, who is the party’s digital rights and AI spokesperson, called the situation a “deep betrayal” of trust. He argued that NDIS participants provide their data believing it will be protected and used solely to assist their claims, not “funnelled into Palantir under the guise of fraud prevention.”
Palantir’s Position
When contacted about the matter, a spokesperson for Palantir stated that the company “builds software that helps organisations use their data to make better decisions and solve their most complex problems.” They affirmed their commitment to supporting Australian government agencies in “tackling complex challenges, including serious financial crime and fraud.”
What This Means for NDIS Participants and Providers
This news highlights the increasing intersection of government services, data analytics, and fraud prevention. For NDIS participants and providers, it means a heightened awareness of how personal information, essential for accessing and delivering supports, is being managed and shared across government bodies.
While the NDIA assures that data sharing is restricted to cases of suspected criminal conduct, the involvement of a company like Palantir, with its history of controversy and powerful data analysis capabilities, raises questions about transparency and oversight.
Looking Ahead: What You Can Do
Staying informed about how your data is used is always important. Advocacy groups and digital rights organisations are closely monitoring this situation, pushing for greater transparency and accountability from government agencies regarding data sharing practices.
If you have specific concerns about your personal NDIS information, you may wish to consider contacting the NDIA directly for clarification on their data privacy policies and how they ensure participant data is protected within multi-agency taskforces.
The focus remains on ensuring that vital services like the NDIS can operate effectively, prevent fraud, and uphold the privacy and dignity of every participant.

