You were never
the customer.
Palantir does not collect your data. It does not sell it. It does not own it. All three are true, and none of them help you. What the company sells is the layer that turns records the government already holds into a single searchable object. In March 2025 an executive order removed the last legal barrier standing between those records.
Nothing else on this site applies here
Every other page here ends with something you can do. Block the trackers. Replace the phone. Find the cameras and go to the council meeting. The advice varies but the shape does not: reduce what gets collected about you.
That shape breaks completely on this page. There is no Palantir product you use, no account you opened, no terms you accepted, no privacy notice with your consent recorded in it, no setting to change and no opt-out to click. You have no relationship with this company at all. Its customers are governments and corporations, and the data it operates on is data those customers already had.
So this page has no mitigation section, because there is no honest one to write. What it has instead is an argument about what actually protected you, and what happened to it.
What Palantir actually sells
Start by granting the company its defence in full, because the argument only works once you do. Palantir says it has "never been" a surveillance company, that it does not conduct surveillance or sell software "for the purposes of enabling unlawful surveillance," and that unlike the advertising giants it has no business model based on selling data. Every one of those statements is accurate. Palantir is not a data broker. It does not have a copy of your life to sell.
What it sells is software that sits on top of records somebody else holds. Its own documentation describes it best:
- Foundry is the data platform, with "200+ prebuilt connectors" that unify "structured and unstructured data" from separate systems.
- The Ontology is the core idea: "an operational layer for the organization that sits on top of the digital assets integrated into the Palantir platform… and connects them to their real-world counterparts." Rows in unrelated databases become one object: a person, a vehicle, a place.
- Gotham is the defence and intelligence version of the same machinery.
- AIP is the language-model layer, built, in Palantir's words, "on top of the Ontology."
Read that list again with one question in mind: what was ever actually stopping any of this?
The government has held this material for decades. Your tax filings, your benefits claims, your immigration file, your licence, your address history. None of it is new, and none of it was ever secret from the agency that collected it.
The protection was separation, not secrecy. The records sat in different systems, at different agencies, under different legal authorities, in incompatible formats, and joining them was slow, expensive and often unlawful. That friction was doing the work that policy was not.
Palantir sells the removal of that friction. That is not a criticism of the company so much as a plain description of the product, and the company would broadly agree with it.
Eighteen agencies
The scale is not a matter of opinion. Federal contract awards are public, and the figures below come from a query run against the U.S. Treasury's USAspending API on 18 August 2026, covering all contract obligations to Palantir on record.
| Agency | Obligated | What it is for |
|---|---|---|
| Defense | $3.19 billion | Maven Smart System and Army Vantage, the largest single line by an order of magnitude. |
| Homeland Security | $457.4 million | ICE case management, covered in detail below. |
| Health and Human Services | $416.2 million | Health data platforms. |
| Justice | $213.0 million | Investigative systems. |
| Treasury | $198.7 million | Includes the IRS. |
| Agriculture | $147.0 million | Farm production and conservation IT, under the "Landmark" platform initiative. |
| Veterans Affairs | $127.2 million | Software as a service. |
| State | $122.0 million | Not stated in the award descriptions. |
| Energy | $99.2 million | Includes the nuclear security administration's SAFER project. |
| Transportation | $71.1 million | Not stated in the award descriptions. |
| Securities and Exchange Commission | $50.4 million | Not stated in the award descriptions. |
| Seven more | $41.5 million | Development Finance Corporation, NASA, GSA, Commerce, Interior, and, at $400,000 and $80,000, Housing and Urban Development and Labor. |
$5.14 billion across eighteen agencies. The headline number is Defense, and the Defense work is the part with the clearest public justification. But the interesting entries are the small ones. A company with $80,000 of business at the Department of Labor and $400,000 at Housing and Urban Development is not a defence contractor that also does other things. It is a general-purpose government contractor whose product happens to be the joining of records.
These are obligations recorded against contract awards, not revenue received, and the total moves as new task orders land. Re-run the query rather than trusting this figure indefinitely. The largest single awards on the day of the query: $545.6M and $292.7M to the Army for the Maven Smart System, $150.7M to ICE for Investigative Case Management running from September 2022, $145.0M and $103.4M for Army Vantage, $94.7M to Agriculture, and $86.3M to ICE for Enforcement and Removal Operations case management.
The order that removed the barrier
On 20 March 2025 the President signed Executive Order 14243, "Stopping Waste, Fraud, and Abuse by Eliminating Information Silos" (90 FR 13681). Its stated purpose is efficiency: "Removing unnecessary barriers to Federal employees accessing Government data and promoting inter-agency data sharing are important steps toward eliminating bureaucratic duplication and inefficiency."
Read what it actually directs.
Section 3(a) is the same instrument turned inward: agency heads shall ensure designated officials have "full and prompt access to all unclassified agency records, data, software systems, and information technology systems," and shall authorise "inter- and intra-agency sharing and consolidation of unclassified agency records." Section 3(d) gives the Secretary of Labor "unfettered access to all unemployment data and related payment records."
The separation described earlier on this page is being dismantled on purpose, in writing, as policy, not eroded by accident or by technology.
One thing this order does not do: name a contractor. Palantir does not appear in it, and anyone telling you the order was written for Palantir is going beyond the document. What the order does is create the conditions. Removing a legal barrier to consolidation raises an immediate practical question. Consolidate them how, and with what? There is a company whose entire product is the answer.
What it looks like in practice
Palantir's largest civilian customer is immigration enforcement, and the relationship is much older than the current administration. The Investigative Case Management system, built on the Gotham platform for Homeland Security Investigations, has been running on ICE contracts since well before 2025. The current award dates from September 2022. In April 2025 ICE was reported to have added roughly $30 million for a platform called ImmigrationOS, with a prototype due that September, intended to streamline identification of removal targets and give "near real-time visibility" into self-deportations.
But the clearest picture of what data consolidation means in practice comes from a case Palantir is not party to at all, and most coverage got the outcome backwards.
In February 2025 the New York Times reported that Homeland Security officials were pressing the IRS for the addresses of 700,000 immigrants. Community organisations sued. On 7 April 2025 the IRS and DHS signed a memorandum of understanding governing ICE requests for "addresses of persons subject to criminal investigation."
The plaintiffs' argument was the intuitive one: tax records are confidential, and Congress said so. The IRS itself had long read the statute that way. Its own Disclosure & Privacy Law Reference Guide stated that addresses could not be handed over on their own.
The court of appeals affirmed the denial of an injunction. The plaintiffs likely had standing, it held, but were unlikely to win, because section 6103(i)(2)(C) says in terms that "a taxpayer's identity shall not be treated as taxpayer return information." Identity includes your mailing address. The IRS guidance saying otherwise was "nonbinding" and "lacked legal effect."
So the protection people believed they had was never a law at all, just an agency's reading of one, maintained for years by institutional habit. When it was finally tested, the statute turned out to permit exactly what everyone assumed it forbade.
A parallel case reached a different posture on different facts: on 21 November 2025, in Center for Taxpayer Rights v. IRS, Judge Colleen Kollar-Kotelly stayed address-sharing over how the agreements were actually being implemented. That litigation continues. But on the central legal question of whether the statute permits it, the appellate answer is on the record.
This is the argument in one case. Nobody hacked anything. No new data was collected. Two agencies with lawful possession of their own records were permitted to join them, and a boundary that people had relied on for decades turned out never to have existed in the first place.
The control case
This is what happens when a country tries to draw the line, because one did. In 2023 NHS England awarded Palantir a £330 million seven-year contract for a Federated Data Platform covering the health records of the population of England.
The most instructive fact about that contract is not in it. When it was first published, 417 of its 586 pages were blanked out. It took a legal challenge from the Good Law Project to force the release of a less redacted version. A further challenge was brought by Foxglove together with Just Treatment, the Doctors' Association UK and the National Pensioners Convention. In June 2025 the British Medical Association voted to lobby against the company's involvement in the health service. The contract carries a break clause available from February 2027, and the UK government is reported to be weighing whether to use it.
The lesson is not that Britain did better. Even in a system with a statutory data protection regime, an information commissioner, an active professional body and a litigious civil society, the terms on which national health records were handed to a private platform had to be prised out through the courts. The public still got a redacted copy.
Their answer, taken seriously
Palantir's response to all of this is not evasive, and it holds up better than most corporate defences. The company's position is that its software makes abuse harder than the alternative. Alex Karp has put it bluntly: "We are the single worst technology to use to abuse civil liberties, which is by the way the reason why we could never get the NSA or the FBI to actually buy our product." The argument rests on real engineering: immutable audit logs, granular access controls, purpose limitation, and a record of every query and who ran it. In its most recent quarterly filing the company put it this way: "Our customers trust us to provide them with maximal control over their operations, data, and decisions."
Take it at face value. It is probably true, and it is more than most vendors offer.
Now notice what it answers. Audit logs and access controls govern who inside an authorised system did what. They are a defence against the rogue analyst looking up an ex-partner. They are excellent at that.
They say nothing whatever about the two questions that matter here: whether the system should have been built, and whether the access it grants is lawful in the first place. An immutable log of a lawful query is still a lawful query. The IRS-ICE case had nothing to do with a rogue employee. It turned on whether an entire category of disclosure was permitted, argued by government lawyers in open court, and decided on the text of a statute. No amount of query logging is responsive to that.
One more thing the frame misses. In the quarter ending June 2026 Palantir reported revenue of $1.935 billion, up 93% year on year, with US government revenue of $809 million and US commercial revenue of $764 million growing faster still at 149%. Full-year guidance was raised to roughly $8.15 billion. Calling this a government surveillance contractor is becoming an incomplete description: the commercial half is about to be the larger one, and the customers there are employers, insurers, hospitals and banks.
What actually changes things
There is no personal mitigation, and pretending otherwise would insult you. What exists instead are the four places where this has actually been slowed down, all of them collective and none of them fast.
- Procurement is public, and almost nobody reads it. Every figure in the table above came from a free government API in a single query. Contract descriptions state what a system is for in plain language, months before anyone reports on it. This is the single most underused accountability tool in existence.
- Statutes, not agency guidance. The central lesson of the IRS case is that the protection people relied on was an interpretation, and interpretations are free to change. A safeguard that lives in a manual is not a safeguard. Only text in a statute survives a change of administration.
- Records requests, then litigation. The NHS contract became public because someone sued for it. The IRS memorandum became public because someone sued. Redaction is the default, and the default only moves when it is challenged.
- The comment period on the next order. Executive orders do not have comment periods, but the rules agencies write to implement them usually do. That is the point at which "unfettered access" either acquires limits or does not.
The uncomfortable conclusion of this page is that the thing protecting you was friction, not a right or a setting or a company's good intentions: the sheer difficulty of joining one government database to another. Friction is not a principle and it was never going to hold. It has now been removed deliberately, by order, and sold back to the government as a service. Whatever replaces it has to be written down.
Palantir now has an entry in our Corporate Dossier, and it is the only one with no fines against it. That is not an oversight. Nothing described on this page is a violation of anything, and that is the uncomfortable part.