The Government is sharing your data between agencies and even with controversial CIA-linked surveillance group Palantir. Without permission, without disclosure. Claudia Weisenberger reports.
If you receive NDIS funding, or provide services to someone who does, 25 government agencies are sharing information about you. You were never asked. You were never told. The rules governing how they do it were written after the sharing began and have never been published.
And the officials overseeing it include two people who gave evidence at the Robodebt Royal Commission — the scheme a Royal Commission found unlawful, that destroyed people’s lives, and for which nobody was ever prosecuted.
At the centre of this story is a question nobody in Parliament was required to answer: does NDIS participant data that flows through a 25-agency government network reach Palantir Technologies — the controversial American surveillance company whose software runs inside the CIA, the Pentagon and Immigration and Customs Enforcement?
AUSTRAC – Australia’s financial intelligence agency – holds a $12.07m Palantir contract. Banks are instructed to send AUSTRAC reports flagging NDIS-referenced transactions. Those reports contain personal details of NDIS participants. Whether that data reaches Palantir’s systems has not yet been confirmed or denied.
Nobody asked. Nobody was required to answer.
The NDIS is not the only part of this story. The same network includes the ATO, the Australian Federal Police, the Australian Criminal Intelligence Commission and the Department of Home Affairs. A Services Australia internal assessment, released under FOI, stated that Palantir “is known to be used by Australian intelligence agencies”.
The Department of Defence holds a separate confirmed Palantir contract.
In the United Kingdom, the National Health Service awarded Palantir a £330 million contract for a national health data platform. By 2026, however, the NHS was trying to exit the arrangement after a parliamentary committee described Palantir’s presence as ‘an unacceptable point of weakness’.
How deeply Palantir is embedded across Australian government – and under what oversight – has never been the subject of a formal parliamentary inquiry.
The rules nobody published
The Fraud Fusion Taskforce was established on 1 November 2022, co-led by the NDIA and Services Australia. Within weeks, 25 government agencies were sharing information about NDIS participants, providers and payments across a network that includes AUSTRAC, the financial intelligence agency, the ATO, the Australian Federal Police and the Australian Criminal Intelligence Commission.
The rules governing who can access the most sensitive details of a disabled person’s life, and the financial records of the businesses that support them, have never been made public.
Two governance documents cover the Taskforce’s arrangements. The first, a Memorandum of Understanding (MOU) dated 25 May 2023, was signed six months after data sharing began. The second, a Data Governance Framework, was finalised in June 2024, eighteen months after data sharing began.
Both these documents have been released in part under Freedom of Information. Both are heavily redacted. The sections covering how data is actually handled — and on what platforms — are not visible.
Freedom *from* information
Of the documents released under Freedom of Information, only one was released in full — an Ethics and Human Oversight Framework. It contains a code of conduct. It does not name any technology vendor. It does not identify what platforms are used to analyse participant data.
The framework governing the ethical handling of your data
does not say who holds it.
Before the Taskforce’s governance framework existed, Services Australia was also in discussions with Palantir Technologies.
Freedom of Information documents show a demonstration in November 2021 and a physical meeting at Services Australia’s offices in June 2022, at which a potential proof of concept was discussed. Services Australia’s own internal assessment of Palantir — released under FOI as LEX 89918 — recorded the following finding: “This system is known to be used by AUSTRAC for managing their vast financial data holdings and is also known to be used by Australian intelligence agencies”.
This is Services Australia’s own documented assessment, not the conclusion of this article. The rules came after the meetings.
The Data Sharing Working Group — named in the official governance diagram released under FOI — has never published its terms of reference, its membership or what data it governs. It is the body responsible for how your information moves between 25 government agencies.
The RoboDebt connection
Two officials inside the NDIA’s integrity division gave evidence at the Robodebt Royal Commission. One wrote the original concept paper for Robodebt at the Department of Human Services in 2014. The other was his supervisor — he signed it off.
The concept paper they wrote became Robodebt — a scheme that raised unlawful debts against 433,000 welfare recipients. People lost their homes. People took their own lives. Neither was prosecuted.
Both now hold senior positions inside the NDIA’s integrity division,
the part of the agency responsible for fraud detection, compliance and the automated systems that will make decisions about participants’ funding.
They were already working there when the Robodebt Royal Commission called them to give evidence about the unlawful automated debt scheme they had built at the Department of Human Services. While they were giving that evidence, the NDIA’s integrity division opened discussions with Palantir Technologies about building the next automated system.
At the time, the Royal Commission had not yet delivered its findings.
The rules that were broken
In April 2023, an email thread opened inside the NDIA’s integrity division titled ‘NDIA/Palantir Progression.’ In May 2023, an NDIA security officer emailed Palantir asking where their mandatory security clearance was.
Under Australian Government rules, this clearance — which verifies that a vendor’s system meets security standards before sensitive government data can enter it — is mandatory, not a recommendation. Palantir did not have it. The engagement with Palantir continued for nine more months.
Palantir received the clearance two and a half years later.
The 22 documents covering the entire engagement were withheld from public release. No Privacy Impact Assessment had been published before this article was written. AUSTRAC has since confirmed that assessments have been conducted but have not been disclosed.
The direction requiring agencies to check whether technology vendors could be compelled by foreign governments to hand over Australian data came into effect in 2024; after the meetings, after the MoU, after the sharing began.
The pattern is consistent: the safeguard that should have applied — didn’t, arrived late, or remains hidden. Not once. Every time.
AUSTRAC responds
AUSTRAC responded to five questions from MWM on 27 August 2026. Here is what was asked, what AUSTRAC said, and what it means.
The NDIA was asked eleven questions. It answered one. AUSTRAC engaged and provided a detailed response to four of five questions. The fifth — the question at the centre of this article — was not addressed.
For the 800,000 Australians on the NDIS, none of this was a choice.
They were never asked whether their data could be shared across 25 government agencies. They were never told what those agencies can see, what platforms process it, or what rules govern it. They still haven’t been.
Australia promised after Robodebt that it had learned its lesson. The lesson, it turns out, was how to build the next automated system — more quietly, with better paperwork, and nobody allowed to look.
The NDIA was contacted for comment and answered one of eleven questions. AUSTRAC responded to our five questions on 27 August 2026. The full response is published above.
Robodebt encore? Palantir lurks as MPs shirk vote, NDIS Bill passes
Claudia Weisenberger is a management consultant with deep experience in pharmaceuticals, hospital transformations, and strategic due diligence across four continents. She combines sharp analysis with hands-on execution.





