Back to Feed
PolicySep 15, 2026

AEPD (Spain) - pd-00055-2026

Spain's AEPD orders Ministry of Defence to disclose identities of health data accessors.

Summary

Spain's AEPD ruled that a blanket refusal to disclose the identities of professionals accessing a patient's health data infringes GDPR Article 15. The data subject, a public civil servant, requested an audit of accesses to his medical history from the Ministry of Defence, suspecting unlawful access. The Ministry refused, citing third-party data privacy, but the AEPD ordered them to grant access or provide a properly reasoned refusal, emphasizing a stricter transparency standard in healthcare.

Full text

Help AEPD (Spain) - pd-00055-2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 15:14, 10 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators309 edits Tag: Decisions [1.0] Latest revision as of 14:52, 15 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators415 editsTag: Visual edit Line 116: Line 116: }}}} The DPA held that a blanket refusal to disclose the identity of persons accessing a patient’s health data infringed [[Article 15 GDPR|Article 15 GDPR]] and ordered the controller to grant access or provide a properly reasoned refusal.The DPA held that a blanket refusal to disclose the identity of persons accessing a patient’s health data infringed [[Article 15 GDPR]] and ordered the controller to grant access or provide a properly reasoned refusal. == English Summary ==== English Summary == === Facts ====== Facts === A public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide an audit of accesses to his medical history, including the date, time, identity of the professional and purpose of each access. The data subject suspected that his health records had been accessed unlawfully.Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of accesses to his medical history, including the date, time, identity of the professional and purpose of each access. The controller rejected the request, relying on [[Article 15 GDPR|Article 15(4) GDPR]] and Article 18(3) Law 41/2002. It argued that identifying the professionals who had accessed the medical history would involve disclosing personal data of third parties. Instead, it provided general information concerning the processing of the data subject's personal data. The data subject subsequently reiterated his request and the controller again refused to disclose the identities of the persons who had accessed the records. The controller rejected the request, relying on [[Article 15 GDPR|Article 15(4) GDPR]] and Article 18(3) Law 41/2002. It argued that identifying the professionals who had accessed the medical history would involve disclosing personal data of third parties. Instead, it provided general information concerning the processing of the data subject's personal data. The data subject subsequently reiterated his request and the controller again refused to disclose the identities of the persons who had accessed the records. Line 131: Line 131: === Holding ====== Holding === The DPA upheld the complaint and found an infringement of [[Article 15 GDPR|Article 15 GDPR]].The DPA upheld the complaint and found an infringement of [[Article 15 GDPR]]. The DPA first recalled that [[Article 15 GDPR|Article 15 GDPR]] allows data subjects to obtain access to personal data concerning them and must be interpreted together with the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and the accountability obligations under Articles 5(2) and 24 GDPR. It also considered that appropriate technical and organisational measures under [[Article 25 GDPR|Article 25 GDPR]] should enable the traceability and control of access to personal data.The DPA first recalled that [[Article 15 GDPR]] allows data subjects to obtain access to personal data concerning them and must be interpreted together with the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and the accountability obligations under Articles 5(2) and 24 GDPR. It also considered that appropriate technical and organisational measures under [[Article 25 GDPR]] should enable the traceability and control of access to personal data. Regarding the identity of employees who accessed the data, the DPA referred to CJEU Case C-579/21. It acknowledged that [[Article 15 GDPR|Article 15 GDPR]] does not generally require controllers to disclose the identity of individual employees who accessed personal data and that providing categories of employees may normally be sufficient. However, their identity may have to be disclosed where this is necessary for the effective exercise of the data subject's rights, subject to the rights and freedoms of those employees.Regarding the identity of employees who accessed the data, the DPA referred to CJEU Case C-579/21. It acknowledged that [[Article 15 GDPR]] does not generally require controllers to disclose the identity of individual employees who accessed personal data and that providing categories of employees may normally be sufficient. However, their identity may have to be disclosed where this is necessary for the effective exercise of the data subject's rights, subject to the rights and freedoms of those employees. The DPA considered that a stricter transparency standard applies in the healthcare context because health data constitute special categories of personal data. In this regard, it relied on the approach introduced by Regulation (EU) 2025/327 on the European Health Data Space, despite acknowledging that the relevant obligations were not yet applicable. The DPA considered this framework relevant for interpreting the direction of EU law regarding transparency and traceability of access to electronic health data.The DPA considered that a stricter transparency standard applies in the healthcare context because health data constitute special categories of personal data. In this regard, it relied on the approach introduced by Regulation (EU) 2025/327 on the European Health Data Space, despite acknowledging that the relevant obligations were not yet applicable. The DPA considered this framework relevant for interpreting the direction of EU law regarding transparency and traceability of access to electronic health data. Latest revision as of 14:52, 15 September 2026 AEPD - pd-00055-2026 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(a) GDPR Article 5(2) GDPR Article 12 GDPR Article 15 GDPR Article 24 GDPR Article 25 GDPR Article 12 LOPDGDDArticle 13 LOPDGDDArticle 18 Law 41/2002 Patient Autonomy Law Type: Complaint Outcome: Upheld Started: 09.10.2025 Decided: Published: 13.09.2026 Fine: n/a Parties: Ministerio de Defensa National Case Number/Name: pd-00055-2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA held that a blanket refusal to disclose the identity of persons accessing a patient’s health data infringed Article 15 GDPR and ordered the controller to grant access or provide a properly reasoned refusal. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of accesses to his medical history, including the date, time, identity of the professional and purpose of each access. The controller rejected the request, relying on Article 15(4) GDPR and Article 18(3) Law 41/2002. It argued that identifying the professionals who had accessed the medical history would involve disclosing personal data of third parties. Instead, it provided general information concerning the processing of the data subject's personal data. The data subject subsequently reiterated his request and the controller again refused to disclose the identities of the persons who had accessed the records. During the proceedings, the controller carried out an audit of the accesses recorded since 2023. It concluded that the accesses identified had been made for justified purposes by administrative or healthcare personnel and that no unauthorised access had occurred. Regarding older information from 2016 to 2023, the control

Entities

Ministry of Defence (vendor)GDPR (product)