Back to Feed
Privacy FinesSep 10, 2026

AEPD (Spain) - pd-00055-2026

Spain's AEPD upholds complaint against Ministry of Defence for denying patient access to health data.

Summary

Spain's AEPD has ruled that the Ministry of Defence infringed upon Article 15 of the GDPR by refusing to disclose the identities of professionals who accessed a patient's health data. The AEPD ordered the controller to either grant access or provide a properly reasoned refusal, emphasizing that a blanket denial violates transparency principles, especially in the sensitive healthcare context.

Full text

Help AEPD (Spain) - pd-00055-2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 15:14, 10 September 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators307 edits Tag: Decisions [1.0] (No difference) Latest revision as of 15:14, 10 September 2026 AEPD - pd-00055-2026 Authority: AEPD (Spain) Jurisdiction: Spain Relevant Law: Article 5(1)(a) GDPR Article 5(2) GDPR Article 12 GDPR Article 15 GDPR Article 24 GDPR Article 25 GDPR Article 12 LOPDGDDArticle 13 LOPDGDDArticle 18 Law 41/2002 Patient Autonomy Law Type: Complaint Outcome: Upheld Started: 09.10.2025 Decided: Published: 13.09.2026 Fine: n/a Parties: Ministerio de Defensa National Case Number/Name: pd-00055-2026 European Case Law Identifier: n/a Appeal: Unknown Original Language(s): Spanish Original Source: AEPD (in ES) Initial Contributor: bms The DPA held that a blanket refusal to disclose the identity of persons accessing a patient’s health data infringed Article 15 GDPR and ordered the controller to grant access or provide a properly reasoned refusal. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts A public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide an audit of accesses to his medical history, including the date, time, identity of the professional and purpose of each access. The data subject suspected that his health records had been accessed unlawfully. The controller rejected the request, relying on Article 15(4) GDPR and Article 18(3) Law 41/2002. It argued that identifying the professionals who had accessed the medical history would involve disclosing personal data of third parties. Instead, it provided general information concerning the processing of the data subject's personal data. The data subject subsequently reiterated his request and the controller again refused to disclose the identities of the persons who had accessed the records. During the proceedings, the controller carried out an audit of the accesses recorded since 2023. It concluded that the accesses identified had been made for justified purposes by administrative or healthcare personnel and that no unauthorised access had occurred. Regarding older information from 2016 to 2023, the controller stated that retrieving the relevant records from historical databases would require extraordinary technical and financial resources. The data subject argued that access information, including the identity of professionals, had previously been provided to him and maintained that organisational or technical difficulties could not justify limiting his rights. Holding The DPA upheld the complaint and found an infringement of Article 15 GDPR. The DPA first recalled that Article 15 GDPR allows data subjects to obtain access to personal data concerning them and must be interpreted together with the transparency principle under Article 5(1)(a) GDPR and the accountability obligations under Articles 5(2) and 24 GDPR. It also considered that appropriate technical and organisational measures under Article 25 GDPR should enable the traceability and control of access to personal data. Regarding the identity of employees who accessed the data, the DPA referred to CJEU Case C-579/21. It acknowledged that Article 15 GDPR does not generally require controllers to disclose the identity of individual employees who accessed personal data and that providing categories of employees may normally be sufficient. However, their identity may have to be disclosed where this is necessary for the effective exercise of the data subject's rights, subject to the rights and freedoms of those employees. The DPA considered that a stricter transparency standard applies in the healthcare context because health data constitute special categories of personal data. In this regard, it relied on the approach introduced by Regulation (EU) 2025/327 on the European Health Data Space, despite acknowledging that the relevant obligations were not yet applicable. The DPA considered this framework relevant for interpreting the direction of EU law regarding transparency and traceability of access to electronic health data. Accordingly, the DPA held that, as a general rule, the right of access to information concerning access to health data includes the identity of the persons who accessed those data where this is necessary to ensure transparency and enable the data subject to effectively control the lawfulness of the processing. However, this right is not absolute. The controller may restrict disclosure where specific circumstances justify doing so, provided that the restriction follows an appropriate balancing exercise and is properly substantiated and documented under Articles 5(2) and 24 GDPR. The DPA therefore rejected the controller's blanket reliance on Article 15(4) GDPR and Article 18(3) Law 41/2002. It found that automatically excluding disclosure of the identity of all persons who accessed the medical records was incompatible with the enhanced transparency required in the healthcare context. The controller had neither provided the requested information nor demonstrated specific circumstances justifying its refusal. The DPA also found that the controller had failed to fully comply with the access request in accordance with Articles 12 and 15 GDPR. Consequently, it ordered the controller, within ten working days, either to provide the requested access information or to issue a properly reasoned refusal explaining why disclosure was not justified. No administrative fine was imposed. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details. Case No.: EXP202521657 DECISION ON RIGHTS PROCEDURE Having reviewed the complaint filed on October 9, 2025, with this Agency and having carried out the procedural steps provided for in Title VIII of Organic Law Organic Law 3/2018, of December 5, on Data Protection and the Guarantee of Digital Rights (hereinafter, LOPDGDD), the following FACTS FIRST: On October 9, 2025, this Agency received a complaint filed by A.A.A. (hereinafter, the complainant) against the MINISTRY OF DEFENSE (hereinafter, the respondent) for failing to properly uphold the right of access. The complainant states that, on April 7, 2025, he requested an audit of accesses to their medical records, to determine the date, time, identity of the healthcare professional, and purpose of each access; and that, in a letter dated May 9, 2025, the respondent denied the access request pursuant to Article 15.4 of Regulation (EU) 2016/679 (GDPR, hereinafter GDPR) and Article 18.3 of Law 41/2002, of November 14, the basic law governing the Autonomy of the and Rights and Obligations Regarding Clinical Information and Documentation (hereinafter LAP), without providing specific reasons, merely offering a general description of the treatments; and that he suspects unauthorized access to his medical records. The patient submits, among other documents: - A response from the General Health Inspectorate dated April 30, 2025, in which they state: o “Regarding your access request for an audit of accesses to your from the first medical care received to the present, it is not possible to provide such information in accordance with the provisions of Article 15.4 of the GDPR and Article 18.3 of Law 41/2002, of November 14, the basic law regulating patient autonomy and rights and obligations regarding clinical information and documentation .” or “Regarding the exercise of your right of access to our processing of your data, we inform you of the following  Personal data concerning you is being processed.  Attached is the following information

Entities

AEPD (vendor)GDPR (product)LOPDGDD (product)Ministerio de Defensa (vendor)