Back to Feed
PolicySep 15, 2026

AEPD (Spain) - pd-00055-2026

Spanish DPA orders Ministry of Defence to disclose identities of healthcare data accessors.

Summary

The Spanish Data Protection Agency (AEPD) ruled that the Ministry of Defence infringed Article 15 of GDPR by refusing to disclose the identities of professionals who accessed a patient's health data. The AEPD emphasized a stricter transparency standard for health data and ordered the Ministry to either provide the requested access logs or a properly reasoned refusal, rejecting the Ministry's blanket reliance on privacy concerns for third parties.

Full text

Help AEPD (Spain) - pd-00055-2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 15:14, 10 September 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators309 edits Tag: Decisions [1.0] Latest revision as of 16:19, 15 September 2026 view source Ls (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators421 editsTag: Visual edit (One intermediate revision by the same user not shown)Line 116: Line 116: }}}} The DPA held that a blanket refusal to disclose the identity of persons accessing a patient’s health data infringed [[Article 15 GDPR|Article 15 GDPR]] and ordered the controller to grant access or provide a properly reasoned refusal.The DPA held that automatically refusing to disclose the identity of persons who accessed medical records was incompatible with the enhanced transparency required in the healthcare context, in violation of [[Article 15 GDPR]]. It ordered the controller to grant access or provide a properly reasoned refusal. == English Summary ==== English Summary == === Facts ====== Facts === A public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide an audit of accesses to his medical history, including the date, time, identity of the professional and purpose of each access. The data subject suspected that his health records had been accessed unlawfully.Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of accesses to his medical history, including the date, time, identity of the professional and purpose of each access. The controller rejected the request, relying on [[Article 15 GDPR|Article 15(4) GDPR]] and Article 18(3) Law 41/2002. It argued that identifying the professionals who had accessed the medical history would involve disclosing personal data of third parties. Instead, it provided general information concerning the processing of the data subject's personal data. The data subject subsequently reiterated his request and the controller again refused to disclose the identities of the persons who had accessed the records. The controller rejected the request, relying on [[Article 15 GDPR|Article 15(4) GDPR]] and Article 18(3) Law 41/2002. It argued that identifying the professionals who had accessed the medical history would involve disclosing personal data of third parties. Instead, it provided general information concerning the processing of the data subject's personal data. The data subject subsequently reiterated his request and the controller again refused to disclose the identities of the persons who had accessed the records. Line 128: Line 128: The data subject argued that access information, including the identity of professionals, had previously been provided to him and maintained that organisational or technical difficulties could not justify limiting his rights.The data subject argued that access information, including the identity of professionals, had previously been provided to him and maintained that organisational or technical difficulties could not justify limiting his rights. === Holding ====== Holding === The DPA upheld the complaint and found an infringement of [[Article 15 GDPR|Article 15 GDPR]].The DPA upheld the complaint and found an infringement of [[Article 15 GDPR]]. The DPA first recalled that [[Article 15 GDPR|Article 15 GDPR]] allows data subjects to obtain access to personal data concerning them and must be interpreted together with the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and the accountability obligations under Articles 5(2) and 24 GDPR. It also considered that appropriate technical and organisational measures under [[Article 25 GDPR|Article 25 GDPR]] should enable the traceability and control of access to personal data.The DPA first recalled that [[Article 15 GDPR]] allows data subjects to obtain access to personal data concerning them and must be interpreted together with the transparency principle under [[Article 5 GDPR|Article 5(1)(a) GDPR]] and the accountability obligations under Articles 5(2) and 24 GDPR. It also considered that appropriate technical and organisational measures under [[Article 25 GDPR]] should enable the traceability and control of access to personal data. Regarding the identity of employees who accessed the data, the DPA referred to CJEU Case C-579/21. It acknowledged that [[Article 15 GDPR|Article 15 GDPR]] does not generally require controllers to disclose the identity of individual employees who accessed personal data and that providing categories of employees may normally be sufficient. However, their identity may have to be disclosed where this is necessary for the effective exercise of the data subject's rights, subject to the rights and freedoms of those employees.Regarding the identity of employees who accessed the data, the DPA referred to CJEU Case C-579/21. It acknowledged that [[Article 15 GDPR]] does not generally require controllers to disclose the identity of individual employees who accessed personal data and that providing categories of employees may normally be sufficient. However, their identity may have to be disclosed where this is necessary for the effective exercise of the data subject's rights, subject to the rights and freedoms of those employees. The DPA considered that a stricter transparency standard applies in the healthcare context because health data constitute special categories of personal data. In this regard, it relied on the approach introduced by Regulation (EU) 2025/327 on the European Health Data Space, despite acknowledging that the relevant obligations were not yet applicable. The DPA considered this framework relevant for interpreting the direction of EU law regarding transparency and traceability of access to electronic health data.The DPA considered that a stricter transparency standard applies in the healthcare context because health data constitute special categories of personal data. It referred in that regard to the approach introduced by the not yet applicable Regulation (EU) 2025/327 on the European Health Data Space. Accordingly, the DPA held that, as a general rule, the right of access to information concerning access to health data includes the identity of the persons who accessed those data where this is necessary to ensure transparency and enable the data subject to effectively control the lawfulness of the processing. However, this right is not absolute. The controller may restrict disclosure where specific circumstances justify doing so, provided that the restriction follows an appropriate balancing exercise and is properly substantiated and documented under Articles 5(2) and 24 GDPR. Accordingly, the DPA held that, as a general rule, the right of access to information concerning access to health data includes the identity of the persons who accessed those data where this is necessary to ensure transparency and enable the data subject to effectively control the lawfulness of the processing. However, this right is not absolute. The controller may restrict disclosure where proportionate and under specific circumstances. The DPA therefore rejected the controller's blanket reliance on [[Article 15 GDPR|Article 15(4) GDPR]] and Article 18(3) Law 41/2002. It found that automatically excluding disclosure of the identity of all persons who accessed the medical records was incompatible with the enhanced transparency required in the healthcare context. The controller had neither provided the requested information nor demonstrated specific circumstances justifying its refusal.The DPA therefore rejected the controller's blanket reliance on [[Article 15 GDPR|Article 15(4) GDPR]] and Article 18(3) Law 41/2002. It found that automatically excluding disclosure of the identity of all persons who

Entities

Ministry of Defence (vendor)