Persónuvernd (Island) - 2025051308
Icelandic DPA reprimands hospital employee for unauthorized medical record access.
Summary
Iceland's Data Protection Authority (Persónuvernd) has issued a reprimand to a Landspítali Hospital employee for conducting unauthorized searches of a patient's medical records. The employee accessed the records nine times without a legitimate medical treatment basis, violating Articles 6(1) and 9 of the GDPR. The DPA emphasized that while the hospital is the data controller, individual employees are personally responsible for exceeding their access rights.
Full text
Help Persónuvernd (Island) - 2025051308: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Latest revision as of 09:41, 9 October 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators113 edits Tag: Decisions [1.0] (No difference) Latest revision as of 09:41, 9 October 2026 Persónuvernd - 2025051308 Authority: Persónuvernd (Island) Jurisdiction: Iceland Relevant Law: Article 6(1) GDPR Article 9 GDPR Type: Complaint Outcome: Upheld Started: 12.05.2025 Decided: Published: 05.10.2026 Fine: n/a Parties: n/a National Case Number/Name: 2025051308 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Icelandic Original Source: Persónuvernd (in IS) Initial Contributor: sf The DPA issued a reprimand against a hospital employee for conducting unauthorised searches of a data subjects medical records, which constituted personal data processing, without an appropriate legal basis. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The DPA received a complaint from a data subject concerning the unauthorised searches by an employee of Landspitali Hospital (the controller) of her medical records. Particularly, because the employee was not involved in the data subject’s medical treatment. The controller had confirmed that the employee had searched for the data subject’s patient record nine times. The controller’s supervisory board investigated the searches of the data subject’s records and clarified that the employee did not have a legitimate reason to access the medical records. Therefore, they found that the employee exceeded her access rights and thus was in violation of the national law on medical records. Holding The DPA held that despite the controller being in charge of its employees’ searches of medical records, if an employee exceeds their access rights they bear personal responsibility. The DPA found that the employee was responsible for the processing of personal data which consisted of searches of the data subject’s medical records. In this regard, the DPA held that the employee did not provide evidence of an appropriate legal basis, in accordance with Articles 6(1) and 9 GDPR. In light of the foregoing, the DPA issued a reprimand against the employee for a violation of Articles 6(1) and 9 GDPR. Comment Share your comments here! Further Resources Share blogs or news articles here! English Machine Translation of the Decision The decision below is a machine translation of the Icelandic original. Please refer to the Icelandic original for more details. The Data Protection Authority has ruled in a case where a complaint was filed over a Landspítali employee's access to the complainant's medical record. The finding of the Oversight Board for the Landspítali Electronic Patient Record was available, which determined that the employee had not demonstrated a legitimate reason for accessing the complainant's medical record on the occasions in question during the board's investigation of the matter. The Supervisory Board therefore concluded that the employee had violated the provisions of the Act No. 55/2009 on Medical Records and Article 21 of the Act No. 70/1996 on the Rights and Duties of Civil Servants. The supervision of the Personal Data Protection Authority was limited to examining whether the processing of personal data involved in the said searches had been in accordance with the requirements of Act No. 90/2018 on Personal Data Protection and Processing of Personal Data, including whether the searches were necessary for a clearly specified purpose. The Data Protection Authority concluded that the employee's processing of the complainant's personal data was not in compliance with Law No. 90/2018. Since the employee in question exceeded her access rights under Act No. 55/2009, she was herself considered responsible for the processing of personal data involved in the aforementioned searches. The Data Protection Authority issued a reprimand to the employee for violations of the data protection law. Decision on the complaint regarding [B]'s searches in the medical record, in case no. 2025051308: Procedural matters 1. On May 12, 2025, the Personal Data Protection Authority received a complaint from [A] (hereinafter the complainant) regarding unauthorized searches of her medical record by [B], an employee of Landspítali. The grounds for the complaint state that the hospital's supervisory board confirmed that [B] had looked up the complainant's name in her medical record a specified number of times.2. By letter from the Personal Data Authority to Landspítali, dated On April 21, 2026, the agency requested specific information and invited the hospital to comment on the complaint. Responses from Landspítali were received in a letter dated July of that year. The complainant was given the opportunity to submit comments on Landspítali's responses in a letter dated July 10 of that year, and these were received by email on August 5 of that year. In a letter from the Personal Data Authority to [B], dated On July 10, 2018, the Data Protection Authority requested specific information and offered it the opportunity to comment on the complaint. No response was received from [B] within the specified response period. In a letter from the Data Protection Authority to Landspítali, dated On August 21 of that year, the Authority requested a copy of the decision of the Electronic Patient Record Supervisory Board and an overview of [B]'s viewings of the complainant's medical record, which had been referenced in the hospital's response letter. The requested documents were received on September 1, 2021.3. All of the above-mentioned documents have been taken into account in the resolution of the case, although not all are specifically detailed in the following ruling. Dispute4. The dispute concerns the legality of the searches [B] conducted in the complainant's medical record on December 23, 2021, April 22, and December 6, 2022, July 31, 2023, and July 23, 2024, in Landspítali's electronic health record systems. Events of the Case and Available Evidence 5. A summary of the searches in the complainant's medical record shows nine searches performed by [B] in the Saga medical record system of Landspítali. Two searches were conducted on December 23, 2021, April 22, 2022, December 6, 2022, and July 31, 2023, and one search on July 23, 2024.6. The Oversight Committee for the Electronic Patient Record at Landspítali reviewed the aforementioned queries following a complaint from the complainant in the fall of 2024. According to the committee's conclusion, dated December 30 of that year, [B] failed to demonstrate during the investigation that she had a legitimate reason to access the complainant's medical record on the occasions in question, and therefore [B] was found to have violated the provisions of Act No. 55/2009 on Medical Records and Article 21. para. of the Civil Service Act No. 70/1996. [B]'s conduct was reported to the Office of the National Superintendent of Health and the Data Protection Authority, in accordance with paragraphs 2 and 3 of Article 22 of the Act No. 55/2009.The Parties' Positions. The Complainant's Position7. The complainant's position is that [B] had no legitimate reason to access and review her medical record, as [B] was not involved in her treatment in any way. [...]. Position of Landspítali8. Landspítali refers to the conclusion of the Supervisory Board for Electronic Patient Records, see discussion in paragraph 6. Since [B] exceeded her access privileges under the Act on Medical Records No. 55/2009 and the hospital's regulations, she herself is responsible for the searches in the complainant's medical record. In this regard, Landspítalinn refers to a decision by the Data Protection Authority in case no. 2025020534, which concerned similar searches by the same emplo