Spain's AEPD: Blanket Refusal to Disclose Health Data Access Logs Violates GDPR Article 15
The Ministry of Defence violated GDPR Article 15 by issuing a blanket refusal to provide a patient with an audit log of who accessed his medical records, citing third-party privacy without adequate justification. This case highlights that organisations cannot use the privacy of staff members as a shield to deny data subjects their fundamental right of access — particularly in sensitive healthcare contexts. A properly reasoned, case-by-case balancing test is required rather than a categorical policy denial. The ruling reinforces that healthcare data controllers must maintain granular access logs and be prepared to disclose them to data subjects upon request. Failure to do so exposes organisations to regulatory enforcement and erodes trust in how sensitive health information is managed.
Tactical Insight
Immediate actions
- Review and update Subject Access Request (SAR) procedures to ensure audit log data is included in responses where legally permissible.
- Replace any blanket refusal policies with a documented, case-by-case balancing assessment that weighs data subject rights against third-party privacy.
Logging & audit controls
- Implement granular, tamper-evident access logging for all electronic health records, capturing user identity, timestamp, and reason for access.
- Ensure access logs are retained for a period sufficient to satisfy regulatory obligations and respond to retrospective SAR queries.
- Regularly audit access logs for anomalous or unauthorised access patterns and flag them for review.
Long-term improvements
- Train legal, compliance, and HR teams on GDPR Article 15 obligations specific to healthcare data, including the limits of third-party privacy exemptions.
- Establish a formal data subject rights framework with escalation paths, response templates, and documented justification requirements for any refusal.
- Conduct periodic Data Protection Impact Assessments (DPIAs) on health records systems to reassess access control and transparency risks.