Back to all lessons
Awareness Lessons
3 days ago

Spain's AEPD Finds Ministry of Defence Violated GDPR Patient Data Access Rights

The Spanish Ministry of Defence violated Article 15 of the GDPR by issuing a blanket refusal to disclose which professionals had accessed a patient's health records, without providing any reasoned justification. This case highlights that data subjects have a fundamental right to know who has accessed their sensitive personal data, particularly in healthcare contexts where unauthorized access can cause significant harm. Controllers cannot simply deny access requests — any refusal must be specific, documented, and legally grounded. The ruling underscores that transparency is not optional under GDPR, and that audit logs of data access must be maintained and made available to support these rights. Organizations handling sensitive health data face heightened obligations to demonstrate accountability and traceability of all data processing activities.

Tactical Insight

Immediate actions

  • Establish a formal Subject Access Request (SAR) process that includes documented procedures for responding to requests about who accessed personal health data.
  • Audit existing access logs to confirm they capture sufficient detail (user identity, timestamp, record accessed) to fulfill Article 15 obligations.
  • Train data protection officers and legal teams to provide reasoned, individualized refusals rather than blanket denials when access cannot be granted.

Long-term improvements

  • Implement role-based access control (RBAC) for all health record systems to ensure every access event is tied to an identifiable, accountable individual.
  • Embed a Data Subject Rights management platform to track, document, and respond to all GDPR access requests within statutory deadlines.
  • Conduct annual GDPR compliance reviews specifically covering Article 15–22 data subject rights obligations across all departments handling sensitive data.

Detection & Accountability measures

  • Deploy immutable audit logging for all access to health records, ensuring logs cannot be altered or deleted without an alert being triggered.
  • Establish automated alerts for bulk or anomalous access patterns to patient health data to support both compliance reporting and breach detection.
  • Schedule quarterly reviews of access log completeness and integrity to verify they can support regulatory inquiries at any time.