[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0qE_0TjxdZQgFeeurhrUVhLoJ3wwwAvGRwG_Kj_-fQM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":25,"created_at":26,"published_at":27,"article":28,"tags":32,"podcasts":51},"ecd35bf7-a388-478d-ab8a-fa9bc0366aee","spains-aepd-finds-ministry-of-defence-violated-gdpr-patient-data-access-rights","d8cbf0ac-af83-49f4-a2e5-dec2fc8052e4","Spain's AEPD Finds Ministry of Defence Violated GDPR Patient Data Access Rights","The Spanish Ministry of Defence violated Article 15 of the GDPR by issuing a blanket refusal to disclose which professionals had accessed a patient's health records, without providing any reasoned justification. This case highlights that data subjects have a fundamental right to know who has accessed their sensitive personal data, particularly in healthcare contexts where unauthorized access can cause significant harm. Controllers cannot simply deny access requests — any refusal must be specific, documented, and legally grounded. The ruling underscores that transparency is not optional under GDPR, and that audit logs of data access must be maintained and made available to support these rights. Organizations handling sensitive health data face heightened obligations to demonstrate accountability and traceability of all data processing activities.","**Immediate actions:**\n- Establish a formal Subject Access Request (SAR) process that includes documented procedures for responding to requests about who accessed personal health data.\n- Audit existing access logs to confirm they capture sufficient detail (user identity, timestamp, record accessed) to fulfill Article 15 obligations.\n- Train data protection officers and legal teams to provide reasoned, individualized refusals rather than blanket denials when access cannot be granted.\n\n**Long-term improvements:**\n- Implement role-based access control (RBAC) for all health record systems to ensure every access event is tied to an identifiable, accountable individual.\n- Embed a Data Subject Rights management platform to track, document, and respond to all GDPR access requests within statutory deadlines.\n- Conduct annual GDPR compliance reviews specifically covering Article 15–22 data subject rights obligations across all departments handling sensitive data.\n\n**Detection & Accountability measures:**\n- Deploy immutable audit logging for all access to health records, ensuring logs cannot be altered or deleted without an alert being triggered.\n- Establish automated alerts for bulk or anomalous access patterns to patient health data to support both compliance reporting and breach detection.\n- Schedule quarterly reviews of access log completeness and integrity to verify they can support regulatory inquiries at any time.",[12,13,14,15,16,17,18,19,20,21,22,23,24],"GDPR Article 15 (Right of Access)","GDPR Article 5(1)(a) (Transparency Principle)","GDPR Article 5(2) (Accountability Principle)","GDPR Recital 63 (Access to Personal Data)","NIST SP 800-53 AU-2 (Audit Events)","NIST SP 800-53 AU-9 (Protection of Audit Information)","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","CIS Control 8 (Audit Log Management)","CIS Control 6 (Access Control Management)","ISO\u002FIEC 27001:2022 A.5.33 (Protection of Records)","ISO\u002FIEC 27001:2022 A.8.15 (Logging)","ITIL Service Design — Information Security Management","published","2026-09-10T16:21:15.507378+00:00","2026-09-10T16:21:15.194+00:00",{"id":7,"url":29,"slug":30,"title":31},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=AEPD_(Spain)_-_pd-00055-2026&diff=52997&oldid=0","aepd-spain-pd-00055-2026-456ae1","AEPD (Spain) - pd-00055-2026",[33,39,45],{"id":34,"name":35,"slug":36,"description":37,"color":38},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":40,"name":41,"slug":42,"description":43,"color":44},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":46,"name":47,"slug":48,"description":49,"color":50},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",[]]