Spain's AEPD Rules Ministry of Defence Violated GDPR by Withholding Health Data Access Logs
The Spanish Ministry of Defence failed to honour a patient's right of access under GDPR Article 15 by refusing to disclose which professionals had viewed their health records, relying on a blanket, unsubstantiated privacy argument about third parties. Health data carries the highest sensitivity classification under GDPR, meaning transparency obligations are stricter, not weaker, when it is involved. The ruling highlights that public bodies cannot simply invoke competing privacy interests without providing a properly reasoned, documented justification. This matters because unchecked access to health records creates risk of both misuse and cover-up, and individuals must be able to verify who has seen their most intimate data.
Tactical Insight
Immediate actions
- Audit all health-record systems to confirm that access logs capture individual user identities, timestamps, and the data accessed.
- Establish a documented, legally reviewed process for responding to GDPR Article 15 access requests within the statutory one-month deadline.
Policy & governance improvements
- Develop a tiered disclosure policy that balances third-party privacy with the data subject's access rights, including criteria for partial redaction rather than blanket refusal.
- Train data protection officers and legal teams on the heightened transparency standard that applies to special-category (health) data under GDPR Articles 9 and 15.
- Assign clear ownership to a designated DPO or privacy team responsible for reviewing and approving all responses to subject access requests involving health data.
Detection & accountability measures
- Implement immutable, tamper-evident audit logging on all electronic health record (EHR) systems so access logs can be reliably produced on request.
- Schedule quarterly internal audits of access log completeness and retention compliance to ensure evidence is available when data subjects exercise their rights.