Fino

AEPD (Spain) · Date not published

Ministerio de Defensa

About: Accountability, Data principles, Data subject rights, Transparency

FineNo fineViolation found
Regulator
AEPD (Spain)
Decided
Date not published
Country
Spain
Sector
Not given
Regulator’s reference
pd-00055-2026
Fino case number
ND/ES/094
Export as PDF

What happened

The DPA held that automatically refusing to disclose the identity of persons who accessed medical records was incompatible with the enhanced transparency required in the healthcare context, in violation of Article 15 GDPR. It ordered the controller to grant access or provide a properly reasoned refusal.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Accountability
  • Data principles
  • Data subject rights
  • Transparency

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote ND/ES/094.