AEPD (Spain) · Date not published
Ministerio de Defensa
About: Accountability, Data principles, Data subject rights, Transparency
FineNo fineViolation found
- Regulator
- AEPD (Spain)
- Decided
- Date not published
- Country
- Spain
- Sector
- Not given
- Regulator’s reference
- pd-00055-2026
- Fino case number
- ND/ES/094
What happened
The DPA held that automatically refusing to disclose the identity of persons who accessed medical records was incompatible with the enhanced transparency required in the healthcare context, in violation of Article 15 GDPR. It ordered the controller to grant access or provide a properly reasoned refusal.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Art. 5Principles relating to processing of personal data5(1)(a) · 5(2)Read →
- Art. 12Transparent information, communication and modalities for the exercise of the rights of the data subjectRead →
- Art. 15Right of access by the data subjectRead →
- Art. 24Responsibility of the controllerRead →
- Art. 25Data protection by design and by defaultRead →
- Accountability
- Data principles
- Data subject rights
- Transparency
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote ND/ES/094.