Skip to content
Case Law · Supreme Administrative Court EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

NSS - 1 As 183/2023-62

Supreme Administrative Court
Summary

Facts — OAKS Consulting s.r.o. (the company) provided consulting services concerning market access conditions for medicinal products and medical devices. Pursuant to the Czech Act on Free Access to Information, it requested information from the General Health Insurance Company of the Czech Republic concerning the treatment of patients with iron deficiency and related conditions for the period from 1 January 2010 to 31 October 2017. The request covered 183 types of diagnoses, 18 types of medical procedures, 96 DRG codes and 13 types of medications. The company stated that it wished to analyse how specific diagnoses were treated, the number of patients treated, and the frequency of related medical procedures, in order to compare clinical practice against the relevant theoretical background. The public health insurer rejected the request on the grounds that granting it would require the creation of new information. Following an appeal by the company, the Prague Municipal Court overturned the decision. The public health insurer provided then the company with five separate tables regarding the diagnoses, diagnoses in conjunction with medical procedures, medical procedures, the DRG codes and prescribed medications. It aggregated the parameters of the provided data as follows: five-year age groups, dates were given only at the monthly level, and healthcare providers were classified into broad geographic regions. However, it refused to add a unique random identifier which would allow linking the individual records and tables pertaining to the same patient. The public health insurer considered that providing the code would result in the disclosure of special categories of personal data. The company lodged an administrative appeal with the Czech DPA (UOOU), which rejected it. The company filed another appeal with the Municipal Court of Prague, which dismissed the appeal. It ruled that the combination of factors such as gender, year of birth, the time and place of care, diagnoses, medications, and medical procedures could, with the addition of other information, lead to the identification of specific patients. According to the court, the random identifier would result in pseudonymisation rather than anonymisation, so the information would remain personal data pursuant to Article 4 (1) GDPR. The Municipal Court also relied on modern technical capabilities for linking different sources and on the availability of a large volume of information in the media and on social media. It cited the CJEU’s decision in the Breyer case, C-582/14, according to which in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, both by the controller and by any other person, to identify that person. It did not follow the approach taken by the General Court in Case T-557/20, SRB v. EDPS, which the company had cited. It ruled that the data were pseudonymised and that the requested information could not be disclosed in its entirety. The company filed a cassation appeal with the Supreme Administrative Court, arguing that the information had been anonymised. It alleged that the addition of a random code with no independent meaning would not alter their anonymous nature. It claimed that the Municipal Court had not explained what specific additional information could be used to identify the patients and had relied on hypothetical scenarios. The company stated that it was objectively impossible to obtain such data through other requests in a detailed and non-aggregated form. It also argued that iron deficiency was not a rare disease, but was associated with a large number of patients and various conditions and that the data had undergone both randomisation and generalisation so the risk of identification was therefore low. Finally, the company emphasized that the tables without the random identifier could not be used effectively for the intended analysis. It further argued that the DPA and the Municipal Court had not adequately balanced the right of access to information against the right to the protection of personal data. The DPA argued that the random identifier constituted personal data when considered in conjunction with the health data to which it would be linked. It stated that the concept of personal data was not limited to information that directly identifies an individual nor did it require that all necessary additional information be held by the same entity. Replacing direct identifiers with a code did not anonymise the data, but made it pseudonymised. Moreover, it argued that certain categories contained a relatively small number of records and that combining them with other data could make it possible to select and identify a specific insured person and their treatment history. It further argued that, even if identifiability was relative, it should be assessed in relation to all potential information applicants and their ability to obtain contextual information. The Supreme Administrative Court stayed the proceedings in the case pending the CJEU’s decision in Case C-413/23 P, EDPS v. SRB. After the judgment was issued, the company argued that whether the data were pseudonymised or anonymised should be assessed in relation to the specific recipient of the data and the means that it could reasonably use. It stated that it did not have any means of re-identification and that only specific and practically available cross-referencing possibilities should be taken into account. Holding — The court relied on Case C-413/23 and noted that pseudonymised data UNDER Article 4(5) GDPR does not automatically constitute personal data in relation to every person. Therefore, it examined whether the company had lawful and reasonably available means to identify the patients directly or indirectly. The court found that the tables, without the random identifier, did not allow for the identification of specific insured individuals. It held that the requested random identifier would link the records from the different tables and allow for the aggregation of information on the diagnoses, medical procedures, hospitalizations, and medications for the same patient during the eight- year period. Certain combinations of these data, along with age group, gender, and region, could be unique and allow for the identification of patients using information from public sources. It pointed out that although iron deficiency was a very common diagnosis and some tables contained a very large number of entries, other categories were not sufficiently generalised. According to the court, in certain cases, such as rare diseases, unusual treatment combinations, or particularly young or old age, knowing even a few details about a person could make it possible to identify the corresponding record. The risk was not negligible, given that information about a person’s age, gender, hospitalization, diagnosis, or treatment could be available in the media or on social media. Consequently, the court held that adding the random identifier to the data already provided would render the linked dataset personal data under Article 4(1) GDPR, including health data falling under Article 9 GDPR. The court clarified that classifying the information as personal data was not sufficient in itself to reject the request. It noted that the right of access to the information must also be balanced against patients’ right to privacy through an assessment of suitability, necessity and proportionality. It determined that the decision not to provide the random identifier was appropriate for the protection of privacy, because without it, it was impossible to link the tables and identify individual patients. It was also deemed necessary because the company insisted on receiving that specific code along with the existing tables and there was no other procedure that would constitute a lesser infringement of its right to information. The court also recognized the public interest in accessing information related to the operation of the healthcare system, but ruled that this did not outweigh the need to protect the detailed health data of potentially hundreds of thousands of insured individuals. It concluded that the refusal to provide the code was therefore proportionate. The Supreme Administrative Court therefore upheld the Municipal Court’s ruling, but partially corrected its reasoning regarding the relative nature of identifiability and the need to conduct a proportionality review. It dismissed the appeal.

Full text

Data Protection: Pseudonymized Data; Identifiability of the Data Subject Regarding Article 4(1) and (5) of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter referred to as “GDPR” Pseudonymized data [Article 4(5) of Regulation (EU) 2016/679 of the European Parliament and of the Council (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data] need not automatically constitute personal data in every case and in relation to every person (Article 4(1) thereof). The determination of whether a data subject is identifiable—and whether information about that person therefore constitutes personal data—may vary depending on the person in relation to whom the data subject’s identifiability is assessed. (According to the judgment of the Supreme Administrative Court dated October 9, 2025, Ref. No. 1 As 183/2023-62) Case law: No. 4064/2020 Coll. NSS, No. 4396/2022 Coll. NSS; Constitutional Court rulings No. 223/2010 Coll. ÚS (Case No. I. ÚS 517/10), No. 40/2023 Coll. and No. 56/2023 Coll. ÚS (Case No. III. ÚS 836/21); Judgments of the Court of Justice dated October 19, 2016, Breyer (C-582/14), dated March 7, 2024, IAB Europe (C-604/22), and dated September 4, 2025, European Data Protection Supervisor v. SRB (C-413/23). Case: OAKS Consulting, s. r. o., v. the Office for Personal Data Protection, with the participation of the General Health Insurance Company of the Czech Republic, regarding the provision of information, on the plaintiff’s cassation appeal. In this case, the Supreme Administrative Court addressed the question of whether pseudonymized data (data on the medical treatment of individuals with iron deficiency, where each individual was assigned a meaningless identifier) constitute personal data in relation to the plaintiff and whether the refusal to provide the personal data requested by the plaintiff under Act No. 106/1999 Coll., on Free Access to Information (hereinafter the “Information Act”), was proportionate. The plaintiff provides consulting services regarding the conditions for placing medicinal products and medical devices on the market. In her request for information, she asked the party to the proceedings—the General Health Insurance Company of the Czech Republic (hereinafter “VZP”) —as the obligated entity—to provide information on the treatment of patients with iron deficiency and primary diseases for which treatment with iron-containing medicinal products is indicated, for the period from January 1, 2010, to October 31, 2017 (covering 13 types of medicinal products, 18 types of medical procedures, 96 DRG codes, and 183 types of diagnoses). According to the court, the purpose of the data collection was to conduct an analysis aimed at verifying the methods of treating specific diagnoses, determining the number of patients treated with medicinal products, and assessing the frequency of reported procedures associated with a diagnosis of iron deficiency. The plaintiff would thus be able to compare and evaluate the outcomes of clinical practice against theoretical principles. VZP initially refused to provide the information in its entirety, as it believed that doing so would constitute the creation of new information. The plaintiff filed a lawsuit challenging the decision of the VZP director, which upheld the first-instance decision. The Municipal Court in Prague, in its judgment dated July 1, 2021, Ref. No. 10 A 120/2018-67, granted her request and overturned the decision on the grounds that it was not subject to review. VZP therefore subsequently provided the plaintiff with separate tables containing information on: (1) diagnoses, (2) diagnoses and procedures, (3) procedures, (4) DRG codes, and (5) prescribed medications. In these tables, it aggregated the parameters of the provided data into the following groups: grouping patients into five-year age groups; grouping calendar data (provision of medical procedures, etc.) at the calendar-month level; and aggregating healthcare providers by the regions of Bohemia, Moravia, and Silesia. It did not grant the plaintiff’s request for the provision of an insured person’s identifier, which would have allowed the linking of individual tables. In its first-instance decision, the court partially rejected the plaintiff’s request, as this portion concerns a special category of personal data (Section 15(1) and Section 8a of the Information Act in conjunction with Article 9 of the GDPR). By a decision dated October 15, 2021, the defendant dismissed the plaintiff’s appeal. The plaintiff challenged this decision by filing a lawsuit, which the Municipal Court dismissed by judgment dated August 14, 2023, Ref. No. 14 A 230/2021-67. The court stated that it cannot be ruled out that certain individuals could be identified based on information provided under an identifier regarding their diagnosis, treatments, and procedures performed. The combination of gender, year of birth, date of care provided, and the name of the healthcare facility where the care was provided constitutes a set of data that, when combined with additional information, could lead to the identification of the person whose health condition is in question. Assigning a meaningless identifier (a unique random number that does not carry any additional information about the person to whom it is assigned) to individual patients does not result in anonymization but only in pseudonymization, so that the information mentioned above remains personal data pursuant to Article 4(1) of the GDPR. Given the current technological capabilities for linking information from various processors and the volume of information obtainable from the media and social networks, the Municipal Court held that the possibility of identifying individuals cannot be ruled out. In this regard, it referred to the judgment of the Court of Justice dated October 19, 2016, Breyer, C-582/14, in which the Court of Justice stated that “in order to determine whether a person is identifiable, account must be taken of all the means that could reasonably be used, either by the controller or by any other person, to identify that person”. In contrast, the Municipal Court did not agree with the application of the General Court’s judgment of April 26, 2023, SRB v. European Data Protection Supervisor, T-557/20, as proposed by the plaintiff. The Municipal Court did not examine in detail who might be able to identify individual persons. It concluded that the data in question was pseudonymized and, therefore, the requested information could not be provided in its entirety. The plaintiff (appellant) challenged the Municipal Court’s judgment by filing a cassation appeal. First, she disagreed with the Municipal Court’s conclusion that the requested information constituted personal data and was pseudonymized. The Municipal Court underestimated the difficulty of identifying a specific individual based on the requested information. Nor did it sufficiently take into account the fact that VZP itself had aggregated the requested data across numerous parameters into larger groups, after which the identification of individual insured persons is no longer possible. Even adding a meaningless identifier to this data cannot alter the anonymous nature of the data. The Municipal Court stated that it cannot be ruled out that the addition of further information could cause the requested data to lose its anonymous nature; however, according to the complainant, it did not specify how, in its opinion, the addition of further information could lead to the identifiability of a specific data subject. This is, however, a hypothetical consideration, since it is objectively impossible—even on the basis of other requests for information—to obtain similar data in a non-aggregated form, or at a level of detail that, when combined with the requested data, would allow for the identification of individual data subjects. VZP and the Institute of Health Information and Statistics of the Czech Republic are the only obligated entities from which the requested data can be obtained. The complainant therefore disagreed with the Municipal Court’s conclusion that the identification of a data subject could result from linking data from “various processors.” Nor was this a rare disease affecting only a handful of patients. Iron deficiency accompanies many different diseases (e.g., gastrointestinal diseases, various types of cancer, hemorrhoids), chronic conditions, or specific circumstances (e.g., heavy menstruation, pregnancy, major surgery). In individual regions, there are hundreds of patients being treated for iron deficiency. It is impossible to identify them, whether or not an identifier is attached. According to the complainant, this is also confirmed by the Constitutional Court’s ruling of April 11, 2023, Case No. III. ÚS 836/21, No. 56/2023 Coll. ÚS. According to the complainant, it also follows from this ruling that the obligated entity cannot use a statutory exemption across the board as a reason for refusing to provide information. Both the defendant and the municipal court should have weighed the right to information against the protection of personal data and properly justified their decision, which they failed to do. A specific patient cannot be identified from such a large dataset also because, upon the provision of a random identifier, the personal data would already have been anonymized through two processes: randomization (data unnecessary for the result, such as a name and birth number, are replaced with random data without losing the informational value of the other data) and generalization (the number of data subjects to whom a certain attribute could be assigned is significantly increased). Such a low risk of identification therefore cannot constitute grounds for refusing to provide the information. Finally, according to the complainant, the Municipal Court incorrectly assessed the General Court’s judgment in Case T-557/20 as irrelevant to this case, even though, in her view, it was essential for assessing whether the data were pseudonymized or anonymized. The complainant summarized that the provision of data without a meaningless identifier is pointless for her, as she lacks the ability to link the individual tables and draw meaningful conclusions from them. Information provided in this manner does not allow her to make effective use of it, as required by Section 4a(3) of the Information Act. The defendant stated that the meaningless identifiers of insured persons are undoubtedly personal data in this context, even though they do not in themselves reveal anything about the data subject’s privacy. Personal data, in fact, encompasses all information relating to an identified or identifiable natural person, not merely information that leads to the direct identification of the natural person to whom the information pertains or relates. According to the defendant, the use of the term “indirectly” in Article 4(1) of the GDPR means that, for information to be classified as personal data, it is not necessary for it to allow the data subject to be identified on its own. According to the Court of Justice’s judgment in Breyer, it is also not required that all information enabling the identification of the data subject be in the possession of a single person. Even if the opposite conclusion were adopted—that the concept of personal data is relative—this relativity should be examined in relation to the set of all potential requesters of information and their right to request contextual information. The use of any code assigned to a specific natural person (e.g., in place of a social security number) does not render the personal data—or the set of personal data—anonymous. It merely renders the associated personal data pseudonymized, which means that additional information—stored separately from the set of personal data in question—is required to identify or uncover commonly used identifying information. According to the defendant, the “anonymization” of the dataset was problematic because the number of packages of medicinal products is very low. The dataset was therefore sufficient, when combined with other data, to lead to the selection and identification of a specific insured person and their treatment process. In the defendant’s view, the decisive factor was that information could be requested repeatedly from the obligated entities, at varying levels of “granularity” (level of detail), in various structures and analytical formats, and that the prior fulfillment of one applicant’s request must not prejudice the assessment of another applicant’s request. Combining the information obtained in this manner results in a substantially more comprehensive database with greater “granularity.” The Supreme Administrative Court, in its ruling dated June 17, 2024, Ref. No. 1 As 183/2023-47, stayed the proceedings because it found that proceedings were pending before the Court of Justice on a legal issue that would be decisive for the further assessment of the cassation appeal. According to the judgment in Case T-557/20, the General Court held that pseudonymized data transferred to a data recipient will not be considered personal data if the recipient lacks the means to re-identify the data subject. An appeal was filed against this judgment, on the basis of which the Court of Justice was to address the question of whether, when assessing the identifiability of a data subject, it is necessary to examine whether the person in relation to whom the possibility of identifying data subjects is being assessed has legal and feasible means at their disposal that would allow them to access additional information necessary to re-identify the data subject. In its judgment of September 4, 2025, European Data Protection Supervisor v. SRB, C-413/23 (hereinafter the “SRB judgment”), the Court of Justice upheld the General Court’s aforementioned opinion. The Supreme Administrative Court therefore, by order dated September 9, 2025, Ref. No. 1 As 183/2025-49, decided to continue the proceedings and invited the parties and the intervenor to submit their comments on the Court of Justice’s judgment. In her statement, the complainant emphasized that the Court of Justice assesses whether the data is pseudonymized or anonymized, depending on whether a given person has at their disposal means that can reasonably be expected to be used for the direct or indirect identification of a specific natural person. However, the complainant did not have any means that would allow for the re-identification of natural persons. The Municipal Court assessed this issue incorrectly; more precisely, it refused to properly consider the complainant’s options. The Municipal Court based its conclusion on a hypothetical scenario, whereas, according to the complainant, only specific means—such as cross-referencing with other data—should have been taken into account. The Supreme Administrative Court dismissed the cassation complaint. From the reasoning: (…) III.b Content of the Requested or Provided Information [28] The complainant received data on the treatment of patients with iron deficiency and primary diseases for which treatment with iron-containing medicinal products is indicated, covering a period of eight years. This consists of five separate tables: - a list of insured persons with one of 183 types of diagnoses (the “Diagnoses” table); - a list of insured persons with the listed diagnoses for whom a medical procedure was performed (the “Diagnoses-Procedures” table); - a list of insured persons for whom one of 18 types of procedures was performed (the “Procedures” table); - a list of insured persons with one of 96 DRG codes (DRG table); and - a list of prescriptions or separately billed medicinal products and medical devices, if they were one of 13 types (LP table). The tables list the following information for individual insured persons, among other things: - gender; - year of birth (aggregated into five-year ranges, e.g., 30–34); - the healthcare provider’s specialty (e.g., “801 – clinical biochemistry”) and the location where the service was provided (aggregated by the regions of Bohemia, Moravia, and Silesia); - the date the care was provided (aggregated by month, e.g., January 2010); and - the cost of care. [29] The issue now is whether the data in the tables could constitute personal data if VZP were to also provide the complainant with an insured person’s identifier that would link the data rows in these tables (except for the “LP” table). III.c Legal Framework and Case Law of the Court of Justice [30] Pursuant to Section 8a of the Information Act, an obligated entity may provide information concerning personality, expressions of a personal nature, the privacy of a natural person, and personal data only in accordance with the legal regulations governing their protection. [31] Personal data means any information relating to an identified or identifiable natural person. According to Article 4(1) of the GDPR, an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. [32] Pseudonymization, according to Article 4(5) of the GDPR, is the processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that it is not associated with an identified or identifiable natural person. [33] It is true that the Supreme Administrative Court has thus far held a view based on the conclusions of the Court of Justice’s judgment in the Breyer case, namely that whether the definition of personal data is met is not assessed from the subjective perspective of the controller or processor who has the data at that moment. According to that view, information constituted personal data if there were “any persons or authorities who could identify the data subject on the basis of that information (in conjunction with supplementary data available to them)” (see the judgments of the Supreme Administrative Court dated August 24, 2023, Ref. No. 3 As 76/2022-54, para. 17; or dated August 13, 2020, Ref. No. 1 As 387/2019-56, No. 4064/2020 Coll. of the Supreme Administrative Court, para. 25). In light of this interpretation, the information whose disclosure the complainant sought could constitute personal data, as the individuals could be identified retrospectively. Although the complainant would receive only a meaningless identifier linking the individual tables, VZP could possess information that would allow the meaningless identifier to be retroactively linked to specific individuals. [34] By contrast, in its judgment in the SRB case, the Court of Justice newly held that pseudonymized data need not automatically constitute personal data in every case and in relation to every individual, “since, depending on the circumstances of the case at hand, pseudonymization may effectively prevent persons other than the controller from identifying the data subject in such a way that the data subject is not, or is no longer, identifiable to them” (paragraph 86 of the cited judgment). This means that it depends on the individual in relation to whom identifiability is assessed (paragraphs 71–75 and 82 ibid.). Indeed, if technical and organizational measures are in place that can prevent the data relating to the data subject from being linked to those individuals, such pseudonymized data may cease to be personal data (paragraph 75, ibid.). [35] Guidance on assessing whether data constitutes personal data for a specific individual is provided, inter alia, by the third sentence of recital 26 of the GDPR, according to which, when determining whether a natural person is identifiable, […] account should be taken of all means […] that a controller or another person might reasonably be expected to use to identify that natural person, either directly or indirectly. The Court of Justice has held that “other persons” are only those who have or may have access to the means that can reasonably be expected to be used to identify the data subject (judgment in SRB, para. 87). III.d Is the requested information regarding the complainant personal data? [36] In the contested judgment, the Municipal Court concluded that the information in question constitutes personal data, based on the case law of the Court of Justice, which was partially superseded during the proceedings before the Court of Cassation; and it is therefore necessary to examine whether the Municipal Court’s view still holds up even after the Court of Justice’s judgment in the SRB case. [37] VZP divided the data requested by the complainant into tables from which specific insured persons cannot be identified. To identify them, a meaningless insured person identifier would have to be assigned to individual data rows, which VZP refused to provide. This therefore constitutes pseudonymization. [38] It follows from the Court of Justice’s conclusions cited above that information may constitute personal data in relation to one person, while it loses this character in relation to another person. The decisive criterion is whether a person has at their disposal lawful and reasonable means that they can use to re-identify the data subject. [39] First, it can be concluded that, in relation to VZP, the information may constitute personal data. If it were to fully comply with the complainant’s request for information and provide her with meaningless identifiers corresponding to specific data subjects, it could indeed retroactively link the meaningless identifiers in the tables to the data subjects. The answer to whether this would be possible could depend on whether VZP would retain information linking the meaningless identifier to a specific data subject, or whether it would create and assign the identifier in a manner that would prevent even itself—or its employees who are not authorized to access the personal data of insured persons—from linking them retroactively. [40] In this case, however, it is necessary to examine whether the meaningless identifier associated with information about data subjects (sensitive data regarding their health status) constitutes personal data in relation to the complainant, who requested this information. The answer depends on whether the complainant has lawful means that can reasonably be expected to be used to directly or indirectly identify the natural person in question (judgments of the Court of Justice of March 7, 2024, IAB Europe, C-604/22, paragraphs 43 and 48; and in the Breyer case, paragraphs 44, 47, and 48). [41] A given means cannot reasonably be used to identify a data subject “if the risk of identification appears, in fact, to be negligible, since the identification of that data subject is prohibited by law or is practically impossible, for example, because it would require a disproportionate effort in terms of time, economic resources, and human resources” (paragraph 82 of the Court of Justice’s judgment in SRB and the case law cited therein). [42] The Supreme Administrative Court will therefore assess whether the requested information, in its entirety (i.e., the disclosed data together with a non-identifying identifier), is in itself sufficient to enable the complainant to identify individual persons. In doing so, it is necessary to take into account “all objective factors, such as the costs and time required for identification, taking into account the technology available at the time of processing as well as technological developments” (para. 79, ibid.). As the Municipal Court also noted, it is also necessary to examine whether individuals can be identified by combining the requested data with information available on the internet (paragraph 48 of the contested judgment, paragraph 81 of the Court of Justice’s judgment in the SRB case), or with other publicly available information, including the content of other (even potential) requests for information. [43] One can agree with the Municipal Court that a non-meaningful identifier will increase the amount of information that can be gleaned from the entire dataset. The identifier will link individual rows within a single table as well as across tables, thereby making it possible to determine, for a single insured person (characterized by the identifier, gender, and age range), the following information for the years 2010–2017: - their specific diagnosis, or rather all 183 types of diagnoses assigned to them; - medical procedures related to iron deficiency that were performed on them; - information about their hospitalization (duration, course of treatment); - whether certain medications or medical devices were prescribed or administered to him; - the number and date of these procedures (specified to the month). In contrast, currently (i.e., in the disclosed dataset), each piece of this information is separate, and the insured person is identified as described above (paragraph 31 of this judgment)—but without an identifier—in each data row individually. [44] However, as the complainant points out, iron deficiency is a very common diagnosis. This also corresponds to the scope of the disclosed information. For example, the table of prescriptions issued for 13 specific medicinal products (or medical supplies) contains approximately one million data rows. Thus, one of these products was prescribed in approximately 10,000 cases per month. Similarly, one of the 18 healthcare procedures (such as the administration of blood or blood products) was performed an average of 80,000 times per month. The number of diagnoses potentially related to iron deficiency recorded in a single month averages 130,000. [45] On the other hand, some tables are not comprehensive enough to allow for sufficient generalization of the data they contain. Although the DRG table (which lists so-called hospitalization cases—in simple terms, information about a patient’s treatment during hospitalization) contains 700,000 rows, if we break these rows down to the smallest distinguishable unit of time for hospitalization (the monthly level), an average of roughly 7,000 insured individuals were hospitalized each month (there were 96 months between 2010 and 2017), while the list of hospitalization cases captured in the table (DRG codes) consists of 96 (ranging from heart failure to disorders of the male reproductive system). If each insured person were assigned only one such code following their hospitalization, an average of 70 insured persons would be associated with each code. If a single insured person had multiple codes in total, adding the insured person’s identifier (which links them to a single individual) can result in unique combinations of codes within a single month. For these insured individuals, who are already identified with some degree of specificity, the same table reveals not only these diagnoses but also age (in five-year intervals), gender, and region. [46] For each of these specified insured individuals, it would also be possible to assign either their diagnosis, the medications they are taking, or the medical procedures they have undergone (provided that this additional information for a specific patient is included in the tables). The Diagnoses table displays a wide range of 183 types of diagnoses, ranging from chronic viral hepatitis, through malignant neoplasms of the root of the tongue or heart failure, to celiac disease. Although the tables of medications and procedures do not contain many types, they are listed specifically—medications include items such as ferrous sulfate or red blood cells, and procedures such as gastric bypass for morbid obesity or total gastrectomy/subtotal gastrectomy. [47] Data linked in this way therefore make it possible to identify individuals based solely on knowledge of their approximate age, gender, the date(s) the procedure(s) were performed; in some cases, just two pieces of information regarding a specific prescribed or administered medication, hospitalization and course of treatment, diagnosis, or procedure performed within an eight-year period may suffice. There is a high probability that, in certain cases (e.g., rare diseases, unusual combinations, or exceptionally low or high age), this method could result in a unique combination of data that excludes other insured persons, which would lead to the identification of a specific individual. [48] As the Court of Justice stated in the Breyer case (and reiterated in the SRB case, para. 83), personal data is involved when information enabling the identification of the data subject is held by different persons and it is not possible to effectively prevent the data subject from being identifiable to any of those persons. The risk that a single person (the complainant or another person to whom the complainant might disclose the data) will have access to the information referred to in the preceding paragraph is not negligible. As the Municipal Court has already pointed out, such information can be obtained from the media or social networks (paragraph 48 of the contested judgment). It is common for people to share this information about themselves on social networks, whether for educational purposes or for private reasons. Certain information regarding health status may also appear in the media. [49] The Supreme Administrative Court therefore concluded that the non-identifying identifier, the disclosure of which the complainant seeks, transforms the otherwise provided dataset into personal data within the meaning of Article 4(1) of the GDPR. It is precisely these specific DRG codes, diagnoses, procedures, and medicinal products that, in conjunction with other information in the tables, narrow down groups with the same characteristics to such an extent that they allow for the creation of specific data links attributable only to a single insured person, who would thus become identifiable to the complainant. III.e Balancing Competing Interests [50] The case at hand involves sensitive personal data (Section 8a of the Information Act and Article 9 of the GDPR). However, the disclosure of such data cannot be ruled out a priori; rather, it is necessary to identify a competing public interest or a constitutionally guaranteed right in relation to the right to information and to balance them against one another. Only a restriction on the right to information that is necessary (proportionate) is constitutionally compliant (see Constitutional Court ruling of January 17, 2023, Case No. Pl. ÚS 25/21, No. 40/2023 Coll., para. 42). The complainant’s right to information is now in conflict with the data subjects’ right to privacy. [51] The proportionality test is used to balance competing interests (rights). It is based on three criteria: (I.) suitability, (II.) necessity, and (III.) proportionality (see, e.g., the judgment of the Supreme Administrative Court dated September 20, 2022, Ref. No. 5 As 65/2021-73, No. 4396/2022 Coll. of the Supreme Administrative Court, para. 43). [52] The refusal to provide the identifier constitutes an appropriate means of protecting patients’ privacy. As the Supreme Administrative Court explained above, without it, individual tables containing health data cannot be linked, and individual patients are therefore not identifiable. [53] In the present case, there is no alternative procedure that would constitute a lesser interference with the complainant’s right to information. The complainant insists on being provided with the identifier along with the data already provided. However, this would again lead to the potential identification of individual insured persons. It is certainly conceivable that the data in the provided tables could be modified so that the data subjects’ right to privacy would be infringed upon less, if at all. However, such data modification (e.g., further aggregation) would have to be requested by the complainant herself (if the obligated entity is processing a comprehensible, clear, and unambiguous request for information, it is also bound by its wording, see the judgment of the Supreme Administrative Court dated August 21, 2024, Ref. No. 8 As 40/2023-52, para. 23), which she did not do. On the contrary, the defendant, in cooperation with her, had already proceeded to aggregate the data in the tables so that it could at least provide them to the complainant. [54] It is therefore necessary to consider whether the data subjects’ right to privacy or the complainant’s right to information should prevail. [55] The insured person’s identifier, in conjunction with the other information provided, makes it possible to determine data regarding the data subjects’ health status. The GDPR generally prohibits the processing of such data (including making it available), with the exceptions set forth in Article 9(2) of the GDPR. The Information Act also stipulates that information concerning a person’s identity, expressions of a personal nature, the privacy of a natural person, and personal data may be provided by the obligated entity only in accordance with the legal regulations governing their protection (Section 8a(1) of the Information Act). Such data thus generally enjoy a higher level of protection. Specifically, information would be provided regarding certain diagnoses, medical procedures, hospitalizations, and the medications they are taking. Although some of this data consists of a limited list related to the treatment of iron deficiency (medications and medical procedures), other data points indicate the patient’s overall health status and, not infrequently, serious medical conditions (associated primarily with malignant, but also with benign, tumors). [56] In contrast, the Constitutional Court notes that the right to information (Article 17 of the Charter of Fundamental Rights and Freedoms) and the corresponding obligation of public authorities to provide such information is a key element of the relationship between the state and the individual. Its purpose is to enable civil society to participate in public affairs and to exercise public oversight of the state’s activities (Constitutional Court ruling of November 15, 2010, Case No. I. ÚS 517/10, No. 223/2010 Coll. of Constitutional Court Decisions, para. 18). In the present case, the provision of the requested information may contribute to the oversight of insurance companies and healthcare providers, and thus also to the management of public funds, while “information and transparency can contribute to the improvement of the healthcare system as a whole” (Constitutional Court ruling, Case No. III. ÚS 836/21, para. 33). [57] Although there is also a public interest in the disclosure of the requested information, its provision cannot be considered sufficiently necessary to justify the disclosure of sensitive personal data of (presumably) hundreds of thousands of insured persons. An identifier would certainly make it possible to link data more effectively and provide more accurate information on how patients’ conditions are treated, as opposed to the information provided, which examines individual diagnoses, prescription of medications, etc., in isolation. However, such an interest cannot outweigh such a fundamental intrusion into the privacy of so many insured persons as the disclosure of what is often the most intimate information about their health status. The defendant cooperated with the complainant and aggregated the data itself in such a way as to accommodate the complainant’s requests to the greatest extent possible. The complainant now has general information regarding the treatment of individuals with iron deficiency. Without the Supreme Administrative Court assessing the usefulness of the provided information for the complainant’s analysis, the scope of the information was extensive. The restriction on the complainant’s right to information is therefore proportionate. IV. Conclusion [58] The Supreme Administrative Court thus concludes that the Municipal Court correctly determined that the insured person’s identifier, which the complainant requested the defendant to provide, constitutes personal data when combined with other data already provided. The Court of Cassation reached this conclusion partly for a different reason, as it relied primarily on the judgment of the Court of Justice in the SRB case, which was issued only during the proceedings on the cassation appeal. It also disagreed with the Municipal Court’s legal opinion that the mere fact that the information constitutes personal data is sufficient grounds to refuse to provide it. In this case as well, any restriction on the right to information must be subject to a proportionality test. Nevertheless, the defendant acted correctly in refusing to disclose the insured person’s identifier. Although the Supreme Administrative Court had to partially correct the conclusions set forth in the contested judgment, the Municipal Court acted correctly in dismissing the complaint.

Similar Content