Persónuvernd · 2025051308
The DPA issued a reprimand against a hospital employee for conducting unauthorised searches of a data subjects medical records, which constituted personal data processing, without an appropriate legal basis.
Status Not cited by any decision here yet
Full text
Machine translation of the decision, via GDPRhub — not the official text.
The DPA issued a reprimand against a hospital employee for conducting unauthorised searches of a data subjects medical records, which constituted personal data processing, without an appropriate legal basis. English Summary. Facts. The DPA received a complaint from a data subject concerning the unauthorised searches by an employee of Landspitali Hospital (the controller) of her medical records. Particularly, because the employee was not involved in the data subject’s medical treatment. The controller had confirmed that the employee had searched for the data subject’s patient record nine times. The controller’s supervisory board investigated the searches of the data subject’s records and clarified that the employee did not have a legitimate reason to access the medical records. Therefore, they found that the employee exceeded her access rights and thus was in violation of the national law on medical records. Holding. The DPA held that despite the controller being in charge of its employ