# Persónuvernd (Island) - 2025051308

- Type: Enforcement
- Source: Persónuvernd
- Date: 2026-10-09
- Original: https://gdprhub.eu/index.php?title=Persónuvernd_(Island)_-_2025051308
- Canonical: https://overview.legal/posts/593304
- Topics: Personal Data, Healthcare, Controllers, Supervisory Authorities, Health Data, Healthcare, Access Controls, Lawful Basis, Authority Access Rights to AI Systems and Documentation

## Summary

The DPA issued a reprimand against a hospital employee for conducting unauthorised searches of a data subjects medical records, which constituted personal data processing, without an appropriate legal basis. English Summary. Facts. The DPA received a complaint from a data subject concerning the unauthorised searches by an employee of Landspitali Hospital (the controller) of her medical records. Particularly, because the employee was not involved in the data subject’s medical treatment. The contr

## Full text

The DPA issued a reprimand against a hospital employee for conducting unauthorised searches of a data subjects medical records, which constituted personal data processing, without an appropriate legal basis. English Summary. Facts. The DPA received a complaint from a data subject concerning the unauthorised searches by an employee of Landspitali Hospital (the controller) of her medical records. Particularly, because the employee was not involved in the data subject’s medical treatment. The controller had confirmed that the employee had searched for the data subject’s patient record nine times. The controller’s supervisory board investigated the searches of the data subject’s records and clarified that the employee did not have a legitimate reason to access the medical records. Therefore, they found that the employee exceeded her access rights and thus was in violation of the national law on medical records. Holding. The DPA held that despite the controller being in charge of its employ

---
Generated by overview.legal · https://overview.legal/posts/593304 · 2026-10-09
