CJEU on Art. 15 GDPR right of access by the data subject

  • Author: Wolfgang von Sandersleben, DP-Dock GmbH
  • Last updated: November 2023
  • Category: Data Security

More and more clients of ours ask us what is the right way to approach and subsequently respond a data subject’s Art. 15 GDPR access request (DSAR). Recently, the Court of Justice of the European Union (CJEU) shed some light on that matter. More specifically, a patient of a dental practice in Germany suspecting malpractice requested a copy of his medical records. The dental practice initially refused to comply with his request citing a German law that required a patient to cover the cost of obtaining such copies.

The case quickly escalated to the CJEU, which ruled out that even though the patient was “fishing” for evidence to establish his legal case, the reasonings behind a DSAR are irrelevant and the Data Controllers (in this case the dental practice) is obliged to provide the data subject with an “accurate and clear copy of their data”: On the question of national legislation requiring the patient to pay for the cost, the Court ruled that this is restricting - unlikely to be allowed after the introduction of the GDPR and that the first copy of the medical records shall be provided without additional costs.

It remains to be seen whether the German legislator will take the decision into account and to which reforms this decision may lead. For more info, please read here: CJEU rules individuals have right to free copy of their personal data (iapp.org)

Folder with patient files
© Stockwerk-Fotodesign / stock.adobe.com | #59126588

Privacy settings

We use cookies on our website. Some of them are essential, while others help us improve this website and your experience.

In this overview you can select and deselect individual cookies of a category or entire categories. You will also receive more information about the cookies available.
Group essential
Name Matomo
Technical name
Provider
Expire in days 72
Privacy policy
Use Use without cookies
Allowed
Group external media
Name Calendly
Technical name __cf_bm,__cfruid,OptanonConsent
Provider Calendly LLC
Expire in days 365
Privacy policy
Use To arrange appointments via the provider Calendly
Allowed
Name Contao CSRF Token
Technical name csrf_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the website from cross-site request forgery attacks. After closing the browser, the cookie is deleted again.
Allowed
Name Contao HTTPS CSRF Token
Technical name csrf_https_contao_csrf_token
Provider Contao
Expire in days 0
Privacy policy
Use Serves to protect the encrypted website (HTTPS) against falsification of cross-site requests. After closing the browser the cookie is deleted again
Allowed
Name PHP SESSION ID
Technical name PHPSESSID
Provider Contao
Expire in days 0
Privacy policy
Use PHP cookie (programming language), PHP data identifier. Contains only a reference to the current session. There is no information in the user's browser saved and this cookie can only be used by the current website. This cookie is used all used in forms to increase usability. Data entered in forms will be e.g. B. briefly saved when there is an input error by the user and the user receives an error message receives. Otherwise all data would have to be entered again
Allowed