The Croatian authority clarifies the conditions for providing aggregated data for scientific research purposes
The Croatian Personal Data Protection Agency (AZOP) has clarified the distinction between aggregated statistical data and personal data in the context of a request for access to information for scientific research purposes.
A researcher was denied access by a hospital to aggregated statistical data for the period 2021-2025, relating to the annual number of cardiology examinations and average waiting times. The hospital justified its refusal by arguing that these data, being derived from medical records, constituted health data protected under the GDPR. AZOP clarified that the fact that statistical indicators originate from personal data processing does not automatically qualify them as personal data. The qualification depends on the possibility of identifying a natural person. Highly aggregated data, such as those requested, are generally not considered personal data. The data controller must carry out a concrete and documented assessment of the risk of identification and cannot merely invoke the origin of the data, in accordance with the accountability principle set out in Article 5, paragraph 2 and Article 24 of the GDPR.
AZOP also recalled that while the scientific research purpose does not in itself constitute a legal basis for obtaining data, the refusal to disclose truly anonymous information cannot be based on the GDPR. The authority emphasized that it is not competent to rule on disputes relating to the right of access to information, this prerogative belonging to the Information Commissioner. It is for the latter to assess the legality of the hospital's refusal, including carrying out a proportionality and public interest test, and to order, if necessary, the disclosure of information. The applicant may appeal the refusal decision before the Commissioner within 15 days.
A researcher was denied access by a hospital to aggregated statistical data for the period 2021-2025, relating to the annual number of cardiology examinations and average waiting times. The hospital justified its refusal by arguing that these data, being derived from medical records, constituted health data protected under the GDPR. AZOP clarified that the fact that statistical indicators originate from personal data processing does not automatically qualify them as personal data. The qualification depends on the possibility of identifying a natural person. Highly aggregated data, such as those requested, are generally not considered personal data. The data controller must carry out a concrete and documented assessment of the risk of identification and cannot merely invoke the origin of the data, in accordance with the accountability principle set out in Article 5, paragraph 2 and Article 24 of the GDPR.
AZOP also recalled that while the scientific research purpose does not in itself constitute a legal basis for obtaining data, the refusal to disclose truly anonymous information cannot be based on the GDPR. The authority emphasized that it is not competent to rule on disputes relating to the right of access to information, this prerogative belonging to the Information Commissioner. It is for the latter to assess the legality of the hospital's refusal, including carrying out a proportionality and public interest test, and to order, if necessary, the disclosure of information. The applicant may appeal the refusal decision before the Commissioner within 15 days.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire