Scenario 1: MED is a healthcare provider located in Norway. It provides high-quality and affordable healthcare services, including disease prevention, diagnosis, and treatment. Founded in 1995, MED is one of the largest health organizations in the private sector. The company has constantly evolved, as a response to patients' needs. Patients that schedule an appointment in MED's medical centers need to initially provide their personal information, including name and surname, address, phone number, and date of birth. Further checkup or admission requires extra information, including previous medical history and genetic data.
When providing the personal data, patients are informed that the data is used for personalizing their treatments and improving the communication between them and MED's doctors. Medical data of patients, including children, are stored in the database of MED's health information system. MED allows patients who are at least 16 years old to use the system and provide their personal information independently. For children below the age of 16, MED requires consent from the holder of parental responsibility before processing their data. MED uses a cloud-based application that allows patients and doctors to upload and access information. Patients can save all personal medical data, including test results, doctor visits, diagnosis history, and medicine prescription, as well as review and track them at any time. Doctors, on the other hand, can access their patients' data through the application and can add information, as needed. Patients who decide to continue the treatment in another health institution can request by MED to transfer their data. Even if patients decide to continue their treatment in other health institutions, their personal data is still used by MED and patients' requests to stop data processing are rejected. This has been decided from MED's top management in order to save the information of everyone who gets registered in their databases. The company shares medical data with InsHealth, a health insurance company. MED's data helps InsHealth create health insurance plans that meet the needs of individuals and families. MED believes that it is its responsibility to ensure the security and accuracy of the patients' personal data. Thus, based on the identified risks presented by data processing activities, MED has implemented appropriate security measures to ensure that data is securely stored and processed. Since personal data of patients is stored and transmitted over the internet, MED uses encryption to avoid unauthorized processing, accidental loss, or destruction of data. The company has established a security policy to define the levels of protection required for each information and processing activity. MED has communicated the policy and other procedures to the personnel and provided customized training to all personnel to ensure that it is able to use MED's systems needed for data processing. Based on this scenario, answer the following question: If a patient requests MED to permanently erase their data, MED should:
- Reject the request since medical history of patients cannot be permanently erased
- Erase the personal data if it is no longer needed for its original purpose
- Erase the personal data only in case it is needed to comply with a legal obligation
Answer(s): B
Explanation:
The scenario describes a patient's request to permanently erase their data from MED, a healthcare provider. Under the General Data Protection Regulation (GDPR), individuals have the "right to erasure," also known as the "right to be forgotten," as stipulated in Article 17.
MED's current practice of rejecting patients' requests to stop data processing, aiming to "save the information of everyone who gets registered," is a direct violation of GDPR principles, particularly the principles of purpose limitation (Article 5(1)(b)) and storage limitation (Article 5(1)(e)), as well as the data subject's rights.
Answer B, "Erase the personal data if it is no longer needed for its original purpose," correctly aligns with a primary condition for exercising the right to erasure under Article 17(1)(a). This article states that the data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay where the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
In the healthcare context, this means that once the patient's treatment has concluded, and any legally mandated retention periods for medical records (which vary by national law, e.g., in Norway) have expired, MED would generally be obliged to erase the data if the patient requests it. MED cannot indefinitely retain personal data based solely on a management decision to "save the information of everyone who gets registered" without a valid legal basis or ongoing necessity for a specific, legitimate purpose.
While there are exceptions to the right to erasure, such as when processing is necessary for reasons of public interest in the area of public health (Article 17(3)(c)) or for compliance with a legal obligation that requires processing by Union or Member State law (Article 17(3)(b)), these are specific conditions. MED must assess if such an exception truly applies to all the data requested for erasure. If a specific legal obligation dictates a retention period for medical records, MED can rely on that. However, once that period expires, or if the data is no longer necessary for providing healthcare to that individual and no other exception applies, the data must be erased upon request.
The fact that MED uses a cloud-based application means it must ensure its cloud service provider can facilitate the secure and complete erasure of data across all systems and backups, demonstrating a robust data lifecycle management process as part of its security measures. MED's sharing of data with InsHealth also implies that if the original purpose for sharing or the lawful basis (e.g., patient consent) ceases, that data should also be erased from InsHealth's systems.
In summary, MED cannot simply reject all erasure requests. It must evaluate each request against the conditions of Article 17, particularly whether the data is still necessary for the original purposes for which it was collected or whether a specific legal obligation or other legitimate exception applies. If not, the data must be erased.
Authoritative Links:
GDPR Article 17 - Right to erasure ('right to be forgotten'): https://gdpr-info.eu/art-17-gdpr/ GDPR Article 5 - Principles relating to processing of personal data: https://gdpr-info.eu/art-5-gdpr/
Reveal Solution Next Question