Article 9 flips the GDPR’s usual logic. For most personal data, processing is allowed with a lawful basis; for the special categories, processing is prohibited unless you can point to one of ten specific exceptions. The categories cover the data whose misuse does the deepest harm: health, beliefs, ethnicity, union membership, genetics, biometrics, and sexual life. Getting this wrong lands in the top fine tier, and the definition reaches further than most teams expect.
| Regulation | GDPR, Article 9 |
|---|---|
| Max penalty | EUR 20M or 4% of global annual turnover |
| Key case | CJEU C-184/20 (2022, indirect disclosure) |
| Enforcing authority | National supervisory authorities, coordinated by the EDPB |
| Official text | EUR-Lex CELEX 32016R0679 |
The scope is wider than the list
The categories themselves are enumerated and closed, but their application is expansive because the article covers data “revealing” the attributes. Three consequences follow. Inferences count: an advertising profile that tags a user as interested in diabetes products processes health data. Combinations count: location history showing weekly visits to a clinic or a place of worship reveals protected attributes. And context counts: a food-delivery order is ordinary data, but the CJEU’s C-184/20 judgment confirms that data liable to reveal sensitive attributes indirectly is covered.
Web tracking is a recurring source of accidental Article 9 processing. Analytics and ad pixels on hospital, clinic, and sexual-health pages transmit page URLs that themselves reveal health information. Several European authorities and the FTC in the US have pursued exactly this pattern. A free scan shows which third parties receive URL-level data from your site, which is the first thing to check if any of your content is health-related.
The ten permissions
Article 9(2) lists the conditions that lift the prohibition. The ones that matter commercially: explicit consent (a); employment, social security, and social protection law (b); vital interests where the person cannot consent (c); processing by nonprofits about their own members (d); data manifestly made public by the person (e); legal claims (f); substantial public interest under EU or member state law (g); health and social care provision (h); public health (i); and research and archiving (j). Note that several conditions require a basis in EU or national law, so the analysis is jurisdiction-specific.
Explicit consent is stricter than ordinary consent: a clear statement specifically referencing the sensitive data and purpose. And remember the two-layer rule: an Article 9 condition supplements, never replaces, the Article 6 lawful basis.
The safeguard package
Special category processing pulls in the rest of the regulation’s heavy machinery: a DPIA where processing is large-scale (Article 35(3)(b)), possibly a mandatory DPO (Article 37(1)(c)), stronger Article 32 security with encryption and tight access control, and honest Articles 13/14 disclosure. Retention deserves particular discipline, since holding sensitive data past its purpose multiplies breach impact. Our DPIA guide covers the assessment this processing almost always requires.