EU Privacy Law EU/EEA

GDPR Special Category Data: Processing Sensitive Personal Data Lawfully

GDPR Article 9 explained: the nine special categories, the ten conditions that permit processing, and the extra safeguards sensitive data demands.

Regulation

GDPR, Article 9

Max Penalty

EUR 20 million or 4% of global annual turnover, whichever is higher

Enforcing Authority

National supervisory authorities, coordinated by the EDPB

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 9(1) prohibits processing nine special categories by default: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, and data on sex life or sexual orientation.
  • Processing is lawful only when one of the ten Article 9(2) conditions applies, in addition to an Article 6 lawful basis.
  • Inference counts: deriving health status or orientation from behavior is special category processing even if nobody typed the sensitive fact in.
  • The CJEU confirmed in 2022 (C-184/20) that data revealing sensitive attributes indirectly falls under Article 9.
  • Special category processing at scale triggers the DPIA duty and often the DPO requirement, and it sits in the top fine tier.

Article 9 flips the GDPR’s usual logic. For most personal data, processing is allowed with a lawful basis; for the special categories, processing is prohibited unless you can point to one of ten specific exceptions. The categories cover the data whose misuse does the deepest harm: health, beliefs, ethnicity, union membership, genetics, biometrics, and sexual life. Getting this wrong lands in the top fine tier, and the definition reaches further than most teams expect.

RegulationGDPR, Article 9
Max penaltyEUR 20M or 4% of global annual turnover
Key caseCJEU C-184/20 (2022, indirect disclosure)
Enforcing authorityNational supervisory authorities, coordinated by the EDPB
Official textEUR-Lex CELEX 32016R0679

The scope is wider than the list

The categories themselves are enumerated and closed, but their application is expansive because the article covers data “revealing” the attributes. Three consequences follow. Inferences count: an advertising profile that tags a user as interested in diabetes products processes health data. Combinations count: location history showing weekly visits to a clinic or a place of worship reveals protected attributes. And context counts: a food-delivery order is ordinary data, but the CJEU’s C-184/20 judgment confirms that data liable to reveal sensitive attributes indirectly is covered.

Web tracking is a recurring source of accidental Article 9 processing. Analytics and ad pixels on hospital, clinic, and sexual-health pages transmit page URLs that themselves reveal health information. Several European authorities and the FTC in the US have pursued exactly this pattern. A free scan shows which third parties receive URL-level data from your site, which is the first thing to check if any of your content is health-related.

The ten permissions

Article 9(2) lists the conditions that lift the prohibition. The ones that matter commercially: explicit consent (a); employment, social security, and social protection law (b); vital interests where the person cannot consent (c); processing by nonprofits about their own members (d); data manifestly made public by the person (e); legal claims (f); substantial public interest under EU or member state law (g); health and social care provision (h); public health (i); and research and archiving (j). Note that several conditions require a basis in EU or national law, so the analysis is jurisdiction-specific.

Explicit consent is stricter than ordinary consent: a clear statement specifically referencing the sensitive data and purpose. And remember the two-layer rule: an Article 9 condition supplements, never replaces, the Article 6 lawful basis.

The safeguard package

Special category processing pulls in the rest of the regulation’s heavy machinery: a DPIA where processing is large-scale (Article 35(3)(b)), possibly a mandatory DPO (Article 37(1)(c)), stronger Article 32 security with encryption and tight access control, and honest Articles 13/14 disclosure. Retention deserves particular discipline, since holding sensitive data past its purpose multiplies breach impact. Our DPIA guide covers the assessment this processing almost always requires.

Frequently Asked Questions

What are the special categories of data under GDPR?

Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, plus genetic data, biometric data processed to uniquely identify someone, health data, and data concerning sex life or sexual orientation (Article 9(1)).

Is a photo biometric data?

Only when processed through specific technical means allowing unique identification, such as face recognition (recital 51). An ordinary staff photo on the intranet is personal data but not biometric data in the Article 9 sense.

Do I always need explicit consent for special category data?

No. Explicit consent (Article 9(2)(a)) is one of ten conditions. Others include employment and social security law, vital interests, substantial public interest, health care provision, public health, and legal claims. Employment contexts usually rely on 9(2)(b), not consent.

Does inferred sensitive data count?

Yes. The CJEU held in C-184/20 (2022) that data liable to indirectly reveal sensitive attributes falls under Article 9. Purchase histories that reveal health conditions or apps that infer orientation are special category processing.

Is criminal conviction data a special category?

It has its own regime under Article 10: processing requires official authority or a specific legal authorization. It is treated with similar strictness but is not technically an Article 9 category.

Regulatory Crosswalk

UK GDPRLGPD sensitive dataHIPAA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.