Cross-Jurisdictional Global

Sensitive Data Definitions Worldwide: One Word, Many Laws

What counts as sensitive data in each regime: GDPR's special categories, CPRA's sensitive personal information, PIPL's risk-based definition, biometric and health-data statutes, and how to run one classification system across all of them.

Regulation

GDPR Articles 9-10, CPRA's sensitive personal information, the Virginia/Colorado consent family, PIPL Articles 28-32, LGPD Article 5(II), Illinois BIPA, Washington My Health My Data, Quebec Law 25

Max Penalty

Special-category violations sit in the GDPR's 4% tier; BIPA statutory damages of $1,000-$5,000 per violation produced the $650M Facebook settlement; sensitive-data processing without consent is a top state-enforcement theory

Enforcing Authority

DPAs, the CPPA and state AGs, the FTC (health and biometric theories), the CAC, and, uniquely for BIPA and MHMD, private plaintiffs with class actions

Official Source

www.edpb.europa.eu

Executive Summary

  • The definitions genuinely differ: GDPR runs a closed list of special categories, CPRA adds geolocation, credentials, and mail contents, PIPL defines sensitivity by harm risk and includes financial accounts, and the US adds standalone biometric and health statutes.
  • The consequences attached differ too: Article 9 demands an additional processing gate, the Virginia-family states require opt-in consent, California grants a limit-use right, and PIPL layers separate consent plus impact assessments.
  • Inference is the modern battleground: health and orientation inferred from browsing or location triggers sensitive-data duties in Europe (CJEU doctrine) and dedicated statutes in Washington and Nevada.
  • BIPA proved the private-enforcement model: per-scan statutory damages produced nine-figure settlements and made biometric templates the highest-litigation-risk data type in America.
  • One classification taxonomy with per-regime flags beats regime-by-regime relabeling: tag data once, let the policy engine apply each jurisdiction's gates.

“Sensitive data” is the most consequential phrase in privacy law and means something different in every statute that uses it: a closed European list built around dignity and discrimination, a Californian list that adds passwords and precise location, a Chinese standard defined by harm and covering bank accounts, and an American archipelago of biometric and health statutes where the definition comes with statutory damages attached. The categories agree at the core, health, biometrics, orientation, beliefs, and diverge exactly where modern systems generate the most data: location, financial identifiers, credentials, inferences. That divergence is why relabeling data regime-by-regime fails, and why mature programs classify once against the superset, flag per regime, and let infrastructure enforce the gates. The stakes are the least symmetric in privacy: sensitive-data failures produce the top-tier fines, the class actions, and the headlines, while the controls, tagging, consent gates, adtech exclusions, are the same finite engineering list every statute above is asking for.

The core (global)Health, biometrics-for-ID, sexual orientation, beliefs, race/ethnicity
The edges (per regime)Geolocation + credentials (CPRA), financial accounts + location tracking (PIPL), immigration status (VA family), inferences (CJEU, MHMD)
The gatesArt. 9 exception, opt-in consent (VA family), limit-use (CA), separate consent + PIPIA (PIPL), written release (BIPA)
Private enforcementBIPA ($650M Facebook), MHMD’s PRA, Texas CUBI ($1.4B Meta)
Doctrine hubEDPB

Working the category

Tag it first. Data mapping and inventory is where sensitivity classification lives.

Assess it. PIA and DPIA requirements worldwide covers the assessments sensitive tags trigger.

Gate the consent. Lawful basis comparison covers the explicit and separate consent standards.

Watch the health flows. Healthcare privacy worldwide covers the HIPAA-and-beyond landscape.

Health pages sending data to ad platforms is the pattern behind the biggest recent cases: check your own site’s flows with a free scan.

Frequently Asked Questions

What are the GDPR's special categories, and what does the Article 9 gate require?

Article 9(1) prohibits processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and processing of genetic data, biometric data for the purpose of uniquely identifying a person, health data, and data concerning sex life or sexual orientation, a closed list, deliberately, with Article 10's criminal-conviction data running a parallel restricted regime. The gate mechanics: processing requires both an Article 6 basis and an Article 9(2) exception, explicit consent (a higher bar than ordinary consent: specific, salient, unambiguous affirmation of the sensitive processing itself), employment and social-security law necessity, vital interests, legitimate activities of nonprofits regarding members, manifestly-made-public data, legal claims, substantial public interest under law, health and social care, public health, and archiving/research, each with conditions, and member-state law adds specificity (especially for health and employment). Doctrinal expansions that catch engineering teams: 'revealing' works by inference, the CJEU's OT v Vyriausioji judgment (2022) held that data from which sensitive attributes can be indirectly deduced falls under Article 9 (a spouse's name revealing orientation, in that case), which pulls browsing patterns, location traces (clinic visits), purchase histories, and app usage into scope when they support sensitive inferences, the reasoning behind DPA actions on adtech health-audience segments; biometric data is special-category only when processed to uniquely identify (face templates for matching yes, a mere photograph generally no, per recital 51), a purpose-based trigger that turns on what the system does; and health data is read broadly (the EDPB's position covering wellness-app data, and the pandemic-era guidance covering temperature and status). The operational consequences beyond the gate: special-category processing is a DPIA trigger (WP248 criterion), weighs heavily in breach risk assessments (Article 34 individual notice becomes presumptively likely), constrains legitimate-interests balancing elsewhere in the program, and triggers the Article 37 DPO analysis at scale. The record-keeping expectation: the RoPA marks special categories per activity, and the Article 9(2) exception is named per purpose, the first thing a DPA checks when a complaint involves health or orientation data.

How do the US definitions differ, and what duties attach in each state?

Two architectures. California (CPRA): 'sensitive personal information' is a defined category, government identifiers (SSN, driver's license, passport), account credentials, financial account plus access credentials, precise geolocation (within ~1,850 feet), racial or ethnic origin, religious or philosophical beliefs, union membership, mail/email/text contents where the business is not the intended recipient, genetic data, biometric information processed for identification, health data, and sex life or sexual orientation, notably broader than Article 9 (credentials, geolocation, communications content, and government IDs are not European special categories), and the attached duty is distinctive: not an opt-in gate but a right to limit use and disclosure to enumerated business purposes, exercised through a 'Limit the Use of My Sensitive Personal Information' link, with full duties applying only when sensitive data is used to infer characteristics. The Virginia/Colorado family (now the majority pattern): sensitive data defined as racial/ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, citizenship or immigration status, genetic or biometric data for identification, children's data, and precise geolocation, with opt-in consent required before processing, a genuine European-style gate, plus mandatory data protection assessments; Colorado's rules elaborate consent standards (no dark patterns, refreshed consent), and several states (Connecticut, Texas, Oregon and successors) tune the list, Oregon adding status as a victim of crime, Maryland's 2025 law banning sale of sensitive data outright rather than gating it, the strictest US position. The federal overlay: the FTC polices sensitive-data misuse through Section 5 and the Health Breach Notification Rule (the GoodRx and Premom actions over health data shared with ad platforms, the BetterHelp order over therapy-intake data, and the Kochava litigation establishing precise location near sensitive venues as an unfairness theory), and its 2024 orders against data brokers restricted sensitive-location-category sales. The design consequence: a US-facing system needs per-state sensitive flags (the categories differ), a consent gate for the Virginia family, the California limit-use pathway, and, because enforcement has concentrated there, special handling for precise geolocation and health-adjacent flows regardless of state.

What do PIPL and the other international regimes classify as sensitive?

PIPL Articles 28-32 run the most consequential non-Western definition: sensitive personal information is defined functionally, information that, once leaked or illegally used, may easily lead to infringement of personal dignity or harm to personal or property safety, with a non-exhaustive enumeration covering biometrics, religious beliefs, specific identity, medical health, financial accounts, individual location tracking, and all personal information of minors under 14, the functional test meaning the category is open (new data types join by risk analysis, not statutory amendment) and the enumeration meaning financial accounts and location tracking, ordinary data in Europe, are sensitive in China. The attached duties stack: processing only with specific purpose and sufficient necessity plus strict protection measures, separate consent (the distinct consent action PIPL doctrine requires, not a bundled checkbox), enhanced notice of necessity and impact, a personal information protection impact assessment (PIPIA) before processing, and interaction with the transfer regime (sensitive volume thresholds trigger CAC routes faster: 10,000 individuals' sensitive PI versus 100,000-1,000,000 for ordinary data in the 2024 rules). The rest of the map: LGPD Article 5(II) defines sensitive data close to the GDPR list (racial/ethnic origin, religious conviction, political opinion, union or organizational membership, health, sex life, genetic or biometric data) with Article 11's restricted bases and no legitimate-interests lane; Quebec Law 25 defines sensitivity contextually (information whose nature or context creates a high reasonable expectation of privacy) with express-consent and PIA consequences; Japan's APPI 'special care-required personal information' (race, creed, social status, medical history, criminal record, crime-victim status) requires opt-in consent for acquisition and blocks the third-party opt-out route; Korea's PIPA runs a similar consent-gated list adding DNA and, by presidential decree, certain biometric and ideology data; India's DPDP Act notably abandoned the sensitive-data tier from earlier drafts (one uniform standard, with children's data as the special case); Australia's Privacy Act defines sensitive information (health, racial origin, political opinions and memberships, religion, sexual orientation, criminal record, biometrics) requiring consent for collection under APP 3; and Africa's major laws (POPIA's special personal information, Nigeria's NDPA) follow the European template. The crosswalk lesson: the intersection (health, biometrics-for-ID, orientation, beliefs, race) is safe to treat as globally sensitive; the edges (financial accounts, location, credentials, immigration status, minors' thresholds) are where per-regime flags earn their keep.

Why are biometric and health data the highest-risk categories in practice?

Because both attract dedicated statutes with teeth beyond the general laws, and one of them arms private plaintiffs. Biometrics: Illinois' BIPA (2008) requires informed written consent before collecting biometric identifiers or information, a published retention-and-destruction schedule, and bars profiting from biometric data, enforced through a private right of action with statutory damages of $1,000 per negligent and $5,000 per reckless/intentional violation; the Illinois Supreme Court's Rosenbach (2019) removed any actual-harm requirement, Cothron v. White Castle (2023) held claims accrue per scan (creating annihilating exposure the court itself flagged, prompting the 2024 amendment consolidating same-method accrual to one violation), and the settlement record, Facebook $650 million, Google $100 million, ClearviewAI's injunctive settlement, plus thousands of employer timeclock cases, made biometric templates the most-litigated data type in America; Texas's CUBI and Washington's HB 1493 run AG-enforced analogues (Texas's Meta settlement: $1.4 billion, 2024, the largest state privacy recovery), Colorado's 2024 amendment added biometric consent duties to its CPA, and globally, biometrics-for-identification sits in every sensitive list above plus the EU AI Act's remote-biometric-identification restrictions. Health: beyond HIPAA's boundary (which covers providers, plans, and their business associates, leaving consumer health apps outside), the gap-filling statutes arrived with private enforcement too, Washington's My Health My Data (2023, effective 2024) defines consumer health data expansively (including inferences and gender-affirming and reproductive care data), requires consent for collection and sharing, separate authorization for sale, geofencing bans around health facilities, and a private right of action via the state consumer-protection act, with Nevada's SB 370 as the AG-enforced sibling; the FTC's health enforcement (GoodRx, BetterHelp, Premom, Cerebral) polices app-to-adtech flows, and the Meta-pixel hospital litigation wave prices the same flows in civil damages. The common thread: both categories are immutable or intimate (you cannot rotate your face or your diagnosis), inference-prone (location and browsing reconstruct them), and politically salient post-Dobbs (location near clinics, cycle-tracking data), which is why the engineering posture for both is presumptive: treat as sensitive at ingestion, gate with explicit consent, exclude from adtech entirely, and document destruction, whatever the user's state.

How should a global program classify and control sensitive data operationally?

One taxonomy, per-regime flags, gates enforced in infrastructure. The taxonomy: a superset classification scheme covering every category any applicable regime treats as sensitive, the Article 9 list, CPRA's additions (credentials, precise geolocation, communications content, government IDs), PIPL's additions (financial accounts, location tracking, under-14 data), the biometric and health statutes' definitions including inferences, applied at the data-inventory level so every dataset, field, and event stream carries sensitivity tags with the regimes that trigger them; inference tagging is the discipline that separates adequate from failing programs, the segment 'visited oncology pages' is health data under CJEU doctrine, MHMD, and the FTC's theories even though no diagnosis field exists. The gate layer, wired per regime by the policy engine: explicit/separate/opt-in consent flows where required (Article 9(2)(a), the Virginia family, PIPL's separate consent, APPI acquisition consent, BIPA's written release), California's limit-use pathway, assessment triggers (DPIA, PIPIA, state data protection assessments fire automatically on sensitive tags), transfer-threshold accounting (PIPL's 10,000-sensitive-individuals trigger), and the categorical exclusions good programs adopt regardless of consent theory: sensitive categories out of behavioral advertising (the position EU enforcement, the FTC's cases, and MHMD converge on), no geofencing of health facilities, no sale of sensitive data (Maryland's rule as the conservative global setting). The protection layer scaled to the tag: encryption and access controls stricter than baseline, minimization reviews (does the purpose require the sensitive field at all, PIPL's necessity test as the useful global prompt), retention shortened, breach playbooks that treat sensitive-data incidents as presumptively notifiable, and vendor flow-downs restricting sensitive-data use explicitly. And the audit reality to design for: regulators and plaintiffs test sensitive-data handling empirically, the network tab on the symptom-checker page, the SDK inventory of the cycle-tracking app, the geofence query against ad exchanges, so the program's own testing must include the same checks, tag-verification sampling, adtech-flow audits on sensitive surfaces, and consent-record reconciliation, run before someone outside runs them for you.

Regulatory Crosswalk

GDPR Article 9CPRAPIPL sensitive PIBIPAWashington MHMD

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.