Laws · GDPR ·art-9-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited.
How it connects
Cited by
- CJEU Bavarian Lager: Disclosing personal data in access-to-documents requests is
- Guidelines 01/2021 on Examples regarding Personal Data Breach Notification
- Guidelines 03/2022 on Deceptive design patterns in social media platform interfaces: how to recognise and avoid them
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 8/2020 on the targeting of social media users
All 132
- Guidelines 3/2018 on the territorial scope of the GDPR (Article 3)
- Guidelines 02/2021 on virtual voice assistants
- Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR
- Medical centers: Insufficient legal basis for data processing
- Concentrix Cvg Italy s.r.l.: Insufficient legal basis for data processing
- HUNGARY DPA: Insufficient legal basis for data processing
- MedHelp AB: Non-compliance with general data processing principles
- UAB VS FITNESS: Non-compliance with general data processing principles
- Comune di Montalbano Jonico: Non-compliance with general data processing principles
- Grindr LLC: Insufficient legal basis for data processing
- Private individual: Insufficient legal basis for data processing
- Lisbon City Council: Insufficient legal basis for data processing
- C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security
- Lawyer: Insufficient legal basis for data processing
- IAB Europe: Insufficient legal basis for data processing
- Azienda Sanitaria Locale Roma: Insufficient legal basis for data processing
- Private individual: Non-compliance with general data processing principles
- Portuguese National Statistical Institute: Non-compliance with general data processing principles
- Praktiškas UAB: Insufficient legal basis for data processing
- MALTA DPA: Non-compliance with general data processing principles
- Irish Departement of Health: Non-compliance with general data processing principles
- Supermarket: Insufficient legal basis for data processing
- Comune di Ustica: Non-compliance with general data processing principles
- National Prosecutor's Office: Insufficient legal basis for data processing
- Clearview AI Inc.: Non-compliance with general data processing principles
- Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles
- Chief Commander of the Police: Insufficient legal basis for data processing
- Doctor´s Office: Insufficient legal basis for data processing
- Doctor´s Office: Insufficient legal basis for data processing
- Doctor´s Office: Insufficient technical and organisational measures to ensure information security
- Departement of Social Security: Insufficient legal basis for data processing
- Municipality of Bologna: Insufficient technical and organisational measures to ensure information security
- Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli: Insufficient legal basis for data processing
- Study on the secondary use of personal data in the context of scientific research
- Guidelines 02/2025 on processing of personal data through blockchain technologies
- EDPB- EDPS Joint Opinion 01/2025 on the Proposal for a Regulation on simplification measures for SMEs and SMCs, in particular the record-keeping obligation under Art. 30(5) GDPR
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Guidelines 3/2025 on the interplay between the DSA and the GDPR
- EDPB contribution to the EBA public consultation on draft regulatory technical standards on AML/CFT
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- GC and Others v CNIL
- Meta Platforms v noyb
- Roverbella Comprehensive School: Insufficient legal basis for data processing
- UODO fines accounting firm €2,760 for email breach security failures
- Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania: Insufficient legal basis for data processing
- Università Telematica e-Campus: Insufficient legal basis for data processing
- Mediaworks Hungary Zrt.: Insufficient legal basis for data processing
- Blikk Kft.: Insufficient legal basis for data processing
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- UODO (Poland) - DKN.5131.27.2023
- Generative AI and data protection
- DSB (Austria) - 2025-0.968.031
- Hoge Raad - 24/02161
- LG Rostock: Pre-ticked cookie consent boxes invalid under Art 6(1)(a) GDPR
- CJEU C-5/25 Pilev: identity verification and extra data under LED 2016/680
- Dutch Supreme Court: patient not entitled to access peer-review assessment of medical file
- DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health
- DPA need not assess law's constitutionality or GDPR proportionality, only legal basis
- Guidelines on processing of personal data through blockchain technologies
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
- Statement 2/2024 on the financial data access and payments package
- Opinion 11/2024 on the use of facial recognition to streamline airport passengers’ flow (compatibility with Articles 5(1)(e) and(f), 25 and 32 GDPR)
- Report of the work undertaken by the ChatGPT Taskforce
- Opinion 08/2024 on Valid Consent in the Context of Consent or Pay Models Implemented by Large Online Platforms
- EDPB-EDPS Joint Opinion 01/2023 on the Proposal for a Regulation of the European Parliament and of the Council laying down additional procedural rules relating to the enforcement of Regulation (EU) 2016/679
- EDPB Annual Report 2022
- EDPB-EDPS Joint Opinion 03/2022 on the Proposal for a Regulation on the European Health Data Space
- Statement 05/2021 on the Data Governance Act in light of the legislative developments
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research
- Guidelines 2/2020 on articles 46 (2) (a) and 46 (3) (b) of Regulation 2016/679 for transfers of personal data between EEA and non-EEA public authorities and bodies
- Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)
- X v Russmedia Digital SRL and Inform Media Press SRL
- European Parliament v TC
- CK v Magistrat der Stadt Wien
- MK v K GmbH
- Maximilian Schrems v Meta Platforms Ireland Limited
- ND v DR
- RL v Landeshauptstadt Wiesbaden
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts
- OQ v Land Hessen
- European Commission v Republic of Poland
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- Meta Platforms Ireland Ltd, formerly Facebook Ireland Ltd v European Commission
- European Commission v Republic of Poland
- Hauptpersonalrat der Lehrerinnen und Lehrer beim Hessischen Kultusministerium v Minister des Hessischen Kultusministeriums
- Criminal proceedings against V.S
- Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH
- OT v Vyriausioji tarnybinės etikos komisija
- Ligue des droits humains ASBL v Conseil des ministres
- G.D. v The Commissioner of the Garda Síochána and Others
- Criminal proceedings against HP
- European Commission v Republic of Poland
- European Commission v Republic of Poland
- Tele2 Sverige AB v Post- och telestyrelsen and Secretary of State for the Home Department v Tom Watson and Others
- Athanassios Oikonomopoulos v European Commission
- Safe Interenvios, SA v Liberbank, SA and Others
- General Data Protection Regulation (GDPR) – Revolution Coming to European Data Protection Laws in 2018. What’s New for Ordinary Citizens?
- HDPA (Greece) - 12/2026
- CJEU C-312/24 Darashev: Data subject's right to erasure of criminal investigation data
- VG Ansbach: Lawyer not required to redact client data when submitting files to court
- VwGH: €18M DSB fine annulled — GDPR corporate fine requires identified culpable natural
- Garante per la protezione dei dati personali (Italy) - 462/2026
- Austrian court reviews postal service selling political affinity data of customers
- UODO (Poland) - DKN.5131.5.2025
- Austrian FAC rules on publishing full court judgment naming witness on social media
- NAIH (Hungary) - NAIH-450-7-2026
- NAIH (Hungary) - NAIH-4462-5-2026
- Austrian DSB: Controller's use of social security number for statutory financial aid was
- NSS - 4749/2026
- Finnish DPA examines anti-doping organization's GDPR compliance over public suspension
- Datatilsynet (Denmark) - 09-07-2026 (Lyngby Boldklub)
- Datatilsynet authorises AC Horsens facial recognition at matches under conditions
- Datatilsynet (Denmark) - 09-07-2026 (Lyngby Boldklub)
- Montelibretti State Comprehensive School: Insufficient legal basis for data processing
- DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful
- BVwG - W292 2292202-1
- VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security
- Ancel Keys Comprehensive School Castelnuovo Cilento: Insufficient legal basis for data processing
- European Commission v Hungary
- Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M
- Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service
- Mediaworks Hungary Zrt.: Insufficient legal basis for data processing
- IndaNext Hungary Kft. (legal successor of Blikk Kft.): Insufficient legal basis for data processing