Special Categories of Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Sensitive data requiring enhanced protection (health, biometric, etc.)
Overview
24 sources · Jul 23, 2026Legal Framework
Special categories of personal data are governed primarily by Article 9 GDPR, which establishes a general prohibition on processing sensitive data, subject to narrowly defined exceptions. The provision sits atop the general lawfulness requirement in Article 6(1), meaning controllers must satisfy both a lawful basis under Article 6 and a specific exemption under Article 9(2) to process special category data.
Article 9(1) sets out the categories subject to the prohibition:
"Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
— GDPR Art. 9(1)
The prohibition is lifted only where one of the conditions in Article 9(2) is met. The most commonly relied-upon exception is explicit consent under Article 9(2)(a), which demands a higher standard than the consent basis in Article 6(1)(a). Other exceptions include processing necessary for employment obligations (9(2)(b)), vital interests where the subject cannot consent (9(2)(c)), and legitimate activities of not-for-profit bodies (9(2)(d)). The constitutional underpinning for this heightened protection traces to Article 21 of the EU Charter, which prohibits discrimination on grounds including sex, race, ethnic origin, religion, disability, and sexual orientation.
Key Developments
Enforcement decisions confirm that the presence of special category data materially raises the stakes for controllers, particularly in breach notification assessments. The EDPB's breach notification guidelines illustrate that when health data is involved, notification to both the supervisory authority and affected data subjects is typically considered necessary:
"A notification to the SA is considered necessary, as special categories of personal data are involved and the restoration of the data could take a long time, resulting in major delays in patient care."
— EDPB Guidelines 01/2021 §39
Dutch courts have also grappled with the boundary between ordinary sensitive data and special category data. In a livestream enforcement case, the AP took the position that even where data does not formally qualify as special category data under Article 9, its sensitivity can still elevate risk:
"Hoewel geen bijzondere persoonsgegevens worden verwerkt, is sprake van de verwerking van gevoelige persoonsgegevens die betrekking hebben op betrokkenen en hun privéleven."
— Rechtbank, AVG-handhavingszaak livestream ¶10.6
This signals that controllers cannot rely solely on the absence of an Article 9 label to justify lower safeguards — the contextual sensitivity of data remains a risk factor.
Status of the Debate
This topic is actively contested in court. The core statutory text of Article 9 is settled, but its application to emerging technologies — particularly biometric processing, inferred special category data, and data that reveals sensitive characteristics indirectly — generates divergent judicial outcomes. Courts have not yet definitively resolved whether data that is not inherently special category data but can be used to infer such characteristics triggers the Article 9 prohibition. The boundary between "sensitive" data in a general sense and formally prohibited special category data under Article 9(1) is a live dispute. A CJEU preliminary reference on inferred special category data would provide the clearest resolution.
Practical Guidance
- Map your data against Article 9(1) categories precisely. Data "concerning health" or "revealing racial or ethnic origin" can include inferences drawn from non-sensitive inputs. Document your classification rationale.
- Secure an Article 9(2) exemption before processing begins. Explicit consent under 9(2)(a) must be specific, informed, and freely given — bundled consent for multiple processing purposes will not satisfy the standard.
- Apply heightened security measures. Article 32 obligations are amplified for special category data; encryption, access controls, and minimisation should be demonstrably calibrated to the elevated risk.
- Prepare for mandatory breach notification. As the EDPB guidance confirms, breaches involving special category data will almost always meet the "high risk" threshold requiring both authority notification and direct communication with data subjects.
- Conduct a DPIA. Article 35(3)(b) mandates a data protection impact assessment for large-scale processing of special category data. This is not optional and should precede deployment.