Genetic Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of genetic and hereditary data
Overview
24 sources · Jul 23, 2026Legal Framework
Genetic data is governed primarily by Article 9 GDPR, which prohibits the processing of special categories of personal data, including genetic data, unless one of the enumerated exceptions applies. The prohibition is categorical:
"processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
— GDPR Art. 9(1)
To lift the prohibition, controllers must identify both a valid Article 6(1) lawful basis and a specific Article 9(2) exception. Explicit consent under Article 9(2)(a) is the most common route, but it must be genuinely freely given and specific. In the Netherlands, the UAVG reinforces this framework. Article 22 UAVG mirrors the Article 9 prohibition, while Article 28 UAVG adds a national layer: genetic data may be processed where the data subject has given explicit consent and appropriate safeguards protect their private life. For processing not relating to the individual from whom the data was obtained, a "substantial medical interest" must prevail, or the processing must serve public-interest scientific research or statistics.
Key Developments
The CJEU's ruling in Ministerstvo na vatreshnite raboti (C-205/21) addressed the collection of biometric and genetic data by police authorities and confirmed that purpose limitation binds authorities from the moment they seek access to personal data. The Hoge Raad reinforced this in its own analysis:
"De doeltreffendheid van dit beginsel vereist noodzakelijkerwijs dat het doel van de gegevensverzameling wordt bepaald vanaf het moment waarop de bevoegde autoriteiten proberen om toegang te krijgen tot persoonsgegevens"
— OM-cassatie en cassatie verdachte, ¶73
This means controllers cannot defer purpose specification until after genetic data is collected; the purpose must be defined ex ante. Domestically, the Raad van State confirmed that Article 9(2)(h) GDPR — covering preventive or occupational medicine and healthcare provision — can justify processing of health-related and genetic data where the processing is necessary and grounded in Union or Member State law. The Rechtbank has separately upheld DNA profiling under the Wet DNA-onderzoek bij veroordeelden, finding the statutory framework compatible with Article 8 ECHR when the legal conditions are met.
On the enforcement side, the EDPB's breach notification guidance establishes that breaches involving genetic data presumptively carry a high risk to data subjects, triggering mandatory notification to both the supervisory authority and the affected individuals.
Status of the Debate
This topic is actively contested. While the core prohibition in Article 9(1) and the exception structure in Article 9(2) are settled, the boundaries of specific exceptions — particularly the scope of "substantial medical interest" under Article 28 UAVG and the interaction between explicit consent and statutory mandates — remain in flux. Courts have diverged on how stringently to assess proportionality when genetic data is processed for purposes beyond the original collection context, especially in law enforcement and research settings. The open question that would resolve the debate is whether the CJEU will clarify the proportionality threshold for secondary use of genetic data under the Law Enforcement Directive (2016/680), particularly regarding retention periods and purpose compatibility.
Practical Guidance
- Establish dual legal bases: Before processing genetic data, document both an Article 6(1) lawful basis and a specific Article 9(2) exception — one without the other is insufficient.
- Define purpose ex ante: Following Ministerstvo na vatreshnite raboti, specify the processing purpose at the point of data access, not after collection, to satisfy purpose limitation.
- Apply heightened safeguards under UAVG Art. 28: When relying on consent for genetic data processing in the Netherlands, ensure explicit consent is obtained and implement safeguards that prevent disproportionate infringement of the data subject's private life.
- Treat breaches as high-risk: Under EDPB guidance, a personal data breach involving genetic data presumptively triggers the high-risk threshold — prepare for mandatory notification to both the DPA and affected individuals within 72 hours.
- Distinguish research from clinical use: Processing genetic data for scientific research under Article 28(2)(b) UAVG requires a public-interest basis and may dispense with consent only where obtaining it is impossible or disproportionately burdensome.