Political Opinions
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of political views and affiliations
Overview
20 sources · Jul 23, 2026Legal Framework
Article 9(1) GDPR establishes a general prohibition on processing personal data revealing political opinions. This is one of the special categories of personal data that receive heightened protection due to the fundamental rights and freedoms at stake, particularly because such data could expose individuals to discrimination or other harm. The prohibition covers not only data that directly states a person's political views but also data from which political opinions can be inferred or revealed.
The prohibition is not absolute. Article 9(2) GDPR provides several derogations. Article 9(2)(g) permits processing when it is necessary for reasons of substantial public interest, subject to Union or Member State law and with appropriate safeguards. At the national level, Article 26 of the Dutch UAVG implements this derogation specifically for processing that occurs in connection with reasonable requirements related to political opinions in the context of fulfilling functions in administrative bodies and advisory councils.
The AI Act adds another layer: Recital 30 prohibits biometric categorisation systems that use biometric data—such as facial features or fingerprints—to deduce or infer an individual's political opinions. This prohibition does not extend to lawful labelling or filtering of biometric data sets acquired in accordance with Union or national law.
Key Developments
The CJEU has consistently affirmed the special-category status of political opinions. In GC and Others v CNIL, the Court confirmed that Article 9(1) GDPR carries forward and strengthens the prohibition previously established under Article 8(1) of Directive 95/46, treating political opinions alongside racial origin, religious beliefs, and trade union membership as data requiring enhanced protection. In Meta Platforms v noyb, the Court reaffirmed the same framework in the context of targeted advertising, underscoring that inferred political opinions fall squarely within the Article 9 prohibition.
In Dennekamp v European Parliament, the General Court addressed whether disclosure of names of former MEP assistants could indirectly reveal political opinions. The Court found that the mere argument that disclosure might reveal political affiliations was insufficiently substantiated and could not substitute for a concrete showing that disclosure would specifically and effectively undermine privacy rights under Article 4(1)(b) of Regulation 45/2001. This establishes that a claim of political-opinion sensitivity requires demonstrable, specific harm—not a theoretical possibility.
Dutch enforcement has been active. The AP fined ten municipalities, including Delft and Ede, each €25,000 for unlawful processing of data revealing political opinions. These cases involved municipalities processing information about individuals' political or religious affiliations without a valid Article 9(2) derogation, demonstrating that public-sector controllers face scrutiny even when processing appears administratively routine.
Practical Guidance
Establish a valid derogation before processing. Identify the specific Article 9(2) ground relied upon—most commonly 9(2)(g) substantial public interest—and ensure it is backed by Union or Member State law, as required by the GDPR and illustrated by Article 26 UAVG.
Distinguish direct revelation from inference. Data need not explicitly state political views to trigger Article 9. If processing combinations of data points would reveal political opinions, the prohibition applies. The Dennekamp ruling shows that a mere theoretical possibility is insufficient, but controllers should assess whether inference is reasonably likely.
Do not use biometric systems to infer political opinions. Recital 30 of the AI Act prohibits biometric categorisation systems that deduce political opinions from biometric data. Ensure any biometric processing is limited to lawful, non-sensitive categorisation purposes.
Conduct a DPIA for any processing involving political opinions. Given the high risk to fundamental rights, a Data Protection Impact Assessment under Article 35 GDPR is mandatory, documenting the necessity, proportionality, and safeguards applied.
Apply data minimisation strictly. The Dutch municipality fines demonstrate that collecting or retaining political-opinion data without a clear legal basis invites enforcement. Limit collection to what is strictly necessary for the identified derogation and delete when no longer needed.