Religious Beliefs
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of religious or philosophical beliefs
Overview
21 sources · Aug 27, 2026Legal Framework
Article 9 GDPR establishes the core prohibition: processing of personal data revealing religious or philosophical beliefs is forbidden unless an exception under Article 9(2) applies. The provision sits within a broader protective architecture — Recital 75 expressly identifies religious belief data as a category that elevates processing risk.
"Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership"
— GDPR Art. 9(1)
The prohibition is not absolute. Article 9(2)(a) permits processing where the data subject has given explicit consent; 9(2)(b) covers employment-law obligations; 9(2)(c) protects vital interests; and 9(2)(d) allows processing by nonprofit bodies with religious aims, subject to appropriate safeguards. Controllers must satisfy both an Article 6(1) legal basis and a separate Article 9(2) exemption — the EDPB has confirmed this dual requirement.
The AI Act adds a further layer: Recital 30 prohibits biometric categorisation systems that infer religious beliefs from biometric data.
Key Developments
The CJEU has repeatedly reaffirmed the Article 9 framework in GC and Others v CNIL, Meta Platforms v noyb, X v Russmedia, and MK v K GmbH. These rulings confirm that religious and philosophical belief data receives the highest tier of statutory protection, though the available paragraphs largely restate the article text rather than resolving edge-case questions.
"the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject"
— GC and Others v CNIL ¶17
Enforcement signals reinforce the risk calculus. The Irish DPC's decision against Permanent TSB treated Article 9 data categories as an aggravating factor in assessing security failures. The EDPB's breach notification guidelines flag religious belief data as automatically triggering high-risk obligations.
"where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership"
— GDPR Recital 75
Status of the Debate
The doctrinal status signals active contestation. While the CJEU has consistently restated the Article 9 framework, courts have not yet definitively resolved key boundary questions: what processing "reveals" religious beliefs when beliefs are inferred rather than directly declared; how narrowly "explicit consent" must be scoped for ongoing processing; and whether the Article 9(2)(d) nonprofit exemption extends to data sharing between affiliated religious organisations. No court split is on record yet — a CJEU preliminary reference on the scope of "revealing" under Article 9(1) would clarify the outer limits.
Practical Guidance
- Dual legal basis: Secure an Article 6(1) lawful basis and a separate Article 9(2) exemption before processing any religious belief data — relying on one without the other is insufficient.
- Explicit consent: Where relying on Article 9(2)(a), ensure consent is specific, granular, and revocable; document the opt-in mechanism separately from general terms.
- Biometric inference: Do not deploy AI systems that categorise individuals by religious belief from biometric data — the AI Act prohibits this outright.
- Breach thresholds: Treat any breach involving religious belief data as presumptively high-risk; prepare for mandatory notification to both the supervisory authority and affected data subjects.
- DPIA: Conduct a data protection impact assessment before processing religious belief data at scale, particularly in employment or service-delivery contexts.
why this is here
The siphoned data contained bank account information, social security numbers, ethnicity, sexual orientation and religion of the data subjects.
The document explicitly mentions religion as compromised data, which is a special category under Art. 9(1) GDPR.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
information on ethnic origin, political opinion, religious beliefs
Religious beliefs are explicitly listed among the data types affected, but it is one of many categories, not the sole focus.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
some supervisors also used the 'Flurfunk' [meaning to hear something through the grapevine] to acquire a broad knowledge of individual employees, for example about family problems and religious beliefs.
Religious beliefs are mentioned as one example of private information collected, but they are not the primary subject of the document.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.