Religious Beliefs
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of religious or philosophical beliefs
Overview
19 sources · Jul 23, 2026Legal Framework
Article 9(1) GDPR establishes a general prohibition on processing personal data revealing religious or philosophical beliefs. This sits within the broader framework of special category data under Chapter II, Section III of the predecessor Directive 95/46, now carried forward and expanded under the GDPR. The prohibition reflects the heightened risk of discrimination, reputational harm, and other significant social or economic disadvantage that Recital 75 associates with such processing.
The prohibition is not absolute. Article 9(2) GDPR enumerates ten specific exceptions, including explicit consent under Article 9(2)(a), processing necessary for substantial public interest under Article 9(2)(g), and processing carried out in the course of legitimate activities by foundations or non-profit bodies with a political, philosophical, religious, or trade-union aim, provided that processing relates solely to members or persons in regular contact and the data is not disclosed outside that body without consent under Article 9(2)(d). Each exception requires a corresponding lawful basis under Article 6 GDPR in addition to the Article 9 condition.
The AI Act adds a further layer. Recital 30 of the AI Act prohibits biometric categorisation systems that infer religious or philosophical beliefs from biometric data such as facial images or fingerprints. This prohibition targets systems that deduce beliefs from physiological characteristics rather than lawful sorting of biometric datasets by objective traits like hair or eye colour.
Key Developments
The CJEU's reasoning in GC and Others v CNIL confirms that the Article 9 prohibition applies to data that reveals beliefs, whether directly or through inference, and that Member States must give effect to both the prohibition and its narrowly defined exceptions. In Minister voor Immigratie v. M, the Court clarified that an applicant's religion listed in an official minute constitutes personal data, while purely abstract legal analysis contained in the same document does not — drawing a practical line between factual data revealing belief and interpretive commentary that may incidentally reference it.
In Meta Platforms v. noyb, the Court reinforced that Article 9 applies squarely to platform processing where user data reveals religious or philosophical beliefs, underscoring that social media operators cannot circumvent the prohibition by characterising such data as merely incidental to broader profiling activities.
Enforcement has been robust. Dutch municipalities were fined for unlawfully processing information about Muslim individuals, demonstrating that public-sector controllers face the same Article 9 constraints as private entities. The Belgian DPA's fine against a researcher linked to EU DisinfoLab further illustrates that academic or research contexts do not automatically exempt controllers from Article 9 obligations.
Practical Guidance
- Establish dual lawful bases. Identify both an Article 6 basis and an Article 9(2) condition before processing any data revealing religious beliefs. Absence of either renders the processing unlawful regardless of purpose.
- Apply the "reveals" test rigorously. Data need not explicitly state a belief to fall within Article 9. If inference from combined data points would reveal religious or philosophical beliefs — through profiling, aggregation, or contextual association — the prohibition applies, as confirmed in GC and Others v CNIL.
- Audit biometric systems for inference capabilities. Under AI Act Recital 30, any system that deduces beliefs from biometric data is prohibited. Controllers deploying biometric tools must verify they sort only by objective physical traits and do not infer protected characteristics.
- Document the Article 9(2)(d) boundary for membership organisations. Religious or philosophical foundations may process member data under this exception, but disclosure to third parties without consent breaches the condition. Maintain internal access controls reflecting this limit.
- Conduct Data Protection Impact Assessments. Recital 75 explicitly links special category processing to elevated risk of discrimination and social harm. Processing religious belief data requires a DPIA under Article 35(3)(b), documenting mitigation measures and demonstrating necessity and proportionality.