Skip to content
Topic Contested in court

Religious Beliefs

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing of religious or philosophical beliefs

51 linked items 27 Case Law8 Guidance9 Enforcement5 News2 Literature

Overview

21 sources · Aug 27, 2026

Legal Framework

Article 9 GDPR establishes the core prohibition: processing of personal data revealing religious or philosophical beliefs is forbidden unless an exception under Article 9(2) applies. The provision sits within a broader protective architecture — Recital 75 expressly identifies religious belief data as a category that elevates processing risk.

"Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership"
— GDPR Art. 9(1)

The prohibition is not absolute. Article 9(2)(a) permits processing where the data subject has given explicit consent; 9(2)(b) covers employment-law obligations; 9(2)(c) protects vital interests; and 9(2)(d) allows processing by nonprofit bodies with religious aims, subject to appropriate safeguards. Controllers must satisfy both an Article 6(1) legal basis and a separate Article 9(2) exemption — the EDPB has confirmed this dual requirement.

The AI Act adds a further layer: Recital 30 prohibits biometric categorisation systems that infer religious beliefs from biometric data.

Key Developments

The CJEU has repeatedly reaffirmed the Article 9 framework in GC and Others v CNIL, Meta Platforms v noyb, X v Russmedia, and MK v K GmbH. These rulings confirm that religious and philosophical belief data receives the highest tier of statutory protection, though the available paragraphs largely restate the article text rather than resolving edge-case questions.

"the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject"
— GC and Others v CNIL ¶17

Enforcement signals reinforce the risk calculus. The Irish DPC's decision against Permanent TSB treated Article 9 data categories as an aggravating factor in assessing security failures. The EDPB's breach notification guidelines flag religious belief data as automatically triggering high-risk obligations.

"where personal data are processed which reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership"
— GDPR Recital 75

Status of the Debate

The doctrinal status signals active contestation. While the CJEU has consistently restated the Article 9 framework, courts have not yet definitively resolved key boundary questions: what processing "reveals" religious beliefs when beliefs are inferred rather than directly declared; how narrowly "explicit consent" must be scoped for ongoing processing; and whether the Article 9(2)(d) nonprofit exemption extends to data sharing between affiliated religious organisations. No court split is on record yet — a CJEU preliminary reference on the scope of "revealing" under Article 9(1) would clarify the outer limits.

Practical Guidance

  • Dual legal basis: Secure an Article 6(1) lawful basis and a separate Article 9(2) exemption before processing any religious belief data — relying on one without the other is insufficient.
  • Explicit consent: Where relying on Article 9(2)(a), ensure consent is specific, granular, and revocable; document the opt-in mechanism separately from general terms.
  • Biometric inference: Do not deploy AI systems that categorise individuals by religious belief from biometric data — the AI Act prohibits this outright.
  • Breach thresholds: Treat any breach involving religious belief data as presumptively high-risk; prepare for mandatory notification to both the supervisory authority and affected data subjects.
  • DPIA: Conduct a data protection impact assessment before processing religious belief data at scale, particularly in employment or service-delivery contexts.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
€5M Interserve Group Limited: Insufficient technical and organisational measures to ensure information security The British DPA has fined the construction group Interserve Group Limited EUR 5,033,000. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. Interserve… UNITED KINGDOM ·ICO ·Art. 5, 32 Enforcement Information Commissioner (ICO) Oct 2022 Religious beliefs as special category data
why this is here
The siphoned data contained bank account information, social security numbers, ethnicity, sexual orientation and religion of the data subjects.

The document explicitly mentions religion as compromised data, which is a special category under Art. 9(1) GDPR.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

€35M H&M Hennes & Mauritz Online Shop A.B. & Co. KG: Insufficient legal basis for data processing The fashion company with seat in Hamburg operates a service center in Nuremberg. Here, according to the findings of the Hamburg data protection officer, since at least 2014… GERMANY ·HmbBfDI ·Art. 5, 6 Enforcement Data Protection Authority of Hamburg Oct 2020 religious beliefs among private data
why this is here
some supervisors also used the 'Flurfunk' [meaning to hear something through the grapevine] to acquire a broad knowledge of individual employees, for example about family problems and religious beliefs.

Religious beliefs are mentioned as one example of private information collected, but they are not the primary subject of the document.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026