Types of Special Categories of Personal Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.A dedicated topic is needed to comprehensively cover the specific types and definitions of special categories of personal data, including racial/ethnic origin, political opinions, religious beliefs, genetic data, biometric data, health data, and criminal convictions.
Overview
24 sources · Jul 23, 2026Legal Framework
The governing provision is Article 9(1) GDPR, which establishes a general prohibition on processing special categories of personal data. The article enumerates the protected types in a single, exhaustive list:
"Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation shall be prohibited."
— GDPR Art. 9(1)
This prohibition operates as a second layer of scrutiny atop the general lawfulness requirement in Article 6(1). A controller must first identify a valid Article 6 basis and then satisfy one of the exceptions in Article 9(2). The most commonly invoked exception is explicit consent:
"the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject"
— GDPR Art. 9(2)(a)
The special-category designation also has structural consequences elsewhere in the GDPR. For instance, Article 27(2)(a) exempts non-EU controllers from designating an EU representative only where processing is occasional and does not involve large-scale processing of Article 9(1) data. Criminal convictions and offences are governed separately under Article 10, which the representative provision references alongside Article 9.
Key Developments
The EDPB's breach-notification guidance confirms that the involvement of special-category data materially elevates risk. In a case involving a stolen log book from a drug rehabilitation facility, the Board stated:
"Due to the failure of appropriate safety precautions, sensitive health data pursuant to Article 9 (1) GDPR was lost. Since in this case a special category of personal data was concerned, the potential risks to the concerned data subjects was increased"
— EDPB Guidelines 01/2021 §100
This framing has direct enforcement consequences. The Italian Garante fined a provincial health authority €20,000 for publishing special-category health data of an individual in an official resolution. The Spanish AEPD imposed a €200,000 fine on an insurance broker following a ransomware attack that exposed sensitive data — a penalty level reflecting the heightened risk the EDPB guidance describes.
Biometric data is a particularly active front. The EDPB has issued guidance on facial recognition in law enforcement and an opinion on its use for airport passenger flow, signalling that the boundary between lawful biometric processing and Article 9(1) violations turns on whether the processing is "for the purpose of uniquely identifying a natural person." Where biometric data is used merely for verification rather than identification, the Article 9(1) designation may not apply — but this distinction remains contested.
Status of the Debate
This topic is actively contested in court. While the enumerated categories in Article 9(1) are textually fixed, their scope is not. Courts and regulators diverge on whether specific data types fall within the prohibition — most prominently on biometric data, where the line between authentication and identification is fought over, and on health data, where incidental inferences from non-medical data can trigger Article 9(1) classification. No definitive CJEU ruling has settled these boundary questions. A future preliminary reference clarifying the threshold for "revealing" racial or ethnic origin — particularly through algorithmic inference — would resolve a significant open question.
Practical Guidance
- Map each data field against the Article 9(1) categories before processing begins. Data that indirectly reveals a special category (e.g., dietary preferences indicating religious belief) can fall within the prohibition.
- Distinguish biometric verification from biometric identification. Only the latter triggers Article 9(1), but document the distinction carefully — regulators are scrutinising this boundary.
- Ensure consent for special-category data is explicit, specific, and separable. Bundling it with general terms will not satisfy Article 9(2)(a).
- Apply heightened security measures to special-category data. The EDPB's breach guidance makes clear that loss of such data presumptively creates high risk, requiring both supervisory-authority notification and communication to affected data subjects.
- Remember that criminal-conviction data is governed by Article 10, not Article 9. Controllers must maintain separate legal bases and safeguards for these two regimes.