Special category data: what counts and extra rules
Special category data is protected by Article 9 GDPR. Learn which data qualifies, when processing is permitted and which extra safeguards apply.

Quick Answer: Special category data covers the sensitive types listed in Article 9 GDPR, including health, genetic and uniquely identifying biometric data. Processing is prohibited unless an Article 9(2) condition applies. The controller still needs an Article 6 lawful basis, suitable safeguards and, for large-scale processing, a data protection impact assessment.
Summary in a mind map
Special category data: what counts and extra rules │ ├─ Closed Article 9 list │ ├─ Origin, beliefs, politics and union membership │ ├─ Genetic, health and identifying biometric data │ └─ Sex life and sexual orientation │ ├─ Prohibition comes first │ ├─ An Article 9 condition must lift the ban │ ├─ An Article 6 lawful basis is still required │ └─ Explicit consent is not universal permission │ ├─ Meaning may be inferred │ ├─ Combinations can reveal sensitive information │ └─ Labels do not control the legal category │ └─ Extra controls ├─ Document both legal layers and safeguards ├─ Assess large-scale processing in a DPIA └─ Check national limits and Article 10 separately
Article 9 protects a closed set of sensitive information
Special category data is not a general synonym for confidential or embarrassing information. It is the defined list in Article 9(1) GDPR. The list covers data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership. It also covers genetic data, biometric data used for unique identification, health data, and data concerning a person's sex life or sexual orientation.1
| Category | Practical example | Boundary to check |
|---|---|---|
| Racial or ethnic origin | An equality-monitoring response | The information must reveal origin |
| Political opinions | A declared political affiliation | Ordinary contact details do not qualify alone |
| Religious or philosophical beliefs | A dietary request that reveals belief | Context can turn an ordinary preference into a revelation |
| Trade union membership | Payroll deductions for union fees | Employment data is not all special category data |
| Genetic data | A DNA test result | The data concerns inherited or acquired characteristics |
| Biometric data | A facial template for staff entry | It qualifies here when used for unique identification |
| Health data | A physiotherapy assessment | It includes information about physical or mental health |
| Sex life or sexual orientation | A patient intake answer | Indirect revelation can be enough |
The boundary is important. Financial difficulty, a home address or a performance score may be sensitive in ordinary speech, yet none is special category data merely for that reason. The controller should still protect such information under the general GDPR rules. It should not claim an Article 9 condition for data that Article 9 does not cover.
The legal starting point is prohibition
Article 9(1) says that processing the listed data is prohibited.1 This structure differs from Article 6, which asks for a lawful basis for ordinary personal data. A firm should therefore record two separate answers: the Article 6 basis for the processing as a whole and the Article 9(2) condition that lifts the additional prohibition.3
Explicit consent is the first listed condition. It must concern one or more specified purposes. Article 9 also preserves a limit: Union or Member State law may provide that the person cannot lift the prohibition by consent.1 A signed box is therefore not a universal permission slip.
Other Article 9(2) conditions may be relevant to a small firm, depending on the exact activity. They include obligations and rights in employment and social protection law, protection of vital interests where the person cannot consent, legal claims, substantial public interest under law, and health or occupational-medicine purposes under the stated safeguards.1 A business must match the condition to the real purpose and any supporting Union or national law. Convenience is not a condition.
Article 6 and Article 9 must both be satisfied
An Article 9 condition sits on top of an Article 6 lawful basis; it does not replace it. The European Data Protection Board tells controllers to identify the Article 6 basis and separately check the additional Article 9 condition.3 For example, a clinic might need health information to provide treatment. It still records why the processing is lawful under Article 6 and which health-related Article 9 condition applies.
This two-layer test prevents a common error. A firm might obtain explicit consent and stop its assessment there. That leaves the Article 6 question unanswered and may ignore whether consent is freely given in an employment relationship. Conversely, a contract under Article 6 does not by itself lift the Article 9 prohibition. Each layer does a different legal job.
The processing must also comply with the remaining GDPR principles. The chosen basis and condition do not remove the duties of purpose limitation, data minimisation, accuracy, storage limitation, security, transparency and accountability.1 Collecting a complete medical history for a one-off workplace adjustment would still need a necessity and minimisation assessment.
Sensitive meaning can be inferred from ordinary fields
Data can fall within Article 9 because of what it reveals, not because of the label on the database column. In Case C-184/20, the Court of Justice held that publishing information liable to disclose a person's sexual orientation indirectly can constitute processing of special category data. The strengthened protection applies where sensitive information is revealed through an intellectual operation involving comparison or deduction.2
A small firm should therefore inspect derived data and combinations. A delivery address plus repeated purchases may reveal religious observance. Appointment patterns and service codes may reveal health. A photograph converted into a facial template for identity matching may become biometric data used for unique identification, although the original photograph was not automatically within that category.
The assessment should follow the output and purpose of the processing. Renaming a field does not change its meaning. Removing the explicit sensitive attribute may also be insufficient if a model score or segmentation reliably exposes the same information.
Extra controls follow the higher risk
The first control is a written record of the two-layer legal test. Record the purpose, Article 6 basis, Article 9 condition, categories of people and data, recipients, retention decision, security controls and relevant national-law provision. The record should be specific enough for another person to understand why the exception applies.
Article 35 requires a data protection impact assessment for large-scale processing of special categories of data.1 The provision does not say that every isolated health note automatically requires a DPIA. Scale is an express trigger, while the wider risk assessment may identify other triggers. A physiotherapy practice holding patient records should evaluate the actual scope and risks instead of treating its size as a complete answer.
Safeguards should follow the use. Restrict access to staff who need the information, separate sensitive fields where practical, protect transfers, set a justified retention period and test deletion. Where the Article 9 condition depends on professional secrecy, employment law or another legal safeguard, record that dependency rather than reducing it to a generic security statement.
The consequences of getting the prohibition wrong can be material. Infringements of Article 9 sit in the GDPR's upper administrative-fine tier: up to EUR 20,000,000 or, for an undertaking, up to 4% of worldwide annual turnover for the preceding financial year, whichever is higher.1 Those are statutory maxima, not an estimate of a likely fine.
National law and Article 10 set further boundaries
EU-wide Article 9 is not always the last word. Article 9(4) allows Member States to maintain or introduce further conditions, including limits, for genetic data, biometric data and health data.1 The same proposed processing may therefore be permitted in one Member State and more restricted in another. A cross-border firm must map the relevant national rule for each establishment or operation; it should not copy one country's conclusion across the group.
Criminal-conviction and offence data is a separate category under Article 10. It is not part of Article 9's list. Processing must take place under official authority or be authorised by Union or Member State law providing appropriate safeguards.1 An employer checking convictions cannot solve the issue by selecting explicit consent from the Article 9 list.
The category label does not by itself decide whether processing is lawful. The answer depends on purpose, context, scale, the Article 6 basis, the precise Article 9 condition and supporting national law. It also depends on what combined or derived information the system reveals. A checklist can identify the questions, but it cannot supply a missing legal power.
Information can also be highly sensitive without falling within Article 9 or Article 10. That does not make it unprotected. The ordinary GDPR principles and security duties still apply. Classify the data accurately, then apply the controls required by the actual risk.
What to do next
Create a short register of every process that uses health, genetic, biometric, belief, union, political, origin, sex-life or sexual-orientation information. For each process, record the Article 6 basis and Article 9 condition separately. Check inferences and national-law limits, then decide whether a DPIA and additional safeguards are required.
Place that record within the wider controls described in AI governance under GDPR and the AI Act. Confirm who decides the purpose using controller or processor, bind service providers through the data processing agreement guide, and check territorial scope through whether GDPR applies outside the EU.
Frequently asked questions
What is special category data under the GDPR?
Special category data is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, plus genetic data, biometric data used for unique identification, health data and data about a person's sex life or sexual orientation. Article 9 starts by prohibiting its processing unless a listed exception applies.
Is all biometric data special category data?
No. Article 9 names biometric data only when it is processed for the purpose of uniquely identifying a natural person. A photograph is therefore not automatically special category data. The purpose and method matter: a facial template used to authenticate an employee may qualify even where the original image looked ordinary.
Does explicit consent make special category processing lawful?
Explicit consent is one Article 9 condition, but it is not a complete legal answer. The controller must also identify an Article 6 lawful basis and meet the GDPR's consent requirements. Union or Member State law may also provide that the person cannot lift the Article 9 prohibition by consent in a particular setting.
Can ordinary personal data become special category data by inference?
Yes. The Court of Justice has held that data capable of indirectly disclosing sexual orientation through comparison or deduction can fall within Article 9. A controller cannot avoid the stronger rules merely by omitting a sensitive label. It must assess what information the data and the processing actually reveal.
Is a DPIA always required for special category data?
Not solely because any special category data appears in a process. Article 35 expressly requires a data protection impact assessment for large-scale processing of Article 9 data. Other risk factors may also make one necessary. A small firm should assess scale, context, purpose, affected people and likely impact rather than apply an automatic yes or no.
Is criminal-offence data special category data?
No. Personal data about criminal convictions and offences is governed separately by Article 10, not included in Article 9's list. It still receives additional protection: processing must be under official authority or authorised by Union or Member State law with appropriate safeguards. Do not use an Article 9 condition as a substitute.
Frequently Asked Questions
What is special category data under the GDPR?
Is all biometric data special category data?
Does explicit consent make special category processing lawful?
Can ordinary personal data become special category data by inference?
Is a DPIA always required for special category data?
Is criminal-offence data special category data?
Sources
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.