Skip to main content
The state of ai impact assessment
Category: Data Types & Classification

Special Categories of Personal Data

Also known as: Special Category Data, Sensitive Personal Data
Simply put

Special categories of personal data are types of personal information considered especially sensitive, such as data about a person's race, ethnic origin, political opinions, religious or philosophical beliefs, or sexual orientation. Because this information can create significant risks to individuals if misused, it is given greater protection under data protection law. In general, organisations may not process this data unless a specific exception to the prohibition applies.

Formal definition

Under the EU GDPR (Article 9) and the UK GDPR, 'special categories of personal data' is a defined class of personal data subject to a general prohibition on processing, from which processing is permitted only where an enumerated exception (a lawful condition under Article 9(2)) applies. The category encompasses personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as data concerning health, sex life, or sexual orientation; per ICO guidance it may also extend to related matters such as disability, pregnancy, and gender reassignment insofar as they reveal special category information. This concept is distinct from 'personal data' generally, which does not carry the same heightened restriction, and from criminal offence data, which is governed under a separate provision. The identification of an applicable Article 9(2) condition is in addition to, not a substitute for, establishing a lawful basis for processing under the general provisions. The specific enumerated categories, applicable conditions, and any supplementary national conditions vary by jurisdiction (for example, additional member-state or UK domestic conditions), and interpretation of borderline data types continues to develop; readers should verify against the current authoritative text and relevant supervisory authority guidance.

Why it matters

Special categories of personal data attract heightened protection because their misuse can expose individuals to discrimination, exclusion, or serious harm in ways that ordinary personal data typically does not. Information revealing a person's health, religious beliefs, political opinions, or sexual orientation can affect employment, access to services, personal safety, and social standing. For this reason, the EU GDPR and UK GDPR start from a general prohibition on processing this data and permit it only where a specific enumerated condition applies. Organisations that handle such data without correctly identifying an applicable condition face a materially greater compliance and enforcement risk than they would for ordinary personal data.

The practical significance lies in the two-part burden. Establishing a lawful basis under the general provisions is not sufficient on its own; where special category data is involved, an organisation must additionally satisfy an Article 9(2) condition, and in some cases meet supplementary national conditions. Failing to appreciate this distinction is a common source of non-compliance, particularly where data types are borderline. Data that at first appears mundane may reveal special category information by inference, and per ICO guidance the class may extend to related matters such as disability, pregnancy, and gender reassignment insofar as they reveal special category information.

Because the enumerated categories, applicable conditions, and any supplementary domestic conditions vary by jurisdiction, and because interpretation of borderline data types continues to develop, organisations should not treat a single approach as universally valid. Requirements in the EU and the UK share a common structure but diverge in national detail, and readers should verify obligations against the current authoritative text and the relevant supervisory authority's guidance rather than relying on general assumptions.

Who it's relevant to

Data Protection Officers and Privacy Teams
DPOs and privacy professionals must identify where special category data is present, confirm that both a general lawful basis and an applicable Article 9(2) condition are documented, and account for any supplementary national conditions. They also need to assess borderline data types that may reveal special category information by inference, an area where interpretation continues to develop.
Healthcare and HR Functions
Organisations that routinely handle health data, or HR teams processing information touching on matters such as disability, pregnancy, or gender reassignment, are directly affected because such data may fall within or reveal special categories. These functions should verify that an appropriate condition applies before processing and confirm the position against current supervisory authority guidance.
Legal Counsel and Compliance Officers
Legal and compliance professionals advising on data processing activities need to keep the general prohibition and its exceptions clearly separated from ordinary personal data obligations and from the distinct rules for criminal offence data. Because conditions vary between the EU and the UK and by national law, application to specific circumstances requires professional judgment against the latest authoritative text.
Product and Systems Designers
Those building systems that collect or infer personal data should consider at the design stage whether data elements could reveal special category information, since this determines whether the heightened processing restrictions apply. Early identification supports appropriate safeguards and helps avoid inadvertently processing sensitive data without a valid condition.

Inside Special Categories of Personal Data

Enumerated special categories
Under the GDPR, special categories comprise personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, together with genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a person's sex life or sexual orientation. This is a defined list rather than an open-ended concept.
General prohibition with derogations
Processing of these categories is generally prohibited unless a specific condition applies. The GDPR sets out a set of exceptions, which may include explicit consent, obligations in the field of employment and social security law, protection of vital interests, processing by certain not-for-profit bodies, data manifestly made public by the data subject, legal claims, substantial public interest, health or social care, public health, and archiving, research, or statistical purposes. Availability of these conditions varies and several depend on further EU or Member State law.
Relationship to a lawful basis
A special-category condition is required in addition to, not instead of, a lawful basis for processing. Practitioners generally need to identify both a general lawful basis and an applicable special-category condition before processing.
Distinct treatment of criminal offence data
Data relating to criminal convictions and offences is addressed separately in the GDPR and is not, strictly speaking, part of the special categories, though it is subject to its own restrictions. It should not be conflated with the enumerated special categories.
Jurisdictional variation
The concept as described here reflects the EU GDPR and, in materially similar form, the UK GDPR. Other jurisdictions, including United States frameworks, may use different terminology (such as 'sensitive data') and define the covered categories and conditions differently. The scope described here should not be assumed to be universal.

Common questions

Answers to the questions practitioners most commonly ask about Special Categories of Personal Data.

Is data automatically 'special category' just because it feels sensitive or private, such as financial or location data?
No. Under the GDPR, 'special categories' is a defined, closed list rather than a general test of sensitivity. It covers personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, together with genetic data, biometric data processed for unique identification, and data concerning health, sex life, or sexual orientation. Financial data, location data, and other information many people consider sensitive fall outside this list, though they remain personal data subject to the general obligations of the GDPR. Some jurisdictions and sectoral laws treat additional categories as sensitive, so scope should be verified against the applicable regime.
Does 'special category' status mean processing this data is prohibited?
Not exactly. The GDPR sets a general prohibition on processing special category data, but that prohibition is subject to a set of exceptions or conditions that, where they apply, permit processing. These include explicit consent and other specified grounds tied to purposes such as employment, health, or substantial public interest. The practical effect is not an outright ban but a requirement to identify both a lawful basis under the general rules and a separate applicable condition for processing special category data. Availability of these conditions is fact-specific and interpretations continue to evolve, so the current official text and relevant guidance should be consulted.
How does processing special category data differ in practice from processing ordinary personal data?
In general, processing special category data requires an additional layer of justification and control beyond that for ordinary personal data. Alongside a lawful basis under the GDPR's general provisions, an organization must identify an applicable condition permitting the processing of the special category itself, and in many cases document that assessment. Heightened safeguards, tighter access controls, and a data protection impact assessment may be expected depending on the risk. This describes typical practice under the GDPR; requirements differ across the EU, the United Kingdom, the United States, and other jurisdictions, and application to a particular case requires professional judgment.
Is explicit consent the only way to process special category data?
No. Explicit consent is one of several conditions, but it is not the only route and is not always the most appropriate. Other conditions may apply depending on context, such as those relating to employment and social security obligations, protection of vital interests, activities of certain not-for-profit bodies, data made public by the data subject, legal claims, substantial public interest, health or social care, public health, or archiving, research, and statistics. Which conditions are available and how they are interpreted depend on the applicable law and any supplementary national provisions, so these should be verified against the current official text.
Does encrypting or pseudonymizing special category data remove it from this regime?
Generally not. Data that can still be attributed to an individual, whether directly or by reference to additional information, remains personal data, and where it falls within a special category it continues to attract the associated requirements. Pseudonymization and encryption are recognized safeguards that can reduce risk and support compliance, but they do not by themselves take data outside the special category rules unless the data is rendered genuinely anonymous such that individuals are no longer identifiable. Whether that threshold is met is a fact-specific assessment.
How should an organization determine whether biometric data it holds is special category data?
The distinction generally turns on purpose. Under the GDPR, biometric data is treated as special category data when it is processed for the purpose of uniquely identifying a natural person; the same underlying data used for another purpose may not attract that status. This makes it important to document the specific purpose of processing rather than to classify by data type alone. Interpretation in this area continues to develop and may vary by jurisdiction and sector, so organizations should verify their approach against current authoritative guidance and the applicable text, and treat classification as a matter requiring professional judgment.

Common misconceptions

Any data that feels sensitive or embarrassing counts as a special category.
Under the GDPR the special categories are a closed, defined list. Data such as financial details, precise location, or general personal circumstances may be sensitive in an ordinary sense and still fall outside the legal definition, though it remains protected as ordinary personal data. Some other jurisdictions define 'sensitive data' more broadly, so the boundary depends on the applicable law.
Explicit consent is the only way to process special-category data lawfully.
Explicit consent is one condition among several. The GDPR provides additional grounds, such as employment and social security obligations, substantial public interest, health and social care, and research purposes. Some of these require supporting EU or Member State law, so the appropriate condition depends on the context and jurisdiction.
Identifying a special-category condition means no separate lawful basis is needed.
A special-category condition and a general lawful basis are distinct requirements. Processing generally requires both. Satisfying one does not remove the need to establish the other.

Best practices

Confirm whether the data actually falls within the enumerated special categories under the applicable regime before applying heightened controls, and treat criminal offence data under its own separate rules rather than folding it into the special categories.
Document both a general lawful basis and a specific special-category condition for each processing activity, and record the reasoning so it can be demonstrated on request.
Where a chosen condition depends on further EU or Member State law (or the equivalent under the UK GDPR), verify that the relevant supplementary provisions and any required safeguards are in place.
Map jurisdictional differences where processing spans multiple regions, since the covered categories, terminology, and available conditions can differ between the EU, the UK, the United States, and elsewhere.
Apply proportionate technical and organizational safeguards to special-category data, keeping in mind that these obligations are fact-specific and may scale with the risk and volume involved.
Verify the current definitions and conditions against the latest authoritative text of the relevant regulation and any regulator guidance, as interpretations evolve and provisions may be amended, and seek professional judgment for application to specific circumstances.
Promotional banner for the Pentest Readiness checklist download