Skip to content
Legiscope
Menu
Data Privacy

GDPR Article 9: Processing Special Categories of Data

GDPR Article 9 prohibits processing of special category data (health, biometrics, religion, etc.) except under 10 specific conditions including explicit consent.

In one sentence. GDPR Article 9(1) prohibits the processing of special categories of data — racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for unique identification, health data, sexual orientation. Article 9(2) lists 10 exceptions that lift the prohibition, the most operational being (a) explicit consent and (b) employment/social security obligations. Special category data also requires a lawful basis under Article 6 — the two layers are cumulative.

Article 9 is the most stringent provision in the GDPR. It treats certain categories as inherently dangerous to the data subject and requires both a lawful basis (Article 6) and an Article 9 exception to process them. Get this wrong and the fine sits at the top of the Article 83 scale: up to €20M or 4% of global turnover.

Key takeaways

  • 8 categories are special: racial/ethnic origin, political opinions, religion, trade union membership, genetics, biometrics for ID, health, sexual orientation.
  • Processing is prohibited by default unless one of 10 Article 9(2) exceptions applies.
  • The most operational exceptions: explicit consent, employment/social security law, vital interests, public interest in health.
  • Article 9 layers ON TOP of Article 6 — both must apply.
  • Article 10 separately governs criminal conviction data.

1. Article 9(1): the 8 special categories

Article 9(1) prohibits processing of personal data revealing:

  1. Racial or ethnic origin
  2. Political opinions
  3. Religious or philosophical beliefs
  4. Trade union membership
  5. Genetic data (Article 4(13))
  6. Biometric data for the purpose of uniquely identifying a natural person (Article 4(14))
  7. Data concerning health (Article 4(15))
  8. Data concerning a natural person’s sex life or sexual orientation

Note: biometric data is special only when used for unique identification — biometric measurements for general analytics may not qualify. Photographs are special only when processed by specific technical means allowing identification (CJEU clarifications).

2. Article 9(2): the 10 exceptions

The prohibition is lifted if one of these applies:

§ Exception Typical use case
(a) Explicit consent Patient consenting to medical research, user opting into health-tracking app
(b) Employment / social security obligations Sick leave records, occupational health
© Vital interests where consent impossible Unconscious patient at the ER
(d) Non-profit body processing for political/religious/philosophical/trade union purposes (members only) Political party member lists
(e) Data manifestly made public by the data subject Public political statements
(f) Legal claims or judicial actions Court evidence
(g) Substantial public interest, EU/Member State law Anti-discrimination monitoring
(h) Preventive medicine, occupational medicine, medical diagnosis Hospital records
(i) Public health, EU/Member State law Pandemic surveillance
(j) Archiving / scientific research / statistical purposes Public health research

For private sector: the practical exceptions are (a) explicit consent, (b) employment/social security, © vital interests, and (h) medical/healthcare. Others are highly contextual. Health organisations rely on a narrower set still, and each condition fails in a specific way — see health data under Article 9, which works through (a), (h) with the Article 9(3) secrecy requirement, (i) and (j).

3. The two-layer requirement

Processing special category data requires:

  • Layer 1 (Article 6): any of the six lawful bases (consent, contract, legal obligation, vital interests, public task, legitimate interests)
  • Layer 2 (Article 9): one of the ten Article 9(2) exceptions

Both must apply. Common combinations:

Layer 1 (Article 6) Layer 2 (Article 9) Use case
Consent (a) Explicit consent (a) Health app subscriber
Legal obligation © Employment/social security (b) Payroll for sick days
Legitimate interests (f) Generally forbidden for special categories
Contract (b) Health processing (h) for healthcare contract Telehealth service
Vital interests (d) Vital interests © Emergency medical

Article 9 generally excludes legitimate interests as a Layer 1 basis — the EDPB has clarified that legitimate interests is rarely an appropriate base for special category data.

For special category data, Article 9(2)(a) requires explicit consent. The EDPB (Guidelines 5/2020) clarifies:

  • Standard consent (Article 4(11)) is unambiguous — clear affirmative action
  • Explicit consent is expressly stated — written declaration, signed form, or unambiguous specific oral declaration witnessed and recorded

Practical implementations:

  • Written declaration signed by the data subject
  • Two-step verification (email confirmation after the form)
  • Recorded oral statement in a regulated context (telemedicine)
  • Signed digital signature with strong identity verification

A standard cookie banner check does not qualify as explicit consent for special category data.

5. Member State derogations

Article 9(4) allows Member States to maintain or introduce further conditions, including limitations, for processing genetic data, biometric data, or health data. This means each EU country may have additional rules:

  • France: stricter rules on health data hosting (HDS certification required)
  • Germany: BDSG adds employment-context restrictions
  • Italy: Garante adds restrictions on biometric data
  • Spain: LOPDGDD adds rules on genetic data

A multi-jurisdiction processor of health data must check each Member State’s overlay. The full compliance picture for the sector — controller mapping, why consent usually fails in a clinical setting, and the national layer — is set out in GDPR for healthcare organisations.

6. Article 10: criminal conviction data

Article 10 separates criminal conviction data from special categories. It can only be processed:

  • Under control of an official authority, OR
  • When authorized by EU or Member State law providing appropriate safeguards

Examples: AML/KYC checks (under banking law), background checks (under specific employment laws). Private companies cannot generally process criminal conviction data without specific legal authorization.

7. Practical implementation checklist

For each processing of special category data:

  • ☐ Layer 1 lawful basis identified (Article 6)
  • ☐ Layer 2 exception identified (Article 9(2))
  • ☐ For explicit consent: written or recorded declaration, not a checkbox
  • ☐ Privacy notice (Article 13) explicitly mentions the special category
  • ☐ DPIA conducted (special category data at scale = mandatory under Article 35)
  • ☐ Heightened Article 32 security measures (encryption mandatory, strict access control)
  • ☐ Member State-specific derogations checked
  • ☐ Sub-processors with special category access have enhanced data processing agreement clauses
  • ☐ Retention period documented and justified

8. Sanctions

Article 83(5) places Article 9 violations at the top tier — up to €20M or 4% of global turnover.

Notable cases:

  • Clearview AI (CNIL, 2022): €20M for biometric processing without lawful basis
  • Hôpital de Bourges (CNIL, 2022): €60K for inadequate security on health data
  • Marriott (ICO, 2020 — partly Article 9): for special category data exposed in breach
  • H&M (Hamburg DPA, 2020): €35.3M including special category data on employees

9. Tooling

Official sources: Article 9 (processing of special categories of data) of Regulation (EU) 2016/679 on EUR-Lex, the EDPB guidelines, recommendations and best practices register, and the ICO guidance.

Conclusion

Article 9 is the strictest GDPR provision because it protects the data most likely to harm the data subject if misused. The two-layer requirement (Article 6 + Article 9) is non-negotiable. For private sector, explicit consent and employment/social security are the realistic exceptions; legitimate interests is rarely available. Document both layers in the ROPA, use explicit consent (not standard consent), and build heightened security in by design.

FAQ

What categories of data are “special” under GDPR Article 9?

Eight categories: racial/ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for unique identification, health data, sex life or sexual orientation.

Can I rely on legitimate interests to process health data?

Generally no. Article 9 requires a specific exception in addition to a lawful basis under Article 6. Legitimate interests is rarely an appropriate base for special categories. Use explicit consent or a specific Article 9(2) exception (employment, healthcare, public health).

Standard consent (Article 4(11)) requires unambiguous indication via clear affirmative action — a checkbox click typically suffices. Explicit consent (Article 9(2)(a)) requires an express statement — written declaration, signed form, or unambiguous oral statement. A cookie banner is not explicit consent.

Are biometric data always special category data?

Only when processed for the purpose of uniquely identifying a natural person. Biometric measurements for general analytics or aggregate statistics may not qualify. Facial recognition for access control is special; counting visitors via anonymous face detection is not.

Is criminal conviction data covered by Article 9?

No — criminal conviction data is governed by Article 10. It can only be processed under official authority or specific EU/Member State law authorization.

L
Written by
Legiscope
Legiscope

Put this guidance into operation

See how Legiscope connects privacy records, source material and review-controlled work.

Book a tailored demo
Continue reading

Related articles

01GDPR Compliance

Health Data Under Article 9 GDPR: Lawful Conditions

Art. 9(2) offers ten conditions. A health organisation will use four of them, and each one fails in a specific, predictable way. The failures are not exotic: a consent that cannot lawfully be…

July 30, 2026
02Data Privacy

Australia–EU Data Transfers: Adequacy Status and SCCs

Australia does not hold an EU adequacy decision. Verified against the European Commission's published list of adequacy decisions on 30 July 2026. Australia has never held one, is not the subject of…

July 30, 2026
03Data Privacy

BCR vs SCC vs DPF: Choosing the Right GDPR Transfer Mechanism

GDPR Article 46 lists multiple safeguards for international data transfers. Three dominate practice: Binding Corporate Rules (BCRs), Standard Contractual Clauses (SCCs), and the EU-U.S. Data Privacy…

April 30, 2026
04Data Privacy

Best DPO Software 2026: Internal & Outsourced DPOs

The DPO role is defined by Art. 37-39 GDPR, and the EDPB made it a 2023 coordinated-enforcement priority — so the software a DPO uses is now itself an accountability signal.

July 7, 2026
05Data Privacy

Best GDPR Compliance Software: 6 Tools Compared + Pricing 2026

Choosing the right GDPR compliance software is no longer optional for small and medium-sized enterprises operating in the EU. Data protection authorities across Europe have shifted enforcement focus…

March 28, 2026
06Data Privacy

Canada-EU Data Transfers: Adequacy Scope and SCCs

Canada is one of the few countries the European Commission has recognised as offering adequate protection, and it is the country where that recognition is most often over-read. The decision is…

July 30, 2026
07Data Privacy

Cassie (Syrenis) Alternatives & Comparison 2026

For a regulated-industry DPO, that distinction is the whole decision. Consent is one lawful basis under Art. 6(1)(a) GDPR; a compliance program is everything around it.

July 9, 2026
08Data Privacy

Consent Management Platforms Compared (2026)

Choosing the right consent management platform is one of the most consequential technical decisions an organisation makes for privacy compliance. A poorly configured CMP exposes you to enforcement…

March 28, 2026