Understanding Sensitive Personal Data

Sensitive personal data, often referred to as special category data under the General Data Protection Regulation (GDPR), includes information of a highly private and personal nature. There are additional protections for sensitive personal data that all organisations that process personal data must understand. Understanding what constitutes sensitive data is also fundamental to ensuring its protection. In addition there are significant risks to processing data of this type.

Any data breach can lead to consequences, but because of the high risk of harm or distress to the people affected any breach related to special category data will be treated much more seriously.

That is why there are separate rules around processing data or this type on top of the existing rules and fundamental rights the GDPR sets out.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Contents

  1. What is sensitive personal data?

  2. The rules for processing sensitive personal data?

  3. Further reading

What is Sensitive Personal Data?

Sensitive personal data can be broken down into various categories, each with its own unique characteristics and significance. This includes health data, which encompasses medical records and information about an individual’s physical, mental and sexual health. Additionally, racial or ethnic origin data is classified as sensitive personal data, while rules around religious beliefs data protects sensitive faith-based information.

Under the General Data Protection Regulation (GDPR), special category data, or sensitive personal data, refers to specific types of personal information that are considered particularly sensitive due to the potential risks associated with their processing. Handling such data requires stricter safeguards and is subject to more stringent regulations. Here are the different types of special category data under the GDPR, along with examples:

Health Data

Information about an individual’s physical, mental or sexual health, including medical history, diagnoses, treatment records, and health conditions.

Examples include medical records, prescription information, social care records, mental health history, or any adjustments needed to account for a disability.

Racial or Ethnic Origin

Anything that reveals an individual’s racial or ethnic background. For example, records indicating a person’s ethnicity, nationality, or race, including self-identification as part of a specific racial or ethnic group.

Religious Beliefs and Philosophical Beliefs

Any information about an individual’s religion, or their philosophical, or moral beliefs. This includes records of religious affiliations, memberships of congregations of places of worship, philosophical beliefs, or moral convictions.

Biometric Data

Biometrics data is made up of unique physical or behavioral characteristics that can be used to identify an individual, including fingerprints, facial recognition data, and iris scans.

Biometric data, a subcategory of sensitive personal data, involves the measurement and analysis of unique physical or behavioral traits, such as fingerprints or facial recognition. It is of paramount importance to ensure the security and responsible use of biometric data, given its unique nature.

Political Opinions

This includes information about an individual’s political beliefs, affiliations, or opinions. Note this is different from philosophical or moral beliefs outlined above. Examples include the membership of a political party, political donations, or public statements expressing political views.

Trade Union Membership

This includes data revealing an individual’s membership in a trade union or similar labor organisation, and any trade union related activity.

Protecting political opinions and trade union membership data is essential in safeguarding individuals’ rights to express their political affiliations and participate in collective bargaining. Handling this information with care is crucial to prevent discrimination or misuse.

Data Concerning Sexual Orientation

Information about an individual’s sexual orientation or preferences, including records of an individual’s sexual orientation, including information about their sexual identity or relationships.

Data concerning an individual’s sexual orientation is highly sensitive and personal. Preserving the privacy and identity of individuals is a paramount concern in handling this type of data, as it carries the potential for discrimination and harm.

Genetic Data

Any data relating to an individual’s inherited or acquired genetic characteristics. This includes DNA sequences, genetic test results, and information about genetic predispositions to diseases.

Genetic data is a blueprint of an individual’s identity, carrying information about their inherited traits. Health data, including medical history and records, is equally sensitive. Special protections and security measures are necessary to safeguard the confidentiality and integrity of this information.

Criminal Offence Data

This relates to an individual’s criminal history, including criminal allegations, arrests, convictions, and related legal proceedings. Examples include criminal records, court documents, details of arrests or convictions.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Rules for Special Category Data

Sensitive personal data, or special category data, needs particular care to ensure it is shared and processed lawfully.

While you still need to comply with the privacy principles and the lawful bases for data processing set out above, for data of this type you will need an additional lawful basis before you can proceed.

There are 10 different circumstances under which you may lawfully process sensitive personal data. Some are allowed under the GDPR, while others have conditions attached to them by the Data Protection Act 2018.

In addition, some of these require you to have a special policy document in place, and others (particularly if there is a high risk to the people whose data you are processing) require you to undertake a Data Privacy Impact Assessment (DPIA).

Remember that the data privacy principles still apply. Your data processing must always be lawful, fair, and transparent; and you can only process the minimum necessary data for the purpose in question.

The lawful bases for processing special category data are:

  • Explicit consent

  • Vital interests

  • Not-for-profit bodies

  • Made public by the data subject

  • Legal claims or judicial acts

  • Employment, social security, and social protection (if authorised by law)

  • Health or social care (with a basis in law)

  • Public health (with a basis in law)

  • Archiving, research and statistics (with a basis in law)

  • Reasons of substantial public interest (with a basis in law)

Only some types of sensitive personal data may be processed under each condition. They do not create a lawful basis for processing all sensitive personal data about a person.

 Consent

 Where you have sought consent for the specific data processing, and are clear about the purposes, then you may rely on consent for the processing of sensitive personal data.

The usual standards of consent apply it must be:

  • freely given

  • via unambiguous, affirmative action

  • separate from any other consent for data processing you are seeking.

It is also necessary to be careful not to make consent a precondition of access to services for which sensitive personal data are not necessary. You should also be mindful of not putting people in a position where they feel they cannot say ‘no’.

This seems simple but be careful that consent is the right lawful basis. From the sections above, you will have seen (or will see later if you skipped ahead) that it is not easy to apply.

Vital interests

For truly life and death situations, you can process sensitive personal data in order to protect anyone (not just the data subject).

This condition can only apply if the data subject is incapable of giving consent. If they are capable of giving consent, then you must seek it – and if they refuse consent you cannot override this. Capacity to give consent may be lacking due to either physical injury, cognitive impairment, or a lack of ability to understand for some other reason – for example if the data subject is a very young child.

Not-for-profit organisations

If you are a not-for-profit organisation; you process data about your members, former members, and other people who have regular contact with your organisation; you have appropriate safeguards in place; and you do not disclose the data more widely, then you may process sensitive personal data.

This is an unusual lawful basis because it does not relate to the purpose, but the type of organisation. A not-for-profit organisation means organisations like:

  • Charities

  • Political parties

  • Religious groups

  • Trade unions etc.

The organisation must have a “political philosophical, religious or trade union aim”.

The lawful basis is restricted in terms of who it applies to. It does not cover employees, suppliers, or people who may become members in the future.

Organisations must be careful to comply with the data privacy principles. This means, for example, a religious organisation might find it difficult to process the health data of its members under this basis as it is unlikely to be fair, necessary for the activities of the organisation, or the minimum necessary data for religious activities.

Made public by the data subject

You can process sensitive personal data if the data subject themselves has deliberately put that information in the public domain.

While this looks broad, care must be taken. A social media post, for example, may not necessarily meet this standard just because someone failed to change the privacy settings on their social media account. Alternatively, if someone chooses to include sensitive personal information in their blog posts, articles they have written, or their online CV, then clearly they have chosen and acted, to make that information fully public in the sense they wanted anyone to be able to find, read and use that information.

The data must be made public by the data subject. If anyone else makes it public, this lawful basis does not apply.

Remember the principle of accountability still applies – you are accountable for demonstrating that you applied this lawful basis properly. And, when thinking about relying on this lawful basis, you must still be fair and must still use the minimum necessary data.

Legal claims and judicial acts

You can rely on this basis if you can show it is necessary to process the data to “establish, exercise and defend legal claims”.  This means not only for actual or prospective court cases but to obtain legal advice or to exercise or defend your legal rights in any other way. Sensitive personal data may also be processed by courts or tribunals where they need to do so as part of their judicial duties.

Employment, social security, and social protection

Because employers are legally obliged to make certain checks and process certain types of information, the GDPR and Data Protection Act 2018, allow for the processing of sensitive personal data when it is necessary for this purpose.

Examples where this might be appropriate include:

  • checking people’s right to work in the UK

  • maintaining accurate records of sickness absence

  • deducting trade union dues.

The same legal provision allows public authorities to make social security or benefit payments or provide social care.

In either case, you must be able to say which statutory requirement you are complying with, and your processing must be both necessary and proportionate. This lawful basis does not apply for the purposes of fulfilling an employment contract. It only applies where the processing is required by law.

You must have an appropriate policy document in place when using this lawful basis

Health or social care

A health or social care professional – someone who is under a professional duty of confidentiality – may process sensitive personal data if there is a basis in law to do so for the following purposes:

  • preventative or occupational medicine

  • the assessment of the working capacity of an employee

  • medical diagnoses

  • providing health or social care

  • the management of health or social care systems.

This provision enables health and social services to process sensitive personal data to provide care to individuals, and also to plan, commission and pay for services.

This is different to sharing data for employment purposes. You cannot, for example, use this lawful basis to refer an employee to occupational health services. For that you can use the lawful basis that allows data to be shared for employment purposes.

Public health (with a basis in law)

If there are appropriate safeguards of professional confidentiality in place, then sensitive personal data may be processed where it is necessary for reasons of public interest in the area of public health.

This is quite broad. To use this lawful basis properly you must be able to:

  • demonstrate the processing is necessary

  • demonstrate there is a benefit to the wider public that outweighs an individual’s privacy

  • have a basis in law of some sort

  • have your data collection or processing done or overseen by a medical professional

  • only share data with people that have a duty of professional confidentiality.

This lawful basis does not mean you can share the identifiable medical data of large numbers of people, for example, for research purposes. In these circumstances, you may well be able to use anonymised or pseudonymised data.

Archiving, research, and statistics

You may process sensitive personal data for scientific and historical research, statistical purposes, or for archiving where it is in the public interest.

To be lawful your processing must meet the conditions set out in section 19 of the Data Protection Act 2018 and Article 89 of the GDPR. Specifically, you may not process data in this way if it is likely to cause substantial damage or distress to the data subject; or where your aim is to make decisions about the individual data subject. The exception to this is where you are undertaking medical research.

In addition, you must ensure that you do use only the minimum necessary data and do not process personal identifiable data for longer than necessary.

It’s essential to note that data controllers must carefully assess and document the lawful basis for processing sensitive personal data. Additionally, they should implement strict security measures and data protection practices to safeguard this highly sensitive information, as violations of GDPR rules related to special category data can result in severe penalties.

Further Reading

  1. Introduction to the GDPR

  2. Personal data processing defined

  3. The data privacy principles

  4. People’s GDPR rights

  5. GDPR breaches: offences and penalties

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

Conclusion: Understanding Special Category Data

It’s important to note that the GDPR imposes strict regulations on the processing of special category data. Data controllers must typically obtain explicit consent from the data subject to process such data unless specific exceptions apply. Additionally, robust security measures and data protection practices are required to safeguard the confidentiality and integrity of this highly sensitive information. Violations of GDPR rules related to special category data can result in significant fines and legal consequences.

Sensitive personal data under the GDPR demands special attention and care. Its protection is not only a legal obligation but also a moral imperative to safeguard the privacy, identity, and dignity of individuals. Adherence to GDPR guidelines, along with implementing comprehensive data protection practices, ensures that sensitive data remains secure and confidential in an increasingly data-driven world.

The GDPR imposes stringent requirements for the processing of sensitive personal data. Consent, particularly explicit consent, plays a crucial role in ensuring that individuals provide informed and voluntary agreement for the processing of their sensitive data. However, exceptions and special conditions exist, allowing for the legitimate processing of such data when necessary.