Sensitive personal data, often referred to as special category data under the General Data Protection Regulation (GDPR), includes information of a highly private and personal nature. There are additional protections for sensitive personal data that all organisations that process personal data must understand. Understanding what constitutes sensitive data is also fundamental to ensuring its protection. In addition there are significant risks to processing data of this type.
Any data breach can lead to consequences, but because of the high risk of harm or distress to the people affected any breach related to special category data will be treated much more seriously.
That is why there are separate rules around processing data or this type on top of the existing rules and fundamental rights the GDPR sets out.
Contents
-
What is sensitive personal data?
-
The rules for processing sensitive personal data?
-
Further reading
What is Sensitive Personal Data?
Sensitive personal data can be broken down into various categories, each with its own unique characteristics and significance. This includes health data, which encompasses medical records and information about an individual’s physical, mental and sexual health. Additionally, racial or ethnic origin data is classified as sensitive personal data, while rules around religious beliefs data protects sensitive faith-based information.
Under the General Data Protection Regulation (GDPR), special category data, or sensitive personal data, refers to specific types of personal information that are considered particularly sensitive due to the potential risks associated with their processing. Handling such data requires stricter safeguards and is subject to more stringent regulations. Here are the different types of special category data under the GDPR, along with examples:
Health Data
Information about an individual’s physical, mental or sexual health, including medical history, diagnoses, treatment records, and health conditions.
Examples include medical records, prescription information, social care records, mental health history, or any adjustments needed to account for a disability.
Racial or Ethnic Origin
Anything that reveals an individual’s racial or ethnic background. For example, records indicating a person’s ethnicity, nationality, or race, including self-identification as part of a specific racial or ethnic group.
Religious Beliefs and Philosophical Beliefs
Any information about an individual’s religion, or their philosophical, or moral beliefs. This includes records of religious affiliations, memberships of congregations of places of worship, philosophical beliefs, or moral convictions.
Biometric Data
Biometrics data is made up of unique physical or behavioral characteristics that can be used to identify an individual, including fingerprints, facial recognition data, and iris scans.
Biometric data, a subcategory of sensitive personal data, involves the measurement and analysis of unique physical or behavioral traits, such as fingerprints or facial recognition. It is of paramount importance to ensure the security and responsible use of biometric data, given its unique nature.
Political Opinions
This includes information about an individual’s political beliefs, affiliations, or opinions. Note this is different from philosophical or moral beliefs outlined above. Examples include the membership of a political party, political donations, or public statements expressing political views.
Trade Union Membership
This includes data revealing an individual’s membership in a trade union or similar labor organisation, and any trade union related activity.
Protecting political opinions and trade union membership data is essential in safeguarding individuals’ rights to express their political affiliations and participate in collective bargaining. Handling this information with care is crucial to prevent discrimination or misuse.
Data Concerning Sexual Orientation
Information about an individual’s sexual orientation or preferences, including records of an individual’s sexual orientation, including information about their sexual identity or relationships.
Data concerning an individual’s sexual orientation is highly sensitive and personal. Preserving the privacy and identity of individuals is a paramount concern in handling this type of data, as it carries the potential for discrimination and harm.
Genetic Data
Any data relating to an individual’s inherited or acquired genetic characteristics. This includes DNA sequences, genetic test results, and information about genetic predispositions to diseases.
Genetic data is a blueprint of an individual’s identity, carrying information about their inherited traits. Health data, including medical history and records, is equally sensitive. Special protections and security measures are necessary to safeguard the confidentiality and integrity of this information.
Criminal Offence Data
This relates to an individual’s criminal history, including criminal allegations, arrests, convictions, and related legal proceedings. Examples include criminal records, court documents, details of arrests or convictions.
Sign Up Here:
Sensitive personal data, or special category data, needs particular care to ensure it is shared and processed lawfully. While you still need to comply with the privacy principles and the lawful bases for data processing set out above, for data of this type you will need an additional lawful basis before you can proceed. There are 10 different circumstances under which you may lawfully process sensitive personal data. Some are allowed under the GDPR, while others have conditions attached to them by the Data Protection Act 2018. In addition, some of these require you to have a special policy document in place, and others (particularly if there is a high risk to the people whose data you are processing) require you to undertake a Data Privacy Impact Assessment (DPIA). Remember that the data privacy principles still apply. Your data processing must always be lawful, fair, and transparent; and you can only process the minimum necessary data for the purpose in question. Explicit consent Vital interests Not-for-profit bodies Made public by the data subject Legal claims or judicial acts Employment, social security, and social protection (if authorised by law) Health or social care (with a basis in law) Public health (with a basis in law) Archiving, research and statistics (with a basis in law) Reasons of substantial public interest (with a basis in law) Only some types of sensitive personal data may be processed under each condition. They do not create a lawful basis for processing all sensitive personal data about a person. Where you have sought consent for the specific data processing, and are clear about the purposes, then you may rely on consent for the processing of sensitive personal data. The usual standards of consent apply it must be: freely given via unambiguous, affirmative action separate from any other consent for data processing you are seeking. It is also necessary to be careful not to make consent a precondition of access to services for which sensitive personal data are not necessary. You should also be mindful of not putting people in a position where they feel they cannot say ‘no’. This seems simple but be careful that consent is the right lawful basis. From the sections above, you will have seen (or will see later if you skipped ahead) that it is not easy to apply. For truly life and death situations, you can process sensitive personal data in order to protect anyone (not just the data subject). This condition can only apply if the data subject is incapable of giving consent. If they are capable of giving consent, then you must seek it – and if they refuse consent you cannot override this. Capacity to give consent may be lacking due to either physical injury, cognitive impairment, or a lack of ability to understand for some other reason – for example if the data subject is a very young child. If you are a not-for-profit organisation; you process data about your members, former members, and other people who have regular contact with your organisation; you have appropriate safeguards in place; and you do not disclose the data more widely, then you may process sensitive personal data. This is an unusual lawful basis because it does not relate to the purpose, but the type of organisation. A not-for-profit organisation means organisations like: Charities Political parties Religious groups Trade unions etc. The organisation must have a “political philosophical, religious or trade union aim”. The lawful basis is restricted in terms of who it applies to. It does not cover employees, suppliers, or people who may become members in the future. Organisations must be careful to comply with the data privacy principles. This means, for example, a religious organisation might find it difficult to process the health data of its members under this basis as it is unlikely to be fair, necessary for the activities of the organisation, or the minimum necessary data for religious activities. You can process sensitive personal data if the data subject themselves has deliberately put that information in the public domain. While this looks broad, care must be taken. A social media post, for example, may not necessarily meet this standard just because someone failed to change the privacy settings on their social media account. Alternatively, if someone chooses to include sensitive personal information in their blog posts, articles they have written, or their online CV, then clearly they have chosen and acted, to make that information fully public in the sense they wanted anyone to be able to find, read and use that information. The data must be made public by the data subject. If anyone else makes it public, this lawful basis does not apply. Remember the principle of accountability still applies – you are accountable for demonstrating that you applied this lawful basis properly. And, when thinking about relying on this lawful basis, you must still be fair and must still use the minimum necessary data. You can rely on this basis if you can show it is necessary to process the data to “establish, exercise and defend legal claims”. This means not only for actual or prospective court cases but to obtain legal advice or to exercise or defend your legal rights in any other way. Sensitive personal data may also be processed by courts or tribunals where they need to do so as part of their judicial duties. Because employers are legally obliged to make certain checks and process certain types of information, the GDPR and Data Protection Act 2018, allow for the processing of sensitive personal data when it is necessary for this purpose. Examples where this might be appropriate include: checking people’s right to work in the UK maintaining accurate records of sickness absence deducting trade union dues. The same legal provision allows public authorities to make social security or benefit payments or provide social care. In either case, you must be able to say which statutory requirement you are complying with, and your processing must be both necessary and proportionate. This lawful basis does not apply for the purposes of fulfilling an employment contract. It only applies where the processing is required by law. You must have an appropriate policy document in place when using this lawful basis A health or social care professional – someone who is under a professional duty of confidentiality – may process sensitive personal data if there is a basis in law to do so for the following purposes: preventative or occupational medicine the assessment of the working capacity of an employee medical diagnoses providing health or social care the management of health or social care systems. This provision enables health and social services to process sensitive personal data to provide care to individuals, and also to plan, commission and pay for services. This is different to sharing data for employment purposes. You cannot, for example, use this lawful basis to refer an employee to occupational health services. For that you can use the lawful basis that allows data to be shared for employment purposes. If there are appropriate safeguards of professional confidentiality in place, then sensitive personal data may be processed where it is necessary for reasons of public interest in the area of public health. This is quite broad. To use this lawful basis properly you must be able to: demonstrate the processing is necessary demonstrate there is a benefit to the wider public that outweighs an individual’s privacy have a basis in law of some sort have your data collection or processing done or overseen by a medical professional only share data with people that have a duty of professional confidentiality. This lawful basis does not mean you can share the identifiable medical data of large numbers of people, for example, for research purposes. In these circumstances, you may well be able to use anonymised or pseudonymised data. You may process sensitive personal data for scientific and historical research, statistical purposes, or for archiving where it is in the public interest. To be lawful your processing must meet the conditions set out in section 19 of the Data Protection Act 2018 and Article 89 of the GDPR. Specifically, you may not process data in this way if it is likely to cause substantial damage or distress to the data subject; or where your aim is to make decisions about the individual data subject. The exception to this is where you are undertaking medical research. In addition, you must ensure that you do use only the minimum necessary data and do not process personal identifiable data for longer than necessary. It’s essential to note that data controllers must carefully assess and document the lawful basis for processing sensitive personal data. Additionally, they should implement strict security measures and data protection practices to safeguard this highly sensitive information, as violations of GDPR rules related to special category data can result in severe penalties. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence. It’s important to note that the GDPR imposes strict regulations on the processing of special category data. Data controllers must typically obtain explicit consent from the data subject to process such data unless specific exceptions apply. Additionally, robust security measures and data protection practices are required to safeguard the confidentiality and integrity of this highly sensitive information. Violations of GDPR rules related to special category data can result in significant fines and legal consequences. Sensitive personal data under the GDPR demands special attention and care. Its protection is not only a legal obligation but also a moral imperative to safeguard the privacy, identity, and dignity of individuals. Adherence to GDPR guidelines, along with implementing comprehensive data protection practices, ensures that sensitive data remains secure and confidential in an increasingly data-driven world. The GDPR imposes stringent requirements for the processing of sensitive personal data. Consent, particularly explicit consent, plays a crucial role in ensuring that individuals provide informed and voluntary agreement for the processing of their sensitive data. However, exceptions and special conditions exist, allowing for the legitimate processing of such data when necessary.Rules for Special Category Data
The lawful bases for processing special category data are:
Consent
Vital interests
Not-for-profit organisations
Made public by the data subject
Legal claims and judicial acts
Employment, social security, and social protection
Health or social care
Public health (with a basis in law)
Archiving, research, and statistics
Further Reading
Conclusion: Understanding Special Category Data
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- October 2022
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: