Specially protected data —also called sensitive data or special categories of data— are the class of personal information to which the GDPR grants the highest level of protection. They are not data to be handled with more care: they are data whose processing starts, as a general rule, from a prohibition. This guide explains what they are exactly, which categories art. 9 GDPR comprises, under what exceptional conditions that prohibition can be lifted and why their handling is subject to severe restrictions and reinforced safeguards.
In 15 seconds
- They are the special categories of art. 9 GDPR: health, racial or ethnic origin, ideology, religion, trade union membership, genetic data, biometric data for identification, sex life and sexual orientation.
- Their processing is prohibited as a general rule (art. 9.1) unless one of the exhaustive exceptions of art. 9.2 applies.
- The dual-basis doctrine applies: you need simultaneously an exception of art. 9.2 and a lawful basis of art. 6.
- Criminal data is not in art. 9: it has its own restrictive regime in art. 10 GDPR.
What is specially protected data?
Specially protected data are the special categories of personal data referred to in art. 9 of the GDPR. They are colloquially known as "sensitive data" because their improper processing can generate a high risk of discrimination, exclusion or harm to the person: revealing someone's illness, their political ideology or their sexual orientation is not comparable to knowing their email address.
That is why the Regulation does not merely require more caution. It sets a different starting point: while the processing of an ordinary piece of personal data is lawful if one of the bases of art. 6 applies, that of a special category piece of data is prohibited unless, in addition, one of the specific exceptions of art. 9.2 is met. The sensitivity of the data reverses the logic: the question is not "can I process it?", but "is there an exception that lets me lift the prohibition?".
It is worth settling the terminology from the outset to avoid common confusion: "specially protected data", "sensitive data" and "special categories of data" are three names for the same thing. And there is a fourth category, criminal data, which practice tends to lump into the same bag but which technically does not belong to art. 9: it is governed by art. 10, with a regime even more restricted, which we will see later.
The special categories of art. 9 GDPR, one by one
Art. 9.1 GDPR lists exhaustively which data merits this reinforced protection. It is not an open or expandable list at the company's discretion: they are exactly these categories. The following table sets them out with examples of the type of information each one encompasses.
| Category (art. 9.1) | What it comprises |
|---|---|
| Racial or ethnic origin | Information revealing a person's ethnic or racial origin. |
| Political opinions | A person's ideology, leaning or political stance. |
| Religious or philosophical beliefs | Religious beliefs or convictions of a philosophical or moral nature. |
| Trade union membership | Belonging or affiliation to a trade union. |
| Genetic data | Data relating to inherited or acquired genetic characteristics that provide information about physiology or health (art. 4.13). |
| Biometric data for unique identification | Biometric data (art. 4.14) when processed for the purpose of uniquely identifying a natural person. |
| Data concerning health | Data on physical or mental health, past, present or future, including the provision of healthcare services (art. 4.15). |
| Sex life or sexual orientation | Data concerning a person's sex life or sexual orientation. |
Two important clarifications about this list. The first concerns biometric data: a fingerprint, a face or an iris only become a special category when processed for the purpose of uniquely identifying a person. However, this technical nuance must not be read as an easy route: the criterion of the AEPD regarding the use of biometrics for identification —notably in access or attendance control— is markedly strict, and it presumes the unlawfulness of these processing operations where a less intrusive alternative exists. Resorting to biometrics requires passing a strict necessity and proportionality test, and it is in no case a default option.
The second concerns health data, which is by far the category that most organisations stumble upon without realising. You do not need a clinical record to process health data: a sick note, an allergy recorded on a form, a disability certificate or the simple record that an employee was absent "due to illness" are already health data. Any organisation that manages staff handles, one way or another, this category.
The general rule: their processing is prohibited
Art. 9.1 GDPR is categorical in its wording: the processing of personal data revealing the categories above "shall be prohibited". It does not say "permitted subject to conditions" or "caution is recommended". It starts from a general prohibition that falls away only if one of the exceptions of the following paragraph applies.
This inversion of the ordinary logic has a practical consequence worth internalising. With normal data, the organisation chooses among several lawful bases of art. 6 and justifies its choice. With special category data, the starting point is that it may not process it, and the burden of finding and documenting the applicable exception falls on it. It is not enough for the processing to be useful, convenient or even reasonable: if it does not fit within one of the exhaustive exceptions, it is simply not allowed.
That is why, before collecting any sensitive data, the right question is not "is it handy for me to have it?", but "under which exception of art. 9.2 may I process it, and do I really need it?". Many incidents arise from collecting health or orientation data —in a form, a record or a survey— without first having asked that question.
The exhaustive exceptions of art. 9.2
Art. 9.2 GDPR contains the closed list of situations in which the prohibition of paragraph 1 can be lifted. They are exhaustive exceptions: outside them there is no room. The most relevant in business and association practice are:
- Explicit consent (art. 9.2.a). The data subject explicitly consents to the processing for one or more specified purposes. It is a reinforced consent, more demanding than the ordinary one, and —as will be seen— the LOPDGDD limits its scope in certain cases.
- Employment and social security field (art. 9.2.b). Processing necessary to carry out obligations and exercise rights in the field of employment, social security and social protection law, where authorised by a rule with appropriate safeguards.
- Vital interests (art. 9.2.c). Protection of the vital interests of the data subject or of another person where the data subject is physically or legally incapable of giving consent.
- Foundations, associations and non-profit bodies (art. 9.2.d). With a political, philosophical, religious or trade union aim, in respect of their members or former members, without disclosing the data outside the body without consent.
- Manifestly public data (art. 9.2.e). Data which the data subject has manifestly made public.
- Claims and courts (art. 9.2.f). Establishment, exercise or defence of legal claims, or courts acting in their judicial capacity.
- Health purposes (art. 9.2.h). Preventive or occupational medicine, assessment of the working capacity, medical diagnosis, provision of health or care. This situation additionally requires the processing to be carried out by a professional subject to the obligation of secrecy (art. 9.3).
- Public health (art. 9.2.i) and archiving, research or statistical purposes (art. 9.2.j), with the safeguards of art. 89.
A warning about explicit consent. Art. 9.1 of the LOPDGDD introduces a significant additional limit: the data subject's consent is not enough on its own to lift the prohibition where the main purpose of the processing is to identify the ideology, trade union membership, religion, sexual orientation, beliefs or racial or ethnic origin. That is, the person saying "yes" does not, in those cases, authorise building a profile on those categories. This reinforcement by the Spanish legislator must always be kept in mind before relying without more on art. 9.2.a.
The dual-basis doctrine: art. 9 + art. 6
This is the point most frequently overlooked. Finding an exception of art. 9.2 does not replace the lawful basis of art. 6: it complements it. To lawfully process a special category piece of data you need both things at once. This is what is known as the dual-basis doctrine.
The reason is that both articles answer different questions. Art. 6 resolves why I may process the data (performance of a contract, legal obligation, legitimate interest…). Art. 9.2 resolves how I lift the specific prohibition weighing on that sensitive category. Lifting the prohibition of art. 9 without having a basis of art. 6 leaves the processing lame; and having a basis of art. 6 without an exception of art. 9 does not authorise touching a prohibited piece of data. You need both pieces fitted together.
An example brings the idea down to earth. A company managing an employee's sick leave usually combines art. 6.1.c (compliance with a legal obligation in the field of employment) with art. 9.2.b (obligations in the field of employment and social security and social protection law). Neither the legal obligation on its own, nor the employment exception on its own, would be enough: it is the sum of the two that covers the processing, and always limited to the strictly necessary data —not the worker's full diagnosis.
"With sensitive data the order of the questions is reversed. You do not start from being able to process it and look for the basis; you start from it being prohibited and you have to prove, data by data, which exception rescues it and why you need it. Whoever does not understand that inversion ends up collecting information they should never have asked for."
Mario P. Talamillo · Managing Partner, Certix®
Criminal data: the separate regime of art. 10
Data relating to criminal convictions and offences is especially sensitive, but —and this surprises many people— it does not form part of art. 9. It has its own regime in art. 10 GDPR, even more restrictive than that of the special categories.
Art. 10 establishes that this type of data may only be processed under the control of an official authority or when authorised by Union or Member State law that offers appropriate safeguards for the rights and freedoms of data subjects. In Spain, art. 10 of the LOPDGDD develops this framework and very narrowly delimits who may process information on criminal convictions and offences outside the sphere of the competent authorities: essentially, when a rule with the rank of law expressly enables it, with the safeguards that law determines.
The practical reading for an ordinary private organisation is direct: it may not set up on its own a register of criminal records of customers, candidates or employees relying on mere consent. Save for specific legal enablement or public control, this processing is barred. It is a terrain where prudence must be maximal and the legal analysis, individualised.
Reinforced safeguards: checklist before processing sensitive data
When the processing of a special category is covered by an exception, the obligation does not end there: a reinforced level of demand begins. These are the points every organisation should verify before handling sensitive data:
- Identify the specific exception of art. 9.2 that lifts the prohibition and keep it documented. A generic "we have consent" is not enough.
- Determine the lawful basis of art. 6 that accompanies it (dual basis) and verify that both fit the real purpose.
- Apply the minimisation principle with particular rigour: collect only the indispensable data. When in doubt, do not ask for it.
- Reflect the processing in the Record of Processing Activities (RoPA), expressly noting that it is a special category.
- Assess whether a Data Protection Impact Assessment (DPIA) is warranted: large-scale processing of special categories usually triggers the obligation of art. 35 GDPR.
- Reinforce the security measures of art. 32: role-based access control, encryption, express confidentiality of staff and access logs.
- Comply with the duty to inform of art. 13 transparently: the data subject must know which category of data is processed, on what basis and for what.
- Watch the reinforced consent and its limits: remember art. 9.1 LOPDGDD when the purpose touches ideology, religion, union membership, sexual orientation, beliefs or racial or ethnic origin.
The general GDPR regulation and its development in the LOPDGDD make up the framework within which all the above sits. It is also worth remembering that the sectoral and regional regulation applicable to certain fields —very especially the health sector— may extend or modify these requirements, so each case requires reviewing the specific regulation applicable to it.
How Certix helps you
Delimiting which of your organisation's data is a special category, which exception of art. 9.2 covers it and which basis of art. 6 accompanies it is not a theoretical exercise: it is the difference between solid processing and one that rests on thin air. And it is an analysis that admits no templates, because it depends on each entity's real activity.
At Certix we analyse your processing operations one by one, we identify where sensitive data appears —often in places the organisation had not noticed—, we set the dual basis that sustains them and we design the reinforced safeguards the rule requires. If your activity involves health, biometric, criminal or any other special category data, individualised analysis is not optional: it is the starting point.
Frequently asked questions
What is the difference between personal data and specially protected data?
All specially protected data is personal data, but not the other way round. A name or a phone number are ordinary personal data. Specially protected data are the special categories of art. 9 GDPR: health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a person, and data concerning sex life or sexual orientation. Their processing starts from a general prohibition and can only be lifted through one of the exhaustive exceptions of art. 9.2.
Is the data subject's consent enough to process sensitive data?
Not automatically. Explicit consent (art. 9.2.a) is one of the possible exceptions, but the LOPDGDD adds a limit in its art. 9.1: consent alone is not enough to cover processing whose main purpose is to identify the ideology, trade union membership, religion, sexual orientation, beliefs or racial or ethnic origin. And even where consent is valid, the processing still requires a basis under art. 6 (dual basis) and reinforced safeguards.
Is criminal data a special category under art. 9 GDPR?
No. Data relating to criminal convictions and offences has its own regime in art. 10 GDPR, separate from art. 9. It may only be processed under the control of an official authority or when authorised by a rule with the rank of law offering appropriate safeguards. The LOPDGDD develops this regime in its art. 10 and notably restricts who may process this information outside the public sphere.
Can my company process its employees' health data?
Only within strict limits and for specific purposes covered by the rule. The processing of health data in the employment context usually relies on art. 9.2.b (obligations of employment and social security and social protection law) or on art. 9.2.h (occupational medicine), always combined with a basis under art. 6. Managing a sick leave does not authorise knowing the diagnosis, but the strictly necessary data. All of this is subject to the minimisation principle and to reinforced safeguards of security and confidentiality.
In short
Specially protected data are not data to be handled with more care, but data whose processing starts from a prohibition. Understanding that inversion —from "can I?" to "which exception allows it?"— is the key to the whole regime of art. 9. Added to it are the dual-basis doctrine, the reinforced safeguards and the even stricter regime of criminal data under art. 10. It is a terrain subject to severe restrictions that requires, in each case, an individualised analysis that no template can replace.
Related reading
- Complete GDPR guide — the regulatory framework within which the special categories sit.
- Complete LOPDGDD guide — the Spanish development, with the limits of arts. 9 and 10.
- Record of Processing Activities (RoPA) — where these processing operations must be reflected.
This content is purely informational and educational; it does not constitute specialised legal advice in any case. Applying the regulations to each specific case requires individual analysis.
Does your organisation process health, biometric or criminal data?
At Certix we analyse your special category processing operations one by one, we set the dual basis that sustains them and we design the reinforced safeguards the rule requires.
Data protection consultancy