Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Category: Privacy & Data Protection

Special Categories of Data

Also known as: Special Category Data, Sensitive Personal Data
Simply put

Special categories of data are types of personal information considered particularly sensitive, so they are subject to stricter controls than ordinary personal data. Under EU and UK data protection law, this includes information revealing things such as a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership. Because of the heightened risk to individuals, processing this data is generally prohibited unless a specific legal exception applies.

Formal definition

Under the GDPR (Article 9) and, correspondingly, UK data protection law, 'special categories of personal data' is a defined subset of personal data whose processing is generally prohibited absent an applicable exception. The categories enumerated in Article 9 GDPR include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership, among others cited in the source evidence. Processing of such data may proceed only where an exception to the general prohibition is established under the GDPR (for example, one of the conditions provided in Article 9), and organizations should verify the full list of categories and applicable conditions against the primary legislative text. The precise scope, additional categories, and permitted processing conditions may vary by jurisdiction and by supplementary national law, and specific application often requires legal interpretation; matters beyond the evidence provided here fall outside this definition.

Why it matters

Special categories of data carry heightened risk to individuals because their misuse can lead to discrimination, exclusion, or other serious harms that ordinary personal data may not. For this reason, EU and UK data protection law treats such data differently: rather than being permitted subject to general conditions, its processing is generally prohibited unless a specific legal exception applies. Compliance teams therefore cannot rely on the same lawful bases they use for routine personal data; they must identify an applicable exception before processing can proceed.

The consequence for organizations is that special category data materially raises the compliance burden across data collection, storage, and use. Failing to establish a valid exception, or misclassifying sensitive data as ordinary personal data, exposes an organization to regulatory enforcement and reputational damage. Because the prohibition operates as the default position, the presence of special category data in a system or process is itself a trigger for closer governance scrutiny and documentation.

Applicability varies by jurisdiction and by supplementary national law, and the precise scope of categories and permitted conditions can differ. As a result, treating special category data appropriately is not solely a legal exercise but a matter of ongoing risk management and control design, requiring organizations to verify their obligations against the primary legislative text and, where scope is contested, to obtain legal advice.

Who it's relevant to

Compliance officers and data protection professionals
Those responsible for data protection compliance must identify when special category data is being processed, confirm that a valid exception to the general prohibition applies, and document that basis. Because these categories are subject to stricter controls than ordinary personal data, they warrant dedicated attention within a compliance program.
General counsel and legal teams
Legal teams are often called upon to interpret whether particular data falls within the special categories and which exceptions under the GDPR or applicable national law permit its processing. Given that scope and conditions can vary by jurisdiction and frequently require legal interpretation, legal advice is central to defensible processing decisions.
Risk managers
Because processing special category data creates heightened risk to individuals, risk managers should treat its presence as a factor in assessing and prioritizing data-related risks, and in confirming that appropriate controls are in place before processing proceeds.
Internal auditors
Auditors reviewing data processing activities can test whether special category data has been correctly identified, whether a documented exception supports its processing, and whether controls reflect the stricter treatment such data typically requires under EU and UK data protection law.

Inside Special Categories of Data

Definition and scope
Special categories of data (sometimes referred to as sensitive personal data) is a term used most prominently under the EU General Data Protection Regulation (GDPR) to designate certain types of personal data whose processing is generally prohibited unless a specific condition applies. The precise categories and treatment vary by jurisdiction, so the term should be interpreted against the applicable legal framework rather than as a universal standard.
Enumerated categories (GDPR context)
Under the GDPR, special categories typically include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership, as well as genetic data, biometric data processed for the purpose of uniquely identifying a person, data concerning health, and data concerning a person's sex life or sexual orientation. Practitioners should verify the exact wording against the primary legal text, as scope can be subject to interpretation.
General prohibition and conditions for processing
In many frameworks the default position is that processing of these categories is prohibited unless a specific legal condition or exception is met, such as explicit consent or other narrowly defined grounds set out in the applicable law. The availability and wording of these conditions are jurisdiction-specific and often require legal interpretation.
Relationship to other categories of data
Special categories are typically distinguished from ordinary personal data and, in some frameworks, from separate regimes covering data such as criminal conviction and offence data, which may be treated under distinct provisions. The boundaries between these categories can be context-dependent.
GRC relevance
The concept spans the compliance and risk management pillars: it creates binding compliance obligations where the relevant law applies, and it informs risk assessment because processing such data often carries heightened potential for harm to individuals. Governance considerations may also arise where organizations must assign decision rights and accountability for handling such data.

Common questions

Answers to the questions practitioners most commonly ask about Special Categories of Data.

Does labeling data as 'special category' mean it is simply more sensitive and must be encrypted more heavily?
Not exactly. 'Special categories of data' is a defined legal classification under the EU GDPR (in Article 9) covering specific types of personal data, rather than a general sensitivity rating. The classification triggers a distinct legal regime: such data is broadly prohibited from processing unless a specific condition applies. Enhanced security measures may be a reasonable outcome of processing this data, but the defining feature is the legal restriction on processing itself, not the strength of any particular control. Treating the category as merely 'high-sensitivity' can lead organizations to overlook the requirement to identify a lawful condition before processing at all. Applicability and the precise conditions vary by jurisdiction and context, and legal interpretation should be confirmed against the primary source.
Is a lawful basis under GDPR Article 6 enough on its own to process special category data?
Typically no. Processing special category data commonly requires both a lawful basis for processing personal data generally and a separate condition that lifts the prohibition on processing the special category itself. These are often described as two distinct requirements that must each be satisfied, not a single test. Relying on a general lawful basis alone, without identifying an applicable condition for the special category, is a frequent misconception. The specific conditions and any national derogations differ by jurisdiction, so the applicable requirements should be verified against the relevant law and any supervisory guidance, and complex cases may warrant professional legal advice.
How do we identify where special category data exists across our systems?
Many organizations approach this through data mapping or data inventory exercises that trace where personal data is collected, stored, processed, and shared. In practice, identifying special category data can be challenging because it may appear in unstructured form, such as free-text notes, or be inferred from other data. It is often useful to involve business process owners who understand the actual content of records rather than relying solely on field labels. Because whether particular data falls within a special category can be context-dependent and a matter of legal interpretation, borderline cases should be assessed with appropriate legal input. This describes a common practice rather than a prescribed method under any single framework.
What should we consider when documenting the condition we rely on to process special category data?
Documentation practices commonly include recording which condition is being relied upon, the corresponding general lawful basis, and the purpose of the processing. Where a particular condition depends on additional safeguards or on national law, organizations often document how those requirements are met. Maintaining this record can support accountability, which is a recurring theme in data protection frameworks. Because the available conditions and any supplementary requirements vary by jurisdiction, the specific documentation expected should be confirmed against the applicable law and supervisory guidance rather than assumed.
How does processing special category data relate to a data protection impact assessment?
Processing special category data, particularly at scale, is often treated as a factor that may indicate higher risk and can be relevant to whether a data protection impact assessment (DPIA) is appropriate or required. A DPIA is generally a structured process for assessing risks to individuals arising from processing and for identifying measures to address them. Whether a DPIA is mandatory in a given situation depends on the applicable legal criteria and any supervisory authority guidance, which vary by jurisdiction. Organizations should verify the specific triggers rather than assume that any single factor is determinative.
What controls do organizations typically apply once special category data is in scope?
Common measures include restricting access on a need-to-know basis, applying access logging, considering pseudonymization or minimization where feasible, and reviewing retention so that such data is not held longer than necessary for the stated purpose. These are risk-treatment measures intended to modify risk rather than eliminate it, and no control should be assumed to guarantee compliance or remove risk entirely. The appropriate combination of controls depends on the processing context, the identified risks, and any legal requirements applicable in the relevant jurisdiction, so specifics should be validated against those sources.

Common misconceptions

Special categories of data is a globally standardized list that applies the same way everywhere.
The term is most closely associated with the GDPR, and both the enumerated categories and the conditions for processing vary by jurisdiction, sector, and applicable law. What qualifies as sensitive and how it may be lawfully processed should be confirmed against the primary source relevant to the organization.
Because processing is generally prohibited, special categories of data can never be processed.
In many frameworks the prohibition is a default that can be overcome where a specific legal condition or exception applies. The existence and applicability of such conditions depend on the governing law and often require legal interpretation for the specific situation.
Classifying data as a special category is itself a control that reduces or eliminates risk.
Classification is an input to risk assessment and compliance, not a control that modifies risk on its own. Identifying data as sensitive typically indicates elevated potential for harm; controls still need to be designed and applied, and no control should be assumed to eliminate risk or guarantee compliance.

Best practices

Confirm which legal framework applies to your processing and verify the exact enumerated categories and conditions against the primary legal text rather than relying on a generic list.
Maintain an inventory or data mapping that flags where special categories of data are collected, stored, or processed, so heightened obligations can be identified early.
Before processing, document the specific legal condition or exception relied upon, and involve legal counsel where the applicability of a condition requires interpretation.
Treat the presence of special categories as a trigger for enhanced risk assessment, distinguishing inherent risk from residual risk once controls are applied.
Design and document proportionate controls for handling such data, recognizing that classification alone does not reduce risk and that no control should be assumed to eliminate it.
Reassess classifications and legal bases periodically, since framework language, jurisdictional requirements, and organizational processing activities can change over time.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide