Special Categories of Data
Special categories of data are types of personal information considered particularly sensitive, so they are subject to stricter controls than ordinary personal data. Under EU and UK data protection law, this includes information revealing things such as a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership. Because of the heightened risk to individuals, processing this data is generally prohibited unless a specific legal exception applies.
Under the GDPR (Article 9) and, correspondingly, UK data protection law, 'special categories of personal data' is a defined subset of personal data whose processing is generally prohibited absent an applicable exception. The categories enumerated in Article 9 GDPR include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership, among others cited in the source evidence. Processing of such data may proceed only where an exception to the general prohibition is established under the GDPR (for example, one of the conditions provided in Article 9), and organizations should verify the full list of categories and applicable conditions against the primary legislative text. The precise scope, additional categories, and permitted processing conditions may vary by jurisdiction and by supplementary national law, and specific application often requires legal interpretation; matters beyond the evidence provided here fall outside this definition.
Why it matters
Special categories of data carry heightened risk to individuals because their misuse can lead to discrimination, exclusion, or other serious harms that ordinary personal data may not. For this reason, EU and UK data protection law treats such data differently: rather than being permitted subject to general conditions, its processing is generally prohibited unless a specific legal exception applies. Compliance teams therefore cannot rely on the same lawful bases they use for routine personal data; they must identify an applicable exception before processing can proceed.
The consequence for organizations is that special category data materially raises the compliance burden across data collection, storage, and use. Failing to establish a valid exception, or misclassifying sensitive data as ordinary personal data, exposes an organization to regulatory enforcement and reputational damage. Because the prohibition operates as the default position, the presence of special category data in a system or process is itself a trigger for closer governance scrutiny and documentation.
Applicability varies by jurisdiction and by supplementary national law, and the precise scope of categories and permitted conditions can differ. As a result, treating special category data appropriately is not solely a legal exercise but a matter of ongoing risk management and control design, requiring organizations to verify their obligations against the primary legislative text and, where scope is contested, to obtain legal advice.
Who it's relevant to
Inside Special Categories of Data
Common questions
Answers to the questions practitioners most commonly ask about Special Categories of Data.

