CHAPTER IIPRINCIPLES

Article 9Processing of special categories of personal data

Official text

(1)Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation shall be prohibited.

(2)Paragraph 1 shall not apply if one of the following applies:

(a)the data subject has given explicit consent to the processing of those personal data for one or more specified purposes, except where Union or Member State law provide that the prohibition referred to in paragraph 1 may not be lifted by the data subject;

(b)processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law in so far as it is authorised by Union or Member State law or a collective agreement pursuant to Member State law providing for appropriate safeguards for the fundamental rights and the interests of the data subject;

(c)processing is necessary to protect the vital interests of the data subject or of another natural person where the data subject is physically or legally incapable of giving consent;

(d)processing is carried out in the course of its legitimate activities with appropriate safeguards by a foundation, association or any other not-for-profit body with a political, philosophical, religious or trade union aim and on condition that the processing relates solely to the members or to former members of the body or to persons who have regular contact with it in connection with its purposes and that the personal data are not disclosed outside that body without the consent of the data subjects;

(e)processing relates to personal data which are manifestly made public by the data subject;

(f)processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity;

(g)processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject;

(h)processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services on the basis of Union or Member State law or pursuant to contract with a health professional and subject to the conditions and safeguards referred to in paragraph 3;

(i)processing is necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices, on the basis of Union or Member State law which provides for suitable and specific measures to safeguard the rights and freedoms of the data subject, in particular professional secrecy;

(j)processing is necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89 (1) based on Union or Member State law which shall be proportionate to the aim pursued, respect the essence of the right to data protection and provide for suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.

(3)Personal data referred to in paragraph 1 may be processed for the purposes referred to in point (h) of paragraph 2 when those data are processed by or under the responsibility of a professional subject to the obligation of professional secrecy under Union or Member State law or rules established by national competent bodies or by another person also subject to an obligation of secrecy under Union or Member State law or rules established by national competent bodies.

(4)Member States may maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health.

Commentary

Article 9 GDPR - Processing of Special Categories of Personal Data

1. Legislative Philosophy and Objective

1.1. Introduction: Why Article 9 Exists

The General Data Protection Regulation (GDPR) establishes a differentiated framework for protecting personal data. While all personal data requires protection against unlawful processing, the GDPR recognises that certain categories of information carry greater risks to fundamental rights and freedoms. Article 9 addresses this concern by creating a heightened protection regime for what are commonly referred to as “sensitive personal data”, formally defined under the GDPR as “special categories of personal data.”

Article 9 reflects the understanding that misuse of certain information can result not merely in privacy violations but also in discrimination, social exclusion, reputational damage, identity-related harm, and violations of human dignity.

Example

disclosure of a person's name or address may cause inconvenience or security concerns. However, disclosure of their medical condition, religious beliefs, political affiliation, genetic information, or sexual orientation may expose them to workplace discrimination, social stigma, harassment, or unequal treatment. Therefore, the GDPR treats such information as requiring additional safeguards.

Article 9 adopts a fundamentally different regulatory approach from ordinary personal data processing. Instead of merely requiring organisations to identify a lawful basis under Article 6, Article 9 begins with a general prohibition and permits processing only when one of the narrowly defined exceptions applies.

This demonstrates the GDPR's rights-based approach: certain categories of personal information are considered so closely connected with personal identity and autonomy that their processing requires exceptional justification.

1.2. Historical Development: From Data Protection Directive to GDPR

The protection of sensitive information is not new under European data protection law. The previous framework, the Data Protection Directive 95/46/EC, contained similar restrictions under Article 8 concerning the processing of “special categories of data.”

Article 8 of the Directive prohibited processing of data revealing:

  • racial or ethnic origin;

  • political opinions;

  • religious or philosophical beliefs;

  • trade union membership;

  • health;

  • sex life.

However, technological developments significantly expanded the risks associated with sensitive information. The rise of:

  • biometric identification systems,

  • genetic testing companies,

  • artificial intelligence,

  • behavioural analytics,

  • digital healthcare platforms,

created new possibilities for collecting and inferring sensitive information.

The GDPR expanded the scope by expressly including:

  • genetic data;

  • biometric data for unique identification purposes;

  • sexual orientation.

This expansion reflects the recognition that modern technology can reveal highly personal information even when individuals have not directly provided it.

Example

a person may never disclose their health condition to a technology company. However, an artificial intelligence system analysing search behaviour, purchase patterns, wearable device data, or location information may infer potential health conditions. Article 9 therefore focuses not merely on intentional disclosure but also on therisk of revealing sensitive characteristics.

1.3. Relationship with Fundamental Rights

Article 9 must be interpreted in light of the European Union Charter of Fundamental Rights.

Article 7 - Respect for Private and Family Life

Article 7 protects an individual's private and family life, home, and communications. Sensitive personal data is closely linked with personal identity and private autonomy.

Information regarding:

  • medical conditions,

  • religious beliefs,

  • sexual orientation,

  • political views,

forms part of an individual's private sphere. Uncontrolled processing may interfere with personal autonomy and dignity.

Article 8 - Protection of Personal Data

Article 8 of the Charter specifically recognises data protection as a fundamental right.

It requires:

  1. processing based on fair principles;

  2. processing for specified purposes;

  3. control by an independent authority.

Article 9 GDPR operationalises this right by recognising that certain data categories require stronger protection because their misuse can have severe consequences.

Article 52 - Limitations on Fundamental Rights

Article 52 of the Charter provides that restrictions on fundamental rights must:

  • be provided by law;

  • respect the essence of the right;

  • be necessary and proportionate.

This principle explains why Article 9 exceptions are narrowly drafted. Processing sensitive data cannot simply be justified by organisational convenience. There must be a clear legal basis and appropriate safeguards.

2. Understanding “Special Categories of Personal Data”

Article 9(1) identifies specific categories of information that receive enhanced protection.

These categories are:

  1. racial or ethnic origin;

  2. political opinions;

  3. religious or philosophical beliefs;

  4. trade union membership;

  5. genetic data;

  6. biometric data for unique identification;

  7. health data;

  8. data concerning sex life or sexual orientation.

The common feature connecting these categories is their potential to create significant risks to fundamental rights.

2.1. Racial or Ethnic Origin

Racial and ethnic origin relates to information concerning an individual's identity, ancestry, cultural background, or membership within a particular racial or ethnic group.

The GDPR does not define these terms exhaustively. However, they are interpreted broadly because discrimination based on race or ethnicity has historically caused severe social harm.

Examples

include:

  • recording an employee's ethnic background for diversity monitoring;
  • analysing customer demographics based on ethnicity;
  • collecting information about indigenous communities. However, not every demographic attribute qualifies as racial or ethnic origin. For example:
  • nationality alone is generally not racial or ethnic origin;
  • place of residence does not automatically reveal ethnicity. A company collecting customer addresses for delivery purposes does not necessarily process ethnic data. However, if the organisation analyses addresses to infer ethnic communities or minority groups, Article 9 may become applicable.

2.2. Political Opinions

Political opinions include information revealing an individual's political beliefs, affiliations, or ideological preferences.

The protection exists because political beliefs are closely connected with democratic participation and personal autonomy.

Examples

  • membership in a political party;
  • support for a political movement;
  • voting preferences;
  • political campaign engagement. Modern technology creates significant risks through political profiling. For example:

A social media platform analyses:

  • pages followed;

  • articles read;

  • political discussions;

  • online interactions,

and predicts whether a user supports a particular political ideology.

Even if the user never explicitly states their political views, such processing may reveal political opinions.

The GDPR therefore recognises that sensitive information can emerge through inference.

2.3. Religious or Philosophical Beliefs

Religious beliefs include information regarding:

  • religious affiliation;

  • religious practices;

  • participation in religious communities.

Philosophical beliefs cover broader convictions concerning fundamental aspects of human existence, morality, or worldview.

Examples

  • information showing membership of a religious organisation;
  • dietary preferences revealing religious practices;
  • participation in philosophical movements. A critical issue is distinguishing between ordinary lifestyle information and information that reveals beliefs. For example: A restaurant recording that a customer prefers vegetarian food does not automatically process religious belief data.

However, if the restaurant specifically records that the customer follows a religious dietary requirement, Article 9 may apply.

2.4. Trade Union Membership

Trade union membership receives special protection because it relates to:

  • workers' collective rights;

  • employment relationships;

  • potential discrimination.

Employers processing trade union information may create risks of retaliation or unequal treatment.

Examples

  • maintaining a list of employees belonging to a union;
  • monitoring union activities;
  • analysing employee participation in labour movements. The protection does not cover every employment-related activity. A company may process ordinary employee information such as payroll details under Article 6. However, information revealing union membership requires Article 9 justification.

2.5. Genetic Data

Genetic data represents one of the significant additions introduced by the GDPR.

Article 4(13) defines genetic data as:

“personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person.”

Genetic information is unique because it reveals not only information about the individual but also their biological relatives.

Examples

  • DNA testing results;
  • genetic disease indicators;
  • hereditary risk information. A major concern is commercial genetic testing. For example: A company offering ancestry analysis collects DNA samples to provide family history information. However, the same genetic information may reveal:
  • health risks;

  • hereditary conditions;

  • biological relationships.

Therefore, genetic data requires enhanced protection.

2.6. Biometric Data

Biometric data refers to personal data resulting from specific technical processing relating to physical, physiological, or behavioural characteristics.

Examples

  • fingerprints;
  • facial recognition templates;
  • iris scans;
  • voice patterns. However, not every photograph or physical characteristic automatically becomes biometric data under Article 9. The GDPR specifically applies Article 9 protection where biometric data is processed:

“for the purpose of uniquely identifying a natural person.”

This distinction is important.

For example:

A company storing employee photographs for an internal directory may process personal data but may not necessarily process Article 9 biometric data.

However:

A company using facial recognition technology to identify employees entering a workplace processes biometric data under Article 9.

The difference lies in the purpose and technical processing involved.

2.7. Health Data

Health data receives extensive protection because medical information directly affects personal dignity and autonomy.

Article 4(15) defines health data broadly as information relating to:

  • physical health;

  • mental health;

  • healthcare services;

  • health status.

Examples

include:

  • medical records;
  • prescriptions;
  • disability information;
  • fitness tracker data;
  • reproductive health information. The Court of Justice of the European Union has adopted a broad interpretation of health data. In Case C-101/01 Bodil Lindqvist, the Court recognised that information relating to an individual's health condition falls within enhanced protection requirements. Modern technology increases complexity. For example: A smartwatch collecting:
  • heart rate;
  • sleep patterns;
  • exercise behaviour; may generate health-related information even if the device is marketed as a lifestyle product.

2.8. Sex Life and Sexual Orientation

Information concerning sex life and sexual orientation receives protection because disclosure may expose individuals to:

  • discrimination;

  • social stigma;

  • harassment.

Examples

  • information about sexual orientation;
  • sexual health records;
  • relationship information revealing orientation. Technology creates additional risks through inference. For example: An advertising platform analysing browsing behaviour may infer a user's sexual orientation based on visited websites or online interactions.

Even if the individual never directly disclosed such information, processing that reveals such information may fall within Article 9.

Article 9 GDPR - Processing of Special Categories of Personal Data

3. General Prohibition under Article 9(1)

3.1. The Fundamental Structure of Article 9

Unlike ordinary personal data processing under Article 6 GDPR, where processing is generally permitted if one of the lawful bases applies, Article 9 follows a stricter regulatory model.

Article 9(1) establishes a general prohibition:

“Processing of personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, or data concerning health or a natural person's sex life or sexual orientation shall be prohibited.”

This structure is intentional. The GDPR does not begin by asking whether a controller has a lawful basis. Instead, it begins from the assumption that processing such data creates a heightened risk and therefore should generally not occur unless specifically justified.

The regulatory logic can be summarised as:

Ordinary personal data

Processing permitted → provided Article 6 lawful basis exists.

Special category data

Processing prohibited → unless Article 9(2) exception applies + Article 6 lawful basis exists.

Therefore, Article 9 does not replace Article 6. It operates as an additional layer of protection.

3.2. Article 9 Creates a Two-Level Compliance Requirement

A common misunderstanding is that satisfying Article 9 automatically makes processing lawful. This is incorrect.

Controllers must satisfy two independent requirements:

First requirement: Article 6 lawful basis

The controller must identify a lawful basis such as:

  • consent;

  • contractual necessity;

  • legal obligation;

  • vital interests;

  • public task;

  • legitimate interests.

Second requirement: Article 9 exception

The controller must also identify one of the specific exceptions under Article 9(2).

For example:

A hospital processing patient medical records may rely on:

  • Article 6(1)(c): compliance with legal obligations;

  • Article 9(2)(h): healthcare and social care purposes.

Both requirements must be satisfied.

Similarly, an employer processing employee health information for sick leave management may need:

  • Article 6 lawful basis for employment administration;

  • Article 9(2)(b) or Article 9(2)(h) depending on circumstances.

3.3. Meaning of “Processing”

Article 9 applies to any “processing” of special category data.

The term processing is defined broadly under Article 4(2) GDPR and includes:

  • collection;

  • recording;

  • organisation;

  • storage;

  • alteration;

  • retrieval;

  • consultation;

  • disclosure;

  • dissemination;

  • restriction;

  • deletion.

Therefore, Article 9 is not limited to disclosure or sharing.

Many organisations incorrectly assume that they only need Article 9 compliance when sharing sensitive information externally. However, even internal activities may constitute processing.

Examples

Example 1

Internal storage A company stores employee medical certificates in its HR system. Even though the information is not shared outside the company, storage itself constitutes processing.

Example 2

Employee access An HR manager accesses information regarding an employee's disability accommodation request. Consultation of health information is processing.

Example 3

AI analysis An organisation uploads employee wellness data into an artificial intelligence tool to identify workplace trends. Analysis and automated evaluation constitute processing.

3.4. Meaning of “Revealing” Sensitive Information

One of the most significant aspects of Article 9 is the word “revealing.”

Article 9 does not only prohibit processing information that directly contains sensitive data. It also covers processing that reveals sensitive information.

This concept was examined by the Court of Justice of the European Union in:

Court of Justice of the European Union, Case C-184/20 OT v Vyriausioji tarnybinės etikos komisija

The Court adopted a broad interpretation of special category data and emphasised that information may fall under Article 9 where it allows conclusions to be drawn regarding protected characteristics.

The significance of this approach is that controllers cannot avoid Article 9 simply by arguing that they did not directly collect sensitive information.

Direct Revelation vs Indirect Revelation

Direct revelation

The data itself explicitly contains sensitive information.

Example

A healthcare database contains:

  • HIV status;
  • diagnosis information;
  • genetic test results. This clearly falls under Article 9.

Indirect revelation

The data does not explicitly state sensitive information but allows reasonable conclusions to be drawn.

Example

A charity collects information about donations. A donation to a religious organisation may reveal religious beliefs. A subscription to a political publication may reveal political opinions. A location history showing repeated visits to a medical clinic may reveal health information.

3.5. The Role of Inference in Article 9

Modern data processing makes inference one of the biggest challenges under Article 9.

Traditional data protection assumed that sensitive information was information voluntarily provided by individuals.

However, artificial intelligence and big-data analytics have changed this assumption.

Today, organisations can infer sensitive characteristics from:

  • browsing behaviour;

  • purchase history;

  • location data;

  • social connections;

  • behavioural patterns.

For example:

A supermarket analyses purchasing patterns and predicts that a customer may be pregnant based on:

  • purchase of pregnancy-related products;

  • dietary changes;

  • vitamin purchases.

Even if the customer never disclosed pregnancy, the analysis may reveal health-related information.

Similarly:

An advertising platform analyses online behaviour and predicts:

  • political preferences;

  • religious affiliation;

  • sexual orientation.

Such processing raises Article 9 concerns.

3.6. What Article 9 Does Not Prohibit

Article 9 does not prohibit all processing connected with sensitive information.

It prohibits processing only where:

  1. the information falls within a special category; and

  2. the processing reveals or involves that category; and

  3. no Article 9(2) exception applies.

Certain activities may involve sensitive information but fall outside Article 9.

Example 1

Ordinary photographs A company takes photographs during a corporate event. A photograph itself does not automatically constitute biometric data. Article 9 applies only if the photograph is processed using technical methods for unique identification. For example:

Not necessarily Article 9

A company publishes event photographs on its website.

Article 9 likely applies

A company uses facial recognition software to identify employees in photographs.

Example 2

General demographic information A company collects customer age and location information. This is personal data but not necessarily special category data. However, if combined with other information to infer:

  • ethnicity;
  • health status;
  • political affiliation;

Article 9 may become applicable.

Example 3

Professional information An employer maintains employee job titles and salaries. This is personal data but generally not special category data. However, if salary deductions reveal trade union membership, Article 9 issues may arise.

3.7. Relationship Between Article 9 and Article 6

Article 9 creates an additional protection layer rather than a replacement for Article 6.

The relationship can be represented as:

Step 1: Is personal data being processed? Identify Article 6 lawful basis. Step 2: Does processing involve special category data? Article 9 applies. Identify Article 9(2) exception. Implement safeguards.

A controller cannot argue:

“We obtained consent under Article 6, therefore we can process health information.”

This is incorrect.

Consent under Article 6 is insufficient because health data requires explicit consent under Article 9(2)(a).

3.8. Common Misconceptions Regarding Article 9

Misconception 1

“If information is publicly available, Article 9 does not apply.”

Incorrect.

Public availability does not remove the sensitive nature of information.

For example:

A person publicly posts their political views online.

The information remains political opinion data.

However, Article 9(2)(e) may permit processing where the individual has manifestly made the information public.

Misconception 2

“Only healthcare organisations process health data.”

Incorrect.

Health data is processed by:

  • employers;

  • insurers;

  • fitness applications;

  • technology companies;

  • advertisers.

Example

A fitness application analysing heart rate and exercise patterns may process health data.

Misconception 3

“Consent solves all Article 9 problems.”

Incorrect.

Consent must satisfy strict GDPR requirements.

For Article 9:

Consent must be:

  • freely given;

  • specific;

  • informed;

  • unambiguous;

  • explicit.

Additionally, individuals must have a genuine ability to withdraw consent.

Misconception 4

“Anonymous data containing sensitive information is still covered.”

If data is genuinely anonymised and cannot reasonably identify an individual, GDPR does not apply.

However, true anonymisation is difficult.

Pseudonymised health or genetic data remains personal data.

3.9. Practical Compliance Approach for Organisations

Organisations processing special category data should implement a structured assessment.

Step 1: Identify the data category

Determine whether information includes:

  • health data;

  • biometric data;

  • genetic data;

  • political opinions;

  • religious beliefs;

  • other Article 9 categories.

Step 2: Determine whether processing reveals sensitive information

Consider:

  • direct collection;

  • inference;

  • profiling;

  • AI analytics.

Step 3: Identify Article 9 exception

The organisation must document why processing is permitted.

Step 4: Apply safeguards

Depending on context:

  • encryption;

  • access controls;

  • confidentiality obligations;

  • data minimisation;

  • retention limits;

  • DPIA.

4. Interpretation of Article 9(2) Exceptions

Article 9(2) creates ten exceptions to the general prohibition.

However, these exceptions are not broad permissions.

They must be interpreted narrowly because Article 9 protects fundamental rights.

The existence of an exception does not mean processing automatically becomes lawful. Controllers must still comply with:

  • Article 5 principles;

  • Article 6 lawful basis;

  • transparency obligations;

  • security requirements;

  • accountability obligations.

The following section analyses each exception individually.

Article 9 GDPR - Processing of Special Categories of Personal Data

4. Interpretation of Article 9(2) Exceptions

Article 9(2) provides specific circumstances where processing of special categories of personal data is permitted despite the general prohibition under Article 9(1).

The exceptions represent a balance between two competing objectives:

  1. Protection of individuals against misuse of highly sensitive information, and

  2. Recognition that certain social, legal, healthcare, and public interest activities require processing of sensitive data.

However, these exceptions are not intended to create broad flexibility for controllers. They must be interpreted strictly because Article 9 concerns information closely connected with individual dignity, autonomy, and equality.

The European Court of Justice has repeatedly emphasised that provisions restricting fundamental rights must be interpreted carefully and proportionately.

A controller relying on Article 9(2) must demonstrate:

  • the exact exception being relied upon;

  • why the processing is necessary;

  • compliance with applicable EU or Member State law where required;

  • appropriate safeguards.

4.1. Article 9(2)(a) - Explicit Consent

Article 9(2)(a) permits processing where:

“the data subject has given explicit consent to the processing of those personal data for one or more specified purposes…”

Explicit consent represents the strongest form of consent under the GDPR.

While Article 6 generally requires valid consent as one possible lawful basis, Article 9 requires a higher threshold because of the sensitivity of the information involved.

The GDPR does not define “explicit consent” separately. However, it requires a clear and express indication of agreement.

Unlike ordinary consent, explicit consent generally requires a stronger affirmative action.

Examples

  • A patient signs a specific consent form allowing a hospital to share genetic information with a research institution.

  • A user checks a separate box specifically authorising processing of biometric information.

  • An employee provides a written statement consenting to processing of health information for a workplace accommodation.

  • Consent hidden inside general terms and conditions.

  • A pre-ticked checkbox.

  • Consent bundled with unrelated services.

  • Silence or inactivity.

Consent must also satisfy the general GDPR requirement of being freely given.

This becomes difficult in employment relationships.

For example:

An employer asks employees to consent to facial recognition attendance systems.

Although employees technically agree, the imbalance of power may raise questions regarding whether refusal was realistically possible.

Therefore, organisations must consider whether another Article 9 exception, such as employment law obligations under Article 9(2)(b), is more appropriate.

Practical Illustration

A fitness application collects information regarding:

  • heart rate;

  • medical conditions;

  • physical activity.

The company wants to use this information to develop personalised health recommendations.

Possible legal approach:

  • Article 6(1)(a): consent;

  • Article 9(2)(a): explicit consent.

The consent request must clearly explain:

  • what health data is collected;

  • how it will be analysed;

  • whether third parties receive access;

  • how consent can be withdrawn.

4.2. Article 9(2)(b) - Employment, Social Security and Social Protection Law

Article 9(2)(b) allows processing where:

processing is necessary for carrying out obligations and exercising specific rights in the field of employment and social protection law.

This exception recognises that employers and public authorities often need sensitive information to fulfil legal obligations.

Examples

include:

  • managing workplace disabilities;
  • maternity protections;
  • occupational health obligations;
  • social security administration.

Unlike Article 9(2)(a), this exception does not depend on individual consent.

The processing must arise from:

  • EU law;

  • Member State law;

  • collective agreements recognised under Member State law.

Therefore, an employer cannot simply claim employment necessity.

There must be a legal basis establishing the obligation or right.

Example

An employee requests reasonable workplace accommodation due to a medical condition. The employer processes limited health information to determine suitable arrangements. Possible basis:

  • Article 6(1)(c): legal obligation;
  • Article 9(2)(b): employment law obligation.

Limitations

Employers must follow data minimisation.

A company requiring medical confirmation for sick leave does not necessarily need complete medical records.

Collecting unnecessary diagnosis information may violate:

  • Article 5(1)(c): data minimisation;

  • Article 5(1)(e): storage limitation.

4.3. Article 9(2)(c) - Vital Interests

Article 9(2)(c) permits processing where:

processing is necessary to protect the vital interests of the data subject or another natural person where the data subject is physically or legally incapable of giving consent.

This exception is designed primarily for emergency situations.

Purpose

The objective is to prevent situations where strict consent requirements could endanger life or physical integrity.

Examples

  • emergency medical treatment;
  • unconscious patient requiring surgery;
  • disaster situations.

Example

A person is unconscious after an accident. Doctors access emergency medical information to determine:

  • allergies;
  • previous medical conditions;
  • medication history. Consent cannot be obtained, but processing is necessary to protect life.

Narrow Interpretation

Vital interests are interpreted narrowly.

Routine healthcare cannot generally rely on this exception because consent or healthcare-specific provisions usually exist.

A hospital cannot use “vital interests” as a general justification for all medical processing.

4.4. Article 9(2)(d) - Legitimate Activities of Foundations, Associations and Religious Organisations

Article 9(2)(d) permits processing by:

  • non-profit organisations;

  • foundations;

  • associations;

  • religious organisations,

where processing relates to their legitimate activities.

Examples

  • religious communities maintaining membership records;
  • political organisations maintaining supporter information;
  • charitable organisations managing beneficiaries.

Conditions

The processing must satisfy three requirements:

1. Appropriate organisation

The controller must be a:

  • foundation;

  • association;

  • non-profit body.

2. Legitimate activities

Processing must be connected with organisational purposes.

3. No disclosure outside organisation

The information generally cannot be disclosed externally without consent.

Example

A religious organisation maintains a list of members to organise:

  • community activities;
  • religious services;
  • internal communication. This may fall under Article 9(2)(d). However, selling the membership database to advertisers would not.

4.5. Article 9(2)(e) - Data Manifestly Made Public by the Data Subject

Article 9(2)(e) permits processing where:

the processing relates to personal data which are manifestly made public by the data subject.

This exception recognises that individuals may voluntarily remove confidentiality expectations regarding certain information.

However, the exception is interpreted narrowly.

Meaning of “Manifestly Made Public”

The individual must have clearly and intentionally made the information public.

The key question is:

Did the person deliberately expose this information to an unlimited audience?

Examples

Example 1

Political opinions A person publishes political views on a publicly accessible website. Processing may potentially rely on Article 9(2)(e).

Example 2

Social media A person publicly announces religious beliefs on an open social media profile. The information has been manifestly made public.What Does Not Qualify? Accidental disclosure does not satisfy this exception.

Example

A privacy mistake causes medical information to become visible online. The information was not intentionally made public.

Important

Principle Public availability does not transform sensitive data into ordinary personal data. The information remains protected. Article 9(2)(e) only creates a specific exception for processing.

4.6. Article 9(2)(f) - Legal Claims and Judicial Proceedings

Article 9(2)(f) permits processing where:

processing is necessary for the establishment, exercise or defence of legal claims or whenever courts are acting in their judicial capacity.

This exception recognises that litigation often requires sensitive information.

Examples

Employment dispute

An employee files a discrimination claim.

The employer processes:

  • medical records;

  • disability information;

to defend the claim.

Insurance dispute

An insurance company uses medical evidence during court proceedings.

Limitation

The processing must be necessary.

A party cannot collect excessive sensitive information merely because litigation exists.

4.7. Article 9(2)(g) - Substantial Public Interest

Article 9(2)(g) allows processing where:

processing is necessary for reasons of substantial public interest, on the basis of Union or Member State law.

This is one of the most complex exceptions.

Requirements

Three elements must exist:

1. Public interest purpose

The objective must benefit society.

Examples

  • anti-corruption measures;
  • equality monitoring;
  • election integrity.

The processing must be supported by:

  • EU law;

  • Member State law.

Controllers cannot independently decide that their activity serves public interest.

3. Proportionate safeguards

The law must provide safeguards protecting individuals.

Example

A government agency processes ethnicity information to monitor discrimination and improve equality policies. The purpose may qualify as substantial public interest if supported by appropriate legislation.

4.8. Article 9(2)(h) - Healthcare and Social Care

Article 9(2)(h) permits processing necessary for:

  • preventive medicine;

  • occupational medicine;

  • medical diagnosis;

  • healthcare treatment;

  • social care.

This is one of the most frequently used Article 9 exceptions.

Healthcare Necessity

Processing must be connected with healthcare purposes.

Examples

  • hospitals maintaining medical records;
  • doctors diagnosing patients;
  • occupational health assessments.

Professional Confidentiality Requirement

Processing must generally occur under:

  • professional secrecy obligations;

  • healthcare law;

  • regulated professional frameworks.

Example

A doctor accesses patient medical history before prescribing treatment. The processing is justified under Article 9(2)(h).

4.9. Article 9(2)(i) - Public Health

Article 9(2)(i) permits processing necessary for:

reasons of public interest in the area of public health.

This includes protection against:

  • serious cross-border health threats;

  • epidemics;

  • infectious diseases.

Example

During a pandemic, health authorities process vaccination information to manage public health risks.

Safeguards

Public health processing must respect:

  • confidentiality;

  • proportionality;

  • legal controls.

The exception cannot justify unlimited surveillance.

4.10. Article 9(2)(j) - Archiving, Research and Statistics

Article 9(2)(j) permits processing necessary for:

  • archiving purposes in public interest;

  • scientific research;

  • historical research;

  • statistical purposes.

However, such processing must comply with:

  • Article 89 safeguards;

  • appropriate technical and organisational measures.

Example

A university conducts medical research using historical health datasets. The processing may be permitted where:

  • research purpose exists;
  • safeguards are applied;
  • individuals' rights are protected.

Key Observation on Article 9(2)

The exceptions demonstrate GDPR's attempt to balance privacy with legitimate societal needs.

Article 9 does not create an absolute prohibition. Instead, it creates a controlled permission system where sensitive information can be processed only when justified by:

  • individual autonomy;

  • legal necessity;

  • healthcare needs;

  • public interest;

  • scientific advancement.

Article 9 GDPR - Processing of Special Categories of Personal Data

5. Important Issues and Jurisprudence

Article 9 has become one of the most actively interpreted provisions of the GDPR because technological developments continuously expand the ability of organisations to collect, analyse, and infer sensitive information.

Courts and regulators have increasingly adopted a broad and risk-oriented interpretation of special categories of personal data. The focus is not merely on what information is collected but on what conclusions can reasonably be drawn from processing activities.

5.1. CJEU Interpretation of Special Categories of Personal Data

The Court of Justice of the European Union (CJEU) has played an important role in defining the scope of sensitive data protection.

Although Article 9 GDPR is relatively new, several decisions under the previous Data Protection Directive continue to influence interpretation because the GDPR retained similar principles.

Case C-101/01 - Bodil Lindqvist

Background

The case concerned an individual who created a webpage containing information about colleagues working in a church community.

The webpage included information about:

  • names;

  • hobbies;

  • telephone numbers;

  • injuries suffered by one individual.

The question before the Court was whether publishing information online constituted processing of personal data.

Significance for Article 9

Although the case was decided under the Data Protection Directive, it established an important principle:

Health-related information receives enhanced protection because it concerns an individual's private sphere.

The Court recognised that information relating to an individual's health condition falls within sensitive categories.

Practical Impact

The case demonstrates that even seemingly limited disclosures can create privacy risks.

For example:

A company newsletter mentioning that an employee is undergoing treatment for a medical condition may constitute processing of health data.

The organisation's intention may be harmless, but the disclosure itself creates Article 9 concerns.

Case C-184/20 - OT v Vyriausioji tarnybinės etikos komisija

Background

The case concerned Lithuanian legislation requiring publication of declarations containing information relating to individuals' private interests.

The information published could reveal personal relationships and potentially sensitive information.

CJEU Approach

The Court adopted a broad interpretation of information that may “reveal” special categories of personal data.

The Court emphasised that Article 9 protection applies not only where information explicitly contains sensitive data but also where processing allows conclusions to be drawn about sensitive characteristics.

Importance

This judgment is highly relevant in the era of:

  • artificial intelligence;

  • predictive analytics;

  • behavioural profiling.

A company cannot avoid Article 9 simply by arguing:

“We did not collect health information; we only collected behavioural data.”

If behavioural analysis reveals health, political opinions, religion, or other protected characteristics, Article 9 may apply.

Case C-434/16 - Nowak v Data Protection Commissioner

Background

The case concerned whether examiner comments on a professional examination constituted personal data.

Relevance to Article 9

Although not directly dealing with special categories, the case confirmed the broad interpretation of personal data under EU law.

The Court emphasised that information is personal data where it relates to an identifiable individual.

Significance

The judgment supports a broader understanding of GDPR protection.

Sensitive information must therefore be interpreted within the wider principle that personal data protection extends beyond obvious identifiers.

5.2. EDPB Guidance on Special Categories

The European Data Protection Board (EDPB) has consistently emphasised that Article 9 requires careful assessment because processing special category data creates significant risks.

The EDPB's approach focuses on:

  • necessity;

  • proportionality;

  • transparency;

  • safeguards.

5.2.1. Biometric Data Guidance

The EDPB has repeatedly highlighted that biometric technologies require special attention.

A key distinction exists between:

Authentication

Determining whether someone is the same person they claim to be.

Example

Fingerprint unlocking a smartphone.

Identification

Determining who a person is among a group.

Example

Facial recognition scanning people in a public area. Identification generally creates greater risks because it enables:

  • mass surveillance;
  • tracking;
  • profiling.

Example

A company uses facial recognition to allow employees access to a building. The organisation must consider:

  • whether less intrusive alternatives exist;
  • whether employees have genuine choice;
  • whether processing is proportionate;
  • whether Article 9 conditions are satisfied.

A simple access card system may achieve the same purpose with significantly lower privacy impact.

5.3. Artificial Intelligence and Article 9

Artificial intelligence creates some of the most challenging Article 9 issues.

AI systems often process enormous quantities of information and identify hidden patterns.

The central challenge is:

Can AI processing reveal special category data even when the input data does not directly contain sensitive information?

The answer is increasingly recognised as yes.

5.3.1. AI-Based Profiling and Sensitive Inference

AI models can infer sensitive characteristics from:

  • online behaviour;

  • writing style;

  • images;

  • voice patterns;

  • purchasing behaviour;

  • social connections.

Example 1

Political Inference An AI advertising system analyses:

  • websites visited;
  • posts liked;
  • online discussions. The system predicts political preferences.

Even though the user never provided political opinions, the processing may reveal political views.

Example 2

Health Inference An insurance company uses AI to analyse:

  • purchase history;
  • fitness data;
  • location information. The system predicts probability of certain diseases.

The company may have created health-related information through inference.

Example 3

Emotion Recognition AI systems analyse:

  • facial expressions;
  • voice tone;
  • body movements. Such systems may attempt to infer:
  • emotional state;

  • psychological characteristics.

This raises significant concerns because emotional inference may overlap with health or behavioural profiling.

5.4. Biometric Identification Systems

Biometric technology represents one of the clearest examples of Article 9's importance.

Traditional identifiers such as passwords or identification numbers can be changed.

Biometric identifiers cannot easily be replaced.

A stolen password can be reset.

A stolen fingerprint cannot.

Risks Associated with Biometric Data

1. Permanent identification

Biometric data creates a persistent link between an individual and their identity.

2. Function creep

Information collected for one purpose may later be used for another.

Example

Facial recognition introduced for building security may later be used for employee monitoring.

3. Mass surveillance

Public facial recognition systems may enable continuous tracking of individuals.

Compliance Requirements

Organisations using biometric systems should consider:

  • whether Article 9 applies;

  • whether a lawful exception exists;

  • whether processing is necessary;

  • whether alternatives exist;

  • whether a Data Protection Impact Assessment (DPIA) is required.

5.5. Genetic Data and Future Privacy Risks

Genetic data creates unique privacy challenges because it is not only about the individual.

A person's DNA reveals information about:

  • biological relatives;

  • ancestry;

  • hereditary conditions;

  • future health risks.

Example

A person uploads DNA information to an ancestry platform. The data may reveal:

  • their own genetic characteristics;
  • information about siblings;
  • parental relationships;
  • inherited disease risks.

Challenges

1. Long-term implications

Unlike ordinary personal data, genetic information remains relevant throughout a person's lifetime.

2. Secondary use

Genetic information collected for ancestry purposes may later be valuable for:

  • research;

  • insurance analysis;

  • pharmaceutical development.

3. Family privacy

An individual's decision to disclose genetic information may affect relatives who never consented.

5.6. Health Data Generated by Wearables

The expansion of wearable technology has transformed health data processing.

Devices such as:

  • smart watches;

  • fitness trackers;

  • health monitoring devices,

collect information previously limited to healthcare environments.

Is Wearable Data Health Data?

The answer depends on the nature and purpose of processing.

Information such as:

  • heart rate;

  • sleep patterns;

  • blood oxygen levels;

  • activity levels,

may become health data where it provides information about an individual's health status.

Example

A fitness application collects exercise data. Initially, the data may appear as lifestyle information. However, AI analysis identifies:

  • abnormal heart patterns;
  • possible medical conditions;
  • health risks.

The resulting information may fall within Article 9.

5.7. Religious and Political Inference Through Digital Platforms

One of the biggest modern challenges is that platforms can infer sensitive characteristics without direct collection.

Religious inference

A platform analyses:

  • websites visited;

  • communities joined;

  • events attended.

It predicts religious affiliation.

Political inference

A platform analyses:

  • news consumption;

  • online interactions;

  • content preferences.

It predicts political beliefs.

The GDPR's use of the term “revealing” is particularly important here.

Article 9 addresses not only the collection of sensitive data but also the creation of sensitive profiles.