GDPR Special Category Data: What Websites Must Protect
GDPR Article 9 special category data for website teams: what counts, the Article 6 plus Article 9 rule, explicit consent, DPIAs, and controls for health, biometrics, and related fields.
- What counts: Health, biometrics for unique ID, genetic data, race/ethnicity, politics, religion, union membership, sex life, and sexual orientation.
- Dual rule: Document Article 6 plus Article 9 (and UK Schedule 1 where UK GDPR applies) before processing starts.
- Explicit consent: Dedicated unticked control, clear purpose, logged proof, easy withdrawal when you rely on 9(2)(a).
- Website risks: Health forms, biometric login, inferred traits in ads, and free-text support tickets.
- Controls: Minimisation, DPIA, encryption, vendor limits, and rights workflows that find every special-category store.
What GDPR calls special category data
Under the EU General Data Protection Regulation (Regulation (EU) 2016/679), some personal data needs stricter conditions because misuse can cause serious harm. Article 9 calls this special category data.
Article 9(1) covers personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation.
Processing of those categories is prohibited unless an Article 9(2) condition applies. You also need a separate lawful basis under Article 6. Legitimate interests alone is not enough for special category data.
This guide is for website and product teams that collect, infer, or share such data through forms, accounts, cookies and SDKs, support tools, or partner integrations. It summarises public EU and UK regulator materials. It is not legal advice.
Official sources used here
- Regulation (EU) 2016/679 (GDPR), Article 9, on EUR-Lex.
- UK Information Commissioner’s Office (ICO) guidance on special category data (useful detail for UK GDPR; EU controllers should confirm with their supervisory authority and EU text).
- EDPB guidelines on consent under Regulation 2016/679 (for explicit consent expectations).
UK GDPR largely mirrors Article 9, but several conditions also need Data Protection Act 2018 Schedule 1 conditions and, in many cases, an appropriate policy document. If you only serve the EU, follow the EU GDPR and Member State law that fleshes out Article 9(2) openings. If you serve the UK, layer the DPA 2018 requirements on top.
What websites commonly collect that may fall under Article 9
Health and accessibility
- Medical questionnaires, allergy fields, disability or accessibility requests that reveal health information.
- Wellness, fitness, or mental-health features that store diagnoses, symptoms, or treatment history.
Biometrics for identification
- Face, fingerprint, or voice templates used to uniquely identify a person (for example login or identity checks).
- Ordinary photos are not automatically special category data. They become biometric special category data when processed with technical means for unique identification, as Recital 51 explains.
Beliefs, politics, union membership, ethnicity
- Signup questions about religion, political preference, ethnicity, or trade union status.
- Community or advocacy sites that store membership tied to those attributes.
Sex life and sexual orientation
- Dating, LGBTQ+ community, or research features that store sexual orientation or sex-life data.
Inferences
Special category data includes data that reveals or concerns those categories. If your product intentionally infers health status, ethnicity, or similar attributes and uses that inference, treat it with caution. Follow current ICO or EDPB guidance on inferences rather than guessing from “certainty” alone.
The dual-condition rule
Before you process special category data:
- Identify an Article 6 lawful basis (for example consent, contract, legal obligation, vital interests, public task, or legitimate interests where that basis truly fits the purpose).
- Identify a separate Article 9(2) condition.
- Document both before processing starts.
- Check whether Member State (or UK Schedule 1) law adds extra conditions, policy documents, or safeguards.
Article 9(2) conditions in plain terms
Article 9(2) lists the openings to the prohibition. Common ones for private websites and apps include:
- (a) Explicit consent: freely given, specific, informed, and unambiguous, plus an explicit affirmative act for this special category purpose. Pre-ticked boxes fail. Withdrawal must be as easy as giving consent.
- (b) Employment, social security, and social protection: only where authorised by law or collective agreement with safeguards (more typical for employers than public marketing sites).
- (c) Vital interests: where the person is physically or legally incapable of giving consent.
- (d) Not-for-profit bodies: limited processing in the course of legitimate activities with appropriate safeguards, relating to members or regular contacts, without disclosure outside the body without consent.
- (e) Data made public by the data subject: narrow; do not treat every social post as a free pass.
- (f) Legal claims or judicial acts.
- (g) Substantial public interest: needs a basis in Union or Member State law, proportionality, and specific safeguards.
- (h) Health or social care: preventive or occupational medicine, diagnosis, care, or management of health systems, on a legal basis or under contract with a health professional, subject to secrecy rules in Article 9(3).
- (i) Public health: with a basis in law and suitable safeguards.
- (j) Archiving, research, and statistics: with Article 89(1) safeguards and a legal basis that meets Article 9(2)(j).
If none of these fit, do not process the special category data.
What website operators should put in place
1. Data map and minimisation
- List every field, event, and vendor that could capture Article 9 data.
- Delete fields you do not need. Prefer optional questions over mandatory ones.
- Separate special category stores from ordinary profile data where practical, with stricter access control.
2. Explicit consent UX (when you rely on 9(2)(a))
- Use a dedicated, unticked control that names the special category purpose.
- Link to privacy information that explains categories, purposes, retention, recipients, and rights.
- Log timestamp, policy version, and what the person saw.
- Allow granular withdrawal without breaking unrelated account features where possible.
3. Privacy notice content
- State clearly that you process special category data, which categories, why, which Article 6 and Article 9 conditions you rely on, and how long you keep the data.
- Name processors and international transfer tools (adequacy, SCCs, or other Chapter V mechanisms).
4. DPIA and risk records
- Article 35 requires a DPIA for processing likely to result in a high risk. Large-scale or systematic special category processing usually triggers that duty.
- Record risks, mitigations, residual risk, and whether you consulted your DPO or supervisory authority where required.
5. Security and access
- Encrypt in transit and at rest.
- Limit production access with role-based controls and audit logs.
- Avoid copying special category exports into shared drives, tickets, or analytics warehouses without the same legal basis and safeguards.
- Train support staff: free-text tickets often become health or belief data by accident.
6. Cookies, pixels, and third parties
- Marketing pixels must not send health, orientation, or similar attributes unless you have a valid Article 9 condition and a transparent notice.
- Review tag managers and customer-data platforms for events that encode diagnoses, disability, or similar traits.
- Update processor agreements (Article 28) to reflect special category processing and instructions.
7. Data subject rights
- Access, erasure, restriction, and objection workflows must locate special category stores, backups, and vendor copies.
- For automated decisions with legal or similarly significant effects, check Article 22 limits, especially where special category data is involved.
UK-specific extra steps (if UK GDPR applies)
The ICO states that you need both an Article 6 basis and an Article 9 condition, documented in advance. Five Article 9 conditions also need a matching condition in Schedule 1 to the Data Protection Act 2018. Substantial public interest processing needs one of the specific Schedule 1 Part 2 conditions. In many Schedule 1 cases you also need an appropriate policy document describing procedures, retention, and compliance measures.
Use the ICO checklist: necessity, Article 6 basis, Article 9 condition, Schedule 1 where required, documentation, DPIA consideration, and privacy information that covers special category processing.
Practical “do / do not” for product teams
Do
- Ask whether the feature can work without special category data.
- Keep purpose limitation tight when consent is the Article 9 condition.
- Run a DPIA before launching health quizzes, biometric login, or orientation-targeted content.
- Align EU and UK records if you operate in both.
Do not
- Rely on “soft” opt-ins or buried privacy-policy clauses for special category processing.
- Assume a photo upload is harmless without checking biometric identification use.
- Ship inferred sensitive attributes into ad audiences without a hard legal review.
- Confuse India’s DPDP Act with GDPR Article 9. DPDP does not copy the special-category list; map each regime separately.
Quick compliance sequence
- Inventory and classify fields against Article 9(1).
- Drop or redesign anything you cannot justify.
- Document Article 6 + Article 9 (+ Schedule 1 / Member State law if needed).
- Implement explicit consent or other condition UX and backend flags.
- Complete DPIA and security hardening.
- Update notices, processor contracts, and rights-request runbooks.
- Monitor vendors and analytics for silent re-introduction of special category events.
Related in this series: Sensitive Data Protection Under India’s DPDP Act, Sensitive Data in Analytics and Marketing Tools, and Data Minimization and Retention for Sensitive Data.
Sources
- Regulation (EU) 2016/679, Article 9 and Recital 51: EUR-Lex official text.
- ICO, “Special category data” guidance: checklist, Article 9 conditions, and DPA 2018 Schedule 1 notes for UK GDPR.
- EDPB Guidelines 05/2020 on consent under Regulation 2016/679 (explicit consent standard).
- Data Protection Act 2018 (UK), Schedule 1 (where UK GDPR applies).
Disclaimer
This article was prepared by Imran using publicly available information. It is for general education only and is not legal advice. Do not rely on it alone when implementing cookie compliance, DSAR handling, consent flows, sensitive-data controls, breach response, or other privacy and data-protection measures. Consult your own legal counsel for advice that fits your business, jurisdictions, and systems.
Last updated on 16 September 2026
