惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

IT之家
IT之家
aimingoo的专栏
aimingoo的专栏
H
Help Net Security
L
LangChain Blog
M
MIT News - Artificial intelligence
The GitHub Blog
The GitHub Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
C
Check Point Blog
P
Proofpoint News Feed
J
Java Code Geeks
大猫的无限游戏
大猫的无限游戏
博客园_首页
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
I
InfoQ
月光博客
月光博客
爱范儿
爱范儿
Stack Overflow Blog
Stack Overflow Blog
V
Visual Studio Blog
Y
Y Combinator Blog
Microsoft Security Blog
Microsoft Security Blog
博客园 - Franky
D
Docker
B
Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
What Is Considered Sensitive Personal Information? | iubenda
Alice Perseval · 2022-12-29 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

Personal information is any data that can be used to identify an individual. Sensitive personal information, on the other hand, is considered as a special category of personal data under most data privacy laws. It is particularly delicate, as it may involve an increased risk of discrimination for the individual it refers to.

Due to its nature, sensitive personal information must be handled with caution and is usually subject to specific processing conditions. 👀 Keep reading for some examples of sensitive personal information.

sensitive personal information

🇪🇺 What is Sensitive Personal Information under Europe’s Privacy Laws

🔍 The EU’s General Data Protection Regulation (GDPR)

The world’s strongest privacy law to date, the GDPR, defines sensitive data in Article 9 under “special categories of personal data”, as:

  • racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership
  • genetic and biometric data, data concerning health or a natural person’s sex life or sexual orientation.

🔍 The UK’s Data Protection Act 2018

The DPA 2018 sets out the framework for data protection law in the UK. According to the ICO, it sits alongside and supplements the UK GDPR. Its definition of special category data is the same as the GDPR (listed above).

🇺🇸 What is Sensitive Personal Information under US Privacy Laws

💡 Did you know?

New privacy laws have been recently introduced across the United States. Most of them have made protecting sensitive personal information essential.

👉 As a business, this is important news for you to be extra cautious when handling this type of data.

🔍 The California Privacy Rights Act (CPRA)

The CPRA (effective in 2023) is an amendment to the CCPA (effective in 2020), which was initially created in order to regulate the sale and collection of consumers’ personal information in California.

Amongst other things, a new category of protected data was introduced by the CPRA, called sensitive personal information (SPI). This idea is similar to the GDPR’s special categories mentioned above, and asks for a higher level of protection.

👉 Check out our dedicated section on SPI in our CPRA guide for more detail.

🔍 The Virginia Consumer Data Protection Act (VCDPA)

The VCDPA (effective January 1, 2023) is the new privacy law in the Commonwealth of Virginia that states that a business cannot process sensitive data concerning a consumer, without obtaining the consumer’s prior consent (opt-in).

It defines sensitive data as a category of personal data that includes:

  • personal data revealing racial or ethnic origin, religious beliefs, mental or physical health diagnosis, sexual orientation, or citizenship or immigration status
  • the processing of genetic or biometric data for the purpose of uniquely identifying a natural person
  • the personal data collected from a known child
  • precise geolocation data.

🔍 The Colorado Privacy Act (CPA)

The Colorado Privacy Act (effective July 1, 2023) governs the processing of personal and sensitive data in the State of Colorado. Like in Virginia, consent (opt-in) is required before processing any sensitive data and controllers are required to conduct data protection assessments.

The definition of sensitive data under the CPA is very similar to the VCDPA one:

  • personal data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, sex life or sexual orientation, or citizenship, or citizenship status
  • genetic or biometric data that may be processed for the purpose of uniquely identifying an individual
  • personal data from a known child.

🇦🇺 What is Sensitive Personal Information under Australia Privacy Laws

🔍 The Australian Privacy Act 1988 and Principles

Once again, the definition of sensitive information in the Australian Privacy Act is in line with the ones above and refers to data that requires a higher level of privacy protection. It includes, among others, information or an opinion about an individual’s:

  • racial or ethnic origin
  • political opinions or membership of a political association
  • religious or philosophical beliefs
  • trade union membership
  • sexual orientation or practices
  • criminal record
  • health or genetic information
  • certain biometric information.

💡 Want to know more about Australia’s privacy news? Read our article about Australia’s incoming data privacy bill.

You handle sensitive personal information?

Make sure to display the required notice on your website and to request consent, when needed.

Generate your US and GDPR-compliant consent banner!

See also