惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Martin Fowler
Martin Fowler
Last Week in AI
Last Week in AI
罗磊的独立博客
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
博客园_首页
人人都是产品经理
人人都是产品经理
量子位
美团技术团队
The Cloudflare Blog
小众软件
小众软件
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
M
MIT News - Artificial intelligence
Microsoft Security Blog
Microsoft Security Blog
D
DataBreaches.Net
博客园 - Franky

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
A Closer Look at Special Categories of Personal Data | iu...
Alice Perseval · 2023-02-13 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

Data privacy laws around the world like the GPDR in Europe have established a much-needed framework for the collection, use and storage of personal data. As a business, you cannot handle data however you want to. This is even more true of special categories of personal data, that, due to their nature, are subject to particular attention.

👀 In this article, we take a look at the GDPR definition of special categories and how you should handle this type of data.

special categories of personal data

Special Categories of Personal Data: Article 9

What are GDPR Special Categories?

The expression “special categories of personal data” is the GDPR’s way of referring to sensitive data. They are defined in GDPR Article 9 as data which is of:

  • racial or ethnic origin;
  • political opinions;
  • religious or philosophical beliefs;
  • trade union membership;
  • genetic data;
  • biometric data (i.e. fingerprints, face recognition, DNA, etc.);
  • data concerning health;
  • data concerning a natural person’s sex life or sexual orientation.

🔍 Read our article for an overview of what is considered sensitive personal information around the world.

Some practical examples can include:

  • A healthcare provider collecting and storing a patient’s medical history and health data (i.e. illnesses, and disabilities);
  • An employer collecting information about an employee’s trade union membership and political opinions;
  • A social media platform collecting information about users’ religious beliefs and sexual orientation in order to show targeted advertisements;
  • A financial institution collecting and storing information about a customer’s criminal convictions.

Personal Data vs. Sensitive Personal Data

As you can see from the description above, sensitive personal data can be considered as more “invasive” or “risky” compared to regular personal data.

Sensitive information, in particular, could potentially lead to things like discrimination against individuals. Which is why you should be even more careful to avoid any sensitive data exposure.

What You Should Do When Handling Special Categories of Personal Data

Under the GDPR, for collecting or processing any type of personal data, you need to have explicit and informed consent from individuals, as well as give the necessary disclosures via a privacy policy.

While these requirements apply to personal data in general, there are some GDPR requirements that specifically apply to special categories of personal data. Here are 3 cases below.

💡 Did you know sensitive personal information gets special attention in US privacy laws?

🇺🇸 Needless to say, handling sensitive data calls for stricter rules outside Europe too!

👉 Check out our US State Privacy Laws Overview

Appoint a Data Protection Officer (DPO)

A Data Protection Officer (DPO) is usually appointed by a company to ensure that personal data is processed following the applicable data protection rules.

Under Article 37 of the GDPR, you are legally-required to designate a DPO if you carry out certain types of processing activities, including when your core activities consist of large-scale processing of sensitive data.

💡 This means if the GDPR applies to you and if you process special categories of personal data on a large scale, you must appoint a DPO.

Perform a Data Protection Impact Assessment (DPIA)

Similar to the previous DPO requirement, the GDPR especially requires you to carry out a DPIA when processing special categories of personal data on a large scale.

A Data Protection Impact Assessment allows you to analyze and minimize risks associated with personal data processing.

🔍 Here is a free template we have on DPIA. Click here to check it out!

Keep Records of Processing Activities

Still under the GDPR, data controllers and processors are expressly required to maintain “full and extensive” up-to-date records of the company’s data processing activities when it involves handling special categories of data.

This can be quite challenging to implement!

🚀 That’s why we recommend using a dedicated tool like our Internal Privacy Management. It allows you to add processing activities from 1700+ pre-made options, divide them by area, assign processors and other member roles, and to document legal bases and other GDPR-required records.