
Short answer: GDPR special category data is personal data that GDPR Article 9 treats as especially sensitive, including health, genetic and biometric data. Processing it is prohibited by default. You may only process it if you have an Article 6 lawful basis and one of the specific conditions in Article 9(2), backed by stronger safeguards.
Related guides:
- The 6 lawful bases for data processing under GDPR
- GDPR and HIPAA: key differences and similarities
- Data protection impact assessment guide
Key takeaways
- Article 9(1) lists eight types of sensitive personal data. For HealthTech, health, genetic and biometric data matter most.
- Processing is prohibited unless one of the ten conditions in Article 9(2) applies.
- You always need two things: an Article 6 lawful basis and an Article 9 condition. One does not replace the other.
- Large-scale processing of special category data is one of the listed cases in Article 35(3) where a DPIA is required.
- Processors carry real obligations too: following documented instructions, securing the data under Article 32 and controlling sub-processors.
What counts as special category data under GDPR?
Special category data is personal data revealing or concerning the eight categories in Article 9(1), which GDPR treats as high risk if misused.
| Category | Typical SaaS or HealthTech example |
|---|---|
| Racial or ethnic origin | Demographic fields in a clinical intake form |
| Political opinions | Survey answers or advocacy platform membership |
| Religious or philosophical beliefs | Dietary or care preferences linked to faith |
| Trade union membership | HR systems handling union dues deductions |
| Genetic data | DNA test results, genomic sequencing files |
| Biometric data used to uniquely identify a person | Face or fingerprint templates used for login |
| Data concerning health | Symptoms, diagnoses, prescriptions, wearable readings, appointment history |
| Sex life or sexual orientation | Fertility or sexual health app records |
Key definitions:
- Data concerning health (Article 4(15)) covers physical or mental health, including the provision of health care services, that reveals information about health status. Recital 35 reads this broadly, so appointment bookings and device readings can qualify.
- Biometric data (Article 4(14)) is only special category when it is processed for the purpose of uniquely identifying a person. A profile photo is not automatically biometric data. A face template used for verification is.
- Genetic data (Article 4(13)) covers inherited or acquired genetic characteristics that give unique information about physiology or health.
Note the word "revealing" in Article 9(1). Data that lets you infer a sensitive trait can fall into scope. Treat inferences, such as medication purchases or membership of a condition-specific community, with the same care as health records.
When can you process special category data under Article 9?
You can only process special category data when at least one of the ten Article 9(2) conditions applies, documented before processing starts.
| Article 9(2) | Condition | Where it tends to apply |
|---|---|---|
| (a) | Explicit consent of the data subject | Consumer health and wellness apps, research sign-ups |
| (b) | Obligations and rights in employment, social security and social protection law | HR and payroll platforms, sick leave records |
| (c) | Vital interests, where the person cannot give consent | Emergency situations only |
| (d) | Legitimate activities of a not-for-profit body with a political, philosophical, religious or trade union aim | Charities and unions, for their members |
| (e) | Data manifestly made public by the data subject | Narrow, and rarely a safe basis for product features |
| (f) | Establishment, exercise or defence of legal claims | Litigation, disputes, insurance claims |
| (g) | Substantial public interest, on the basis of EU or member state law | Only where a specific national law provides for it. The UK's Data Protection Act 2018, for example, covers fraud prevention, safeguarding and equality of opportunity |
| (h) | Preventive or occupational medicine, medical diagnosis, health or social care or treatment | Clinics, telehealth, care platforms acting under professional secrecy |
| (i) | Public health, such as serious cross-border threats or quality and safety of health care and medicines | Pharmacovigilance, public health reporting |
| (j) | Archiving in the public interest, scientific or historical research, or statistics, with Article 89(1) safeguards | Clinical and academic research |
Three practical notes:
- Explicit consent is a higher bar than ordinary consent. It needs a clear, express statement covering the specific sensitive processing, such as a separate checkbox with plain wording, not bundled acceptance of your terms. Withdrawal must be as easy as giving it.
- Condition (h) is not a blanket "we are a health company" condition. Article 9(3) requires the data to be processed by or under the responsibility of a professional subject to an obligation of professional secrecy. A consumer wellness app with no clinical relationship often cannot rely on it.
- Conditions (b), (g), (h), (i) and (j) depend on EU or member state law. Article 9(4) also lets member states add further conditions or limitations for genetic, biometric and health data. The UK, which since Brexit applies a separate regime that was amended by the Data (Use and Access) Act 2025, sets its own additional conditions in domestic law. National rules differ, so check the law of each country you operate in with qualified advice.
Do you need both an Article 6 basis and an Article 9 condition?
Yes. Article 9 lifts a prohibition, but it does not by itself make processing lawful, so you still need an Article 6 lawful basis for the same processing.
Think of it as two gates. Article 6 answers "is this processing lawful at all?" and Article 9 answers "is this sensitive processing permitted?" Our lawful bases guide covers the first gate, so here is how the pairing tends to look:
| Processing activity | Possible Article 6 basis | Possible Article 9 condition |
|---|---|---|
| Telehealth consultation notes | Contract, or public task for public providers | 9(2)(h) health care |
| Wellness app symptom tracking | Consent or contract | 9(2)(a) explicit consent |
| Employee sick leave records | Legal obligation | 9(2)(b) employment law |
| Biometric login for staff | Legitimate interests, if the balancing test supports it. Check national employment and biometric rules, which can restrict workplace use | Often 9(2)(a), which is hard in employment because consent must be freely given |
| Clinical trial data | Varies by country and sponsor | 9(2)(j) research, sometimes with 9(2)(i) |
The two do not have to match, but they must be consistent. Record both in your records of processing and your privacy notice.
How is criminal offence data treated differently?
Personal data relating to criminal convictions and offences is not special category data, but Article 10 restricts it separately: it may only be processed under the control of official authority or when authorised by EU or member state law.
This matters for platforms that run background checks or trust and safety tooling. Article 9 conditions do not apply, so explicit consent alone is generally not enough. You need a legal authorisation under EU or member state law plus an Article 6 basis.
When do you need a DPIA, and what security is appropriate?
A DPIA is mandatory under Article 35(3)(b) when you process special category or criminal offence data on a large scale, and security must be appropriate to the higher risk under Article 32.
GDPR does not define "large scale" as a number. Regulators look at the number of people affected, the volume and range of data, duration and geographic reach. A national telehealth platform clearly qualifies; a single doctor's practice usually does not. Supervisory authorities also publish lists of processing that requires a DPIA, so check your lead authority's list.
Special category processing also changes other obligations:
- Data Protection Officer: Article 37(1)(c) requires one where your core activities consist of large-scale processing of special category data.
- Records of processing: the Article 30(5) exemption for organizations with fewer than 250 employees does not apply when processing includes special category data.
- Automated decisions: Article 22(4) restricts solely automated decisions based on special category data unless explicit consent or substantial public interest applies, with suitable safeguards.
- Fines: infringements of Article 9 fall within the higher tier of Article 83(5).
Article 32 names pseudonymisation, encryption, resilience, timely restoration and regular testing. For sensitive data, that typically means encryption at rest and in transit, role-based access with MFA, access logging and review, pseudonymised analytics datasets, no production health data in test environments, and tested backups.
What are your responsibilities as a processor?
If you host or process special category data for customers, you are usually a processor, and you must follow their documented instructions, secure the data and support them in meeting their own Article 9 obligations.
Choosing the Article 9 condition is the controller's job, but processors are not passive. Article 28 requires a contract covering the types of data (name the special categories explicitly), staff confidentiality, security, sub-processor approval, assistance with data subject requests and DPIAs, breach support, and deletion or return at the end. If you are unsure which role you play for a feature, our guide on controller vs processor explains the test.
Watch for role drift. If you use customer health data to train models or build benchmarks for your own purposes, you may become a controller for that processing and need your own legal grounds. A HIPAA business associate agreement also does not replace an Article 28 contract.
Practical checklist for HealthTech apps
Use this checklist before a customer, investor or regulator asks.
- Map the data. Tag every field, table and event stream that contains or reveals special category data, including inferred data and free-text notes.
- Record both legal grounds. For each processing activity, document the Article 6 basis and the Article 9 condition, plus any national law you rely on.
- Design consent properly. If you rely on explicit consent, use a separate, specific prompt, store a timestamped record and build a working withdrawal path.
- Minimise. Collect only what each feature needs, and avoid sending health data to analytics, marketing or error-tracking tools.
- Run a DPIA for large-scale or novel processing, and repeat it when features change.
- Check DPO and representative needs. Large-scale health data processing can trigger a DPO requirement, and non-EU companies may need an EU representative.
- Harden security. Encrypt, restrict and log access, pseudonymise where possible and keep production data out of test environments.
- Control vendors. Sign Article 28 terms with every sub-processor that touches sensitive data and confirm transfer mechanisms for data leaving the EEA.
- Prepare for breaches. Breaches involving health data are more likely to require notifying individuals as well as the supervisory authority, so build that into your incident process.
Our overview of GDPR for healthcare covers the wider picture.
How SecureSlate helps
SecureSlate helps you map GDPR requirements for special category data, such as your Article 9 condition, DPIAs and records of processing, to controls with named owners. Cloud and identity integrations help you track whether the safeguards around that data, such as encryption and access reviews, are in place. Vendor risk management helps you track which sub-processors receive special category data, and policy management keeps the related policies and procedures current.
Start your free SecureSlate trial
FAQ
Is health data always special category data under GDPR?
Data concerning health is always special category data, and the definition is broad. It covers information that reveals someone's past, current or future physical or mental health status. Generic fitness data, such as step counts, may or may not qualify depending on what it reveals and how it is combined.
Is explicit consent the best Article 9 condition for a health app?
Not always. It is often the realistic option for consumer apps, but it can be withdrawn at any time and is hard to rely on where there is an imbalance of power, such as employment. Clinical services may be better suited to condition 9(2)(h), and research to 9(2)(j).
Does a small startup need a DPIA for special category data?
It depends on scale and risk, not company size. Large-scale processing of special category data requires a DPIA under Article 35(3)(b), and the EDPB-endorsed WP29 DPIA guidelines (WP248 rev.01) list sensitive data and innovative technology among the criteria that point to high risk. Many supervisory authorities also publish Article 35(4) lists of processing that always needs a DPIA, so check your lead authority's list.
Is a photo of a person biometric data?
Not by default. Recital 51 explains that photographs are only biometric data when processed through specific technical means that allow unique identification or authentication, such as facial recognition.
Disclaimer (legal note)
This article is for general information only and is not legal, regulatory or professional advice. Requirements vary by framework, industry and jurisdiction. Consult qualified advisors for your specific obligations.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds