
Special category data: the two-part GDPR test
A practical guide to spotting special category data, separating the Article 6 and Article 9 decisions, and recording the safeguards that make approval defensible.
A product team has no field called
religion. It does have location history and purchase data. The team wants to infer which customers may be interested in particular communities, foods, or events, then use those predictions in advertising.The sensitive fact entered the system as a prediction rather than a form field. That does not settle the privacy analysis. The EDPB gives a closely related example: a company infers religious beliefs from visits to places of worship or from shopping habits, then predicts lifestyle and shopping patterns. 1
The working question is: what does the team have to prove before it processes a sensitive attribute? Under GDPR Article 9, the answer has two parts. First, identify a lawful basis under Article 6. Then identify a separate Article 9(2) condition and satisfy any extra safeguards that condition requires. The ICO states this two-part test directly in its guidance. 2
When data becomes special category data
Article 9(1) covers personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, or sexual orientation. It also covers genetic data and biometric data processed to uniquely identify a natural person. 3
The verb matters: revealing. A team should inspect what its processing discloses, not only the names of the input columns.
The EDPB describes the scope as broad. It can include data derived or inferred through profiling, or information disclosed indirectly. The EDPB also says it does not matter whether the information revealed is correct or whether the controller intended to obtain information in that category. 1
That creates four practical screening questions:
- What is collected directly? A diagnosis, union membership, or fingerprint template is an obvious trigger.
- What is derived? A risk score, segment, or classification may encode a sensitive fact even when the label sounds neutral.
- What is inferred? A model's probability that a person holds a religious belief or has a health condition still needs review when the output is used as information about that person.
- What is disclosed indirectly? A combination of location, behaviour, or context can reveal a category without naming it.
The question is not whether a person has formally declared the attribute. It is whether the processing reveals, or is used to act on, information that falls within Article 9's categories. Uncertainty in a model output may affect the risk assessment and the design of the control. It does not remove the need to ask the Article 9 question.
This boundary is separate from criminal-offence data. Criminal convictions and offences are governed by Article 10, with their own conditions. A record can fall under Article 9, Article 10, both, or neither depending on what it contains and how it is used. Treating every sensitive record as one undifferentiated bucket makes the legal condition and the safeguards harder to identify.
The two columns a review must keep separate
A normal Article 6 review asks whether the organisation has a lawful basis for the processing purpose. The possible bases include consent, contract, legal obligation, vital interests, public task, and legitimate interests, with the choice depending on the purpose and context. 2
Article 9 asks a different question: which exception permits this category of data to be processed? Article 9(1) states a prohibition in principle. Article 9(2) provides specific derogations. The EDPB describes this as a separate legal regime, not as a more emphatic version of Article 6. 13
| Review column | Question to answer | Evidence to retain |
|---|---|---|
| Article 6 | Why is this processing lawful for this purpose? | The purpose, the selected basis, the necessity analysis, and the facts that make the basis fit this activity. |
| Article 9 | Why may this special category be processed? | The category revealed, the exact Article 9(2) paragraph, the facts that satisfy it, and any additional legal safeguards. |
| Controls and accountability | How will the organisation reduce harm and show it followed the decision? | Access, transparency, retention, security, review triggers, and the person who approved the record. |
A legitimate-interest assessment, contract, or consent record can fill the Article 6 column. It does not fill the Article 9 column by implication. The record should make the two answers visible side by side so a reviewer cannot mistake a general lawful-basis conclusion for permission to use the sensitive attribute.
Choose the exact Article 9 condition
Article 9(2) is a closed list of conditions, running from explicit consent to specific employment, public-interest, care, public-health, legal-claims, and research or statistical situations. The condition must match the actual purpose and operation. 3
A useful way to narrow the choice is to start with the reason the processing exists:
- The person chooses the processing: Article 9(2)(a) covers explicit consent. Article 9(2)(e) covers data the person has manifestly made public. These are different facts. A person posting something publicly does not automatically mean the organisation has explicit consent for a new use.
- A defined relationship creates the need: Article 9(2)(b) concerns employment, social security, and social protection; Article 9(2)(c) concerns vital interests where the person cannot consent; and Article 9(2)(d) covers specified activities of qualifying non-profit bodies.
- A legal or public function creates the need: Article 9(2)(f) covers legal claims. Article 9(2)(g) covers substantial public interest where the applicable EU or Member State law provides the basis and safeguards. Article 9(2)(h) and (i) cover defined health, social-care, and public-health contexts.
- The purpose is knowledge or preservation: Article 9(2)(j) covers specified archiving, scientific or historical research, and statistical purposes, subject to Article 89 safeguards and the other requirements in the provision.
This grouping is a starting screen, not a shortcut. The legal record should name the paragraph rather than say
Article 9 applies. For national-law conditions, it should also identify the law or statutory provision that supplies the necessary authority.The same purpose can produce different answers in different jurisdictions. For example, the ICO's UK guidance says the substantial-public-interest route may require one of the specific conditions in Schedule 1 to the UK Data Protection Act 2018 and an appropriate policy document. That document should describe the condition relied on, compliance with the principles, and retention and deletion policies. 2 A general statement that the project benefits the business is not the same as a substantial-public-interest condition.
Why explicit consent is a higher bar
Explicit consent is often proposed because it sounds like the cleanest answer. It is a specific Article 9 condition, and consent can also be the Article 6 lawful basis. That makes the two columns easy to align in some cases. It does not make the condition automatic.
The ICO says explicit consent must be expressly confirmed in words. Its wider consent guidance also requires a clear affirmative opt-in, a specific and understandable request, separation from other terms, a record of who consented, when, how, and what they were told, and an easy withdrawal route. 4
A usable consent review therefore asks:
- Was the person given a real choice? A service relationship, employment relationship, or other imbalance may make consent difficult to show as freely given.
- Was the sensitive purpose named? A broad permission to use data for "personalisation" may not tell the person that the service will infer health, religion, or sexual orientation.
- Was the action explicit? Pre-ticked boxes, silence, and acceptance of unrelated terms do not create the express confirmation the condition requires.
- Can the organisation prove the event? Keep the wording, version, timestamp, purpose, and withdrawal path, not just a Boolean field saying
consent=true. - What happens after withdrawal? The service needs a working path to stop the relevant processing and to handle data already derived from it.
Consent is one route. It is not a reason to redesign a coercive or unavoidable processing operation as an opt-in screen. The ICO says consent is appropriate where people have real choice and control; it warns that making consent a precondition can make it an inappropriate basis in context. 4
A decision screen for product and policy review
The following sequence keeps the legal question attached to the actual system rather than to a data dictionary.
1. Name the processing operation
Write the action as a verb and include the purpose: collect, classify, predict, share, rank, target, retain, or delete. "Use customer data" is too broad to support a lawful-basis decision.
A feature that predicts a health-related risk, a feature that stores a medical document, and a feature that sends a care reminder may be separate processing operations. Their purposes, recipients, retention, and Article 9 conditions may differ.
2. Inventory outputs, not only inputs
List direct fields, derived fields, model outputs, segments, and decisions. Include what downstream teams receive. Ask whether an output can reveal a category in combination with other information.
For the advertising example, the input table may contain only coordinates and transactions. The output may contain an inferred religious belief or a lifestyle segment. That output is the point at which the Article 9 review must become explicit, even if the model calls it a propensity score.
3. Test the category and the evidence
For each candidate attribute, record:
- the Article 9 category that may be revealed;
- the field, rule, model, or human decision that produces it;
- whether the result is direct, derived, inferred, or indirectly disclosed;
- the confidence or uncertainty, where relevant; and
- how the organisation will use, share, or act on it.
Do not overstate the result. If the system cannot reliably distinguish a category, record that uncertainty and still explain why the processing could reveal it. The EDPB's point is about the information revealed by the processing, not about whether the controller's prediction is ultimately true. 1
4. Fill Article 6 and Article 9 independently
Put the two conclusions in separate fields. For Article 6, record the purpose and why the chosen basis fits. For Article 9, record the category and the exact paragraph that permits the processing.
If the team can fill only the Article 6 field, the review is incomplete. If it names an Article 9 paragraph but cannot show the facts and safeguards required by that paragraph, it is incomplete for a different reason.
5. Add the conditions around the condition
Some Article 9 routes carry their own requirements in EU or Member State law. The ICO's UK example shows why the paragraph alone may be insufficient: a substantial-public-interest condition can require a specified Schedule 1 condition and an appropriate policy document. 2
Record the required policy, professional role, statutory authority, confidentiality duty, research safeguard, or other legal constraint next to the Article 9 conclusion. Do not leave these requirements in a separate compliance folder where the product decision cannot see them.
6. Make the control match the exposure
Special category status does not prescribe one universal technical control. The control should follow the operation: strict role-based access, separation of identifiers, encryption, output suppression, purpose-limited sharing, shorter retention, audit logs, human review, or a refusal to create the sensitive inference may each be relevant.
The product decision should state what the system will do when a person withdraws consent, exercises a right, changes a preference, or asks how an inference was produced. It should also say who can see the raw attribute, the model output, and any decision made from it.
7. Set the reopening triggers
Reopen the analysis when any of these changes:
- a new input source or data broker is added;
- a model starts producing a new attribute or a more specific score;
- a new recipient, vendor, or jurisdiction is introduced;
- the purpose changes from measurement to targeting, eligibility, or enforcement;
- the data is combined with another dataset; or
- the legal condition, policy document, retention period, or safeguard changes.
An Article 9 conclusion belongs to a processing operation in context. It should not be copied into a new feature merely because the feature uses the same table.
Failure modes that should stop sign-off
"Article 6 is covered"
The team has a legitimate-interest assessment or contract analysis and treats it as permission to use every field produced by the system. The repair is mechanical: require a separate Article 9 category, paragraph, and safeguard record for each sensitive output.
"It is only a prediction"
The model returns a probability rather than a declared fact. The team excludes it from the review because it may be wrong. The EDPB's guidance makes the screening question broader: derived or inferred information can fall within the Article 9 analysis, and correctness or intent does not decide the scope. 1
"The user made it public"
The person disclosed a fact on a public page, so the team assumes every reuse is covered by Article 9(2)(e). The record still needs to show that the data was manifestly made public by the data subject and that the proposed processing fits that condition and the other GDPR requirements. Public visibility is evidence about one condition, not a universal reuse permission.
"Hashed means safe"
The team hashes a sensitive identifier and removes the original column. Hashing or pseudonymisation may reduce exposure, but they do not answer whether the underlying personal data is special category data or whether the processing has an Article 9 condition. A control can reduce risk while leaving the legal analysis intact.
"The purpose is beneficial"
A public-interest, safety, or research label is used as the Article 9 conclusion. The record must identify the exact condition and any supporting EU or national law. Where the condition requires an appropriate policy document or research safeguards, those documents must exist before the processing is approved.
"The label is enough"
A data catalogue says
sensitive=false because the raw table contains no obvious health, religion, or biometric field. Catalogue status is an input to review, not its conclusion. Derived attributes and downstream decisions must be visible in the same inventory.The record a reviewer can use
A compact review record should answer these questions without relying on the original project team’s memory:
- What exact processing operation and purpose are being approved?
- Which direct, derived, inferred, or indirectly disclosed attributes could reveal an Article 9 category?
- What is the Article 6 lawful basis, and why is it necessary and appropriate for this purpose?
- What is the exact Article 9(2) condition, and what facts satisfy it?
- What EU or national-law safeguard, policy document, professional duty, or research measure must also be met?
- Who can access the source data, sensitive output, and decisions made from it?
- What transparency, withdrawal, rights, retention, security, and audit controls apply?
- Which change will reopen the analysis, and who owns that review?
The final check is simple: what sensitive fact does the processing reveal, which Article 6 basis permits the operation, which Article 9 condition permits the category, and what evidence proves both answers? If the record has only the first legal basis, the team has described why it wants to use the data. It has not yet shown why this category of personal data may be processed.
References
- 1
- 2
- 3Regulation (EU) 2016/679, Article 9
eur-lex.europa.eu
- 4ICO, Consent
ico.org.uk
This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.
Related content
More from this channel›
- International data transfers under GDPR: why signing the SCCs is not the approval
- Data protection by design and by default: test the starting state
- Valid consent under GDPR: prove the choice, not just the click
- Right to object under GDPR: stop marketing immediately, test other uses case by case
- Pseudonymisation vs anonymisation: decide whether the identity link survives
- Storage limitation: turn retention periods into a working control
- DPIA before launch: turn high-risk processing into a decision
- Controller or processor? A practical role test for GDPR data processing
