Compliance, Standards and Contracts
GDPR Special Category Data: What It Is and How to Handle It Safely
GDPR special category data is the most sensitive personal information your organisation can hold, and the UK GDPR treats it accordingly. Getting it wrong is one of the fastest routes to an ICO enforcement action, because the rules are stricter than for ordinary personal data and many businesses process this data without realising it. This guide explains what special category data is, the extra conditions you need to process it lawfully, and the practical safeguards UK organisations should have in place.
Handling special category data safely is not just a compliance box to tick. It is also central to your cyber risk: a breach of health, biometric or ethnicity records causes far more harm than a leaked mailing list, and insurers and regulators both know it.
What is special category data?
Special category data is personal data that reveals or concerns particularly sensitive aspects of a person’s life. Article 9 of the UK GDPR sets out nine categories:
- racial or ethnic origin
- political opinions
- religious or philosophical beliefs
- trade union membership
- genetic data
- biometric data, where used to uniquely identify someone
- data concerning health
- data concerning a person’s sex life
- data concerning a person’s sexual orientation
A few points catch people out. Biometric data, such as a fingerprint or face template, only counts as special category data when you use it for the purpose of uniquely identifying an individual. Ordinary photographs are not automatically special category data. And information can be special category data by inference: a photo showing someone wearing a religious symbol, or a supermarket loyalty record that reveals a health condition, can bring you into scope even if you never set out to collect it.
Criminal offence data is handled separately under Article 10 of the UK GDPR and section 11 of the Data Protection Act 2018. It is not technically special category data, but it carries similar extra protection, so treat it with the same care.
Why the rules are stricter
Article 9 starts from a prohibition: you must not process special category data at all, unless you can point to one of ten specific conditions. This is on top of, not instead of, the usual requirement to have a lawful basis under Article 6. In other words, you always need two things: a lawful basis for processing (such as consent or legitimate interests) and a separate special category condition. Our guide to the UK GDPR and the Data Protection Act 2018 explains the Article 6 lawful bases in full.
The ten conditions for processing
Article 9(2) lists ten conditions. You need to identify and document which one applies before you process:
- explicit consent from the individual
- employment, social security and social protection law
- vital interests, where someone is physically incapable of giving consent
- processing by a not-for-profit body in the course of its legitimate activities
- data the individual has manifestly made public
- legal claims or judicial acts
- reasons of substantial public interest, with a basis in law
- health or social care, with a basis in law
- public health, with a basis in law
- archiving, research and statistics, with a basis in law
Five of these conditions (broadly employment, substantial public interest, health, public health, and research) require you to meet additional conditions and safeguards set out in Schedule 1 of the Data Protection Act 2018. For most of the Schedule 1 conditions you also need an Appropriate Policy Document (APD) in place that explains how you comply with the data protection principles and your retention and erasure policy for that data.
“Explicit consent” is a higher bar than ordinary consent: it must be a clear, specific, affirmative statement, not a pre-ticked box or implied agreement, and the individual can withdraw it at any time.
How to handle special category data safely
Once you know you process special category data, put these controls in place:
- Map it. Record where special category data lives in your systems, why you hold it, and which Article 9 condition and lawful basis apply. This belongs in your Record of Processing Activities.
- Write the paperwork. Prepare an Appropriate Policy Document where required, and make sure your privacy notice tells people you process this data and why.
- Do a DPIA. Large-scale processing of special category data usually requires a Data Protection Impact Assessment before you start.
- Restrict access. Apply the principle of least privilege so only staff who genuinely need the data can see it, and log access.
- Encrypt and separate. Encrypt special category data at rest and in transit, and keep it apart from lower-sensitivity data where practical.
- Set retention and deletion rules. Do not keep it longer than you need it, and delete it securely.
These controls also map neatly onto the technical measures insurers and certifications expect. If you are pursuing certification, see our overview of the eight data protection principles, which underpin all of this.
Special category data and cyber insurance
Insurers pay close attention to sensitive data. If your business processes health, biometric or other special category records, expect underwriters to ask how it is stored, who can access it, and whether you encrypt it. Strong controls here can lower your premium and, just as importantly, reduce the size and cost of a breach if one happens. A breach involving special category data is far more likely to cause serious harm to individuals, which raises both your regulatory exposure and your claims risk.
For the authoritative rules, the ICO’s own guidance on special category data is the definitive UK reference, and the full legal text sits in Article 9 of the UK GDPR.
Frequently asked questions
What is special category data under the UK GDPR? It is personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, and data concerning health, sex life or sexual orientation. These nine types are listed in Article 9 and get extra legal protection.
Is criminal offence data special category data? No. Criminal offence data is covered separately by Article 10 of the UK GDPR and section 11 of the Data Protection Act 2018. It is not technically special category data, but it needs a similar level of protection and its own specific conditions to process.
Do I need consent to process special category data? Not always. Explicit consent is one of ten conditions, but you may instead rely on conditions such as employment law, health or social care, legal claims, or substantial public interest. You must also have a separate lawful basis under Article 6 regardless of which Article 9 condition you use.
What is an Appropriate Policy Document? It is a written document required for many Schedule 1 conditions that explains how you comply with the data protection principles and sets out your retention and erasure policy for the special category or criminal offence data you process. It must be kept under review and available to the ICO on request.
Is a photograph special category data? Not by default. An ordinary photo is normal personal data. It becomes special category data if you process it as biometric data to uniquely identify someone, or if it reveals sensitive information such as someone’s ethnicity, religion or health.