Skip to main content
Category: Special Category Data

Genetic Data

Also known as: Genomic Data
Simply put

Genetic data is information about a person's inherited or acquired genetic characteristics, such as the biological features revealed by analysing their DNA or RNA. Because it can uniquely identify an individual and reveal sensitive information, it is treated as a particularly protected type of personal data. Note that where information relates only to an anonymous sample and cannot be linked to an identifiable person, it generally falls outside this definition.

Formal definition

Under the GDPR, genetic data is personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about that person's physiology or health, and which typically result from an analysis of a biological sample (for example, DNA or RNA analysis). Recital 34 provides interpretive context for this definition. As genetic data constitutes a special category of personal data, its processing generally requires both an Article 6 lawful basis and a separate condition under Article 9; the reader should verify the precise defining article and applicable Article 9 condition against the current official text, and note that member state derogations may vary the position and that the UK GDPR applies its own corresponding provisions.

Why it matters

Genetic data occupies a distinctive position in data protection law because it is both uniquely identifying and deeply revealing. A single genetic profile can distinguish one individual from nearly all others, and it can disclose information not only about the person concerned but also, by inference, about biological relatives who never consented to any processing. Because it can reveal sensitive information about physiology and health, the GDPR treats it as a special category of personal data, meaning that its processing generally requires both an Article 6 lawful basis and a separate condition under Article 9. The reader should verify the precise defining article and the applicable Article 9 condition against the current official text.

The stakes are practical as well as legal. Genomic data is used to power innovation across a range of fields, including vaccine development, pharmaceutical manufacturing, biofuel development and agriculture. This breadth of use expands the number of organisations handling such data and increases the range of contexts in which sensitive characteristics may be exposed, re-used or combined with other datasets. Unlike a password or an account number, genetic characteristics cannot be reset if compromised, which heightens the long-term risk associated with any loss of control over the data.

Scope is a central limitation to keep in mind. Where information relates only to an anonymous sample and cannot be linked to an identifiable person, it generally falls outside the definition of genetic data and, more broadly, of personal data. Assessing whether a sample or dataset is genuinely anonymous is often a fact-specific judgement rather than a settled conclusion, and positions can vary between regulators and under member state derogations. The UK GDPR applies its own corresponding provisions, so organisations operating across jurisdictions should not assume a single uniform treatment.

Who it's relevant to

Healthcare and clinical organisations
Hospitals, laboratories and clinical research bodies routinely analyse biological samples and generate genetic data that gives unique information about a person's physiology or health. They generally need to identify both an Article 6 lawful basis and a separate Article 9 condition, and to assess how national implementing law and any derogations affect the position in their jurisdiction.
Research institutions and academia
Genomic data underpins research and data science that decode genetic characteristics. Researchers should consider whether datasets are genuinely anonymous, since data that cannot be linked to an identifiable person generally falls outside the definition, and should treat re-identification risk as a fact-specific assessment rather than a settled outcome.
Commercial and industrial users
Genomic data is used to power innovation in areas such as vaccine development, pharmaceutical manufacturing, biofuel development and agriculture. Organisations in these sectors should assess whether the data they handle qualifies as genetic data about identifiable individuals, which would bring special category obligations, or whether it is anonymous and outside scope.
Data protection officers and compliance leads
Those responsible for compliance need to document the lawful basis and the Article 9 condition relied upon, monitor divergence between EU and UK GDPR positions and member state derogations, and account for the long-term sensitivity of genetic data, which cannot be reset if compromised. Precise article references and conditions should be verified against the current official text.
Data subjects and their relatives
Because genetic data can reveal information by inference about biological relatives, the interests affected by its processing may extend beyond the individual who provided the sample. This wider impact is relevant to transparency, risk assessment and the handling of individual rights.

Inside Genetic Data

Special category status
Genetic data is treated as a special category of personal data under GDPR, meaning its processing is generally prohibited unless an Article 9(2) condition applies in addition to an Article 6 legal basis.
Inherited or acquired characteristics
The concept covers data relating to inherited or acquired genetic characteristics of a natural person that give unique information about that person's physiology or health, typically resulting from analysis of a biological sample.
Derivation from analysis
Genetic data generally arises from a specific technical analysis, such as chromosomal, DNA, or RNA analysis, or from analysis of another element enabling equivalent information to be obtained.
Individual and relational dimension
Because genetic information can reveal characteristics shared with biological relatives, processing may have implications beyond the individual data subject; the precise treatment of relatives' interests can depend on context and may not be fully settled.
Scope boundary with anonymous data
The classification applies to data relating to an identified or identifiable natural person. Data that has been rendered genuinely anonymous falls outside GDPR, though achieving true anonymisation of genetic data can be difficult given its potential to identify individuals.
Interaction with health data
Genetic data may overlap with data concerning health, but the two are distinct special categories; a given dataset may fall under one or both depending on what it reveals.

Common questions

Answers to the questions practitioners most commonly ask about Genetic Data.

Is genetic data just another type of ordinary personal data?
No. Genetic data is treated as a special category of personal data under Article 9 GDPR. This means that, in addition to identifying an Article 6 lawful basis, you generally need to satisfy a separate Article 9 condition before processing it. Treating it as ordinary personal data would understate the applicable safeguards and conditions.
Does processing genetic data always require the individual's explicit consent?
Not necessarily. Explicit consent is one of the Article 9 conditions, but it is not the only one. Other conditions, such as those relating to health or scientific research purposes, may apply, and some depend on member state implementing law. You should assess which Article 9 condition genuinely fits your processing rather than assuming consent is the default or the only route.
How do we identify a lawful basis and condition for processing genetic data?
Generally you need two things: an Article 6 lawful basis and a separate Article 9 condition, because genetic data is a special category. Document both, and check whether the relevant Article 9 condition depends on national implementing law or additional safeguards. The correct combination depends on your specific purpose and context and should be assessed case by case.
When would a Data Protection Impact Assessment be relevant to genetic data processing?
Processing special category data such as genetic data, particularly at scale, is a factor that typically points toward a higher likelihood of high risk and may trigger the need for a Data Protection Impact Assessment under Article 35. Whether a DPIA is required is subject to assessment against the relevant criteria and any regulator guidance, so evaluate your specific processing rather than assuming a fixed outcome.
What should we consider before transferring genetic data outside the EU?
Transfers of genetic data are subject to the same international transfer rules as other personal data, which may involve an adequacy decision, an appropriate transfer tool, and, where relevant, supplementary measures. Given the sensitivity of special category data, you should assess the risks carefully. Transfer mechanisms and adequacy positions evolve, so verify the current status against official sources at the time of transfer.
How does genetic data's sensitivity affect security and access controls?
Because genetic data is a special category, organisations generally apply heightened technical and organisational measures proportionate to the risk, which may include restricting access, limiting retention, and applying strong safeguards. The appropriate measures depend on the nature, scope, and risk of the processing and should be determined through assessment rather than a one-size-fits-all standard.

Common misconceptions

Consent is always required to process genetic data.
Consent is only one of the possible conditions. Processing genetic data generally requires both an Article 6 legal basis and a separate Article 9 condition, of which explicit consent is one option among several; the appropriate combination depends on the context and, in some cases, on member state law that may impose further conditions or limitations.
All genetic data is automatically also health data, and the terms are interchangeable.
Genetic data and data concerning health are distinct special categories. Genetic data may reveal health information, but not all genetic data does, and each category should be assessed on its own terms rather than treated as a single label.
Aggregating or coding genetic data makes it non-personal and outside GDPR.
Coding, pseudonymisation, or aggregation does not necessarily make genetic data anonymous. Given its high potential to single out or re-identify individuals, such data typically remains personal data subject to GDPR unless it is genuinely and irreversibly anonymised, which is often difficult to achieve in practice.

Best practices

Identify and document both an Article 6 legal basis and an applicable Article 9 condition before processing genetic data, and verify whether relevant member state or national implementing law imposes additional conditions.
Consider whether a Data Protection Impact Assessment is warranted, as large-scale processing of special category data such as genetic data is generally likely to require one.
Assess whether the data can be considered genuinely anonymous before excluding it from GDPR, and treat pseudonymised or coded genetic data as personal data in most cases.
Distinguish in your records whether a dataset constitutes genetic data, health data, or both, since the applicable conditions and safeguards may differ.
Apply strong technical and organisational safeguards proportionate to the sensitivity and re-identification risk of genetic data, and document the basis for those measures.
Account for the potential relational implications of genetic data for biological relatives when scoping processing, recognising that this area may involve unsettled points and verifying current regulatory guidance.