Skip to main content
Category: Special Category Data

Genetic Data Definition

Also known as: Genetic Data, Genetic Personal Data
Simply put

Genetic data is information about a person's inherited or acquired genetic characteristics, such as details revealed by analysing their DNA or RNA. Because it can uniquely identify someone and reveal sensitive information about them and their relatives, it receives heightened protection under data protection law. It applies to identifiable living individuals rather than anonymous information.

Formal definition

Under the GDPR, genetic data is defined as personal data relating to the inherited or acquired genetic characteristics of a natural person, which give unique information about that person's physiology or health and which result in particular from an analysis of a biological sample from the individual (such as DNA or RNA analysis). It is treated as a special category of personal data, meaning its processing generally requires both an Article 6 lawful basis and satisfaction of an additional Article 9 condition; the precise conditions and any member state derogations should be verified against the current official text and applicable national implementing law. The concept applies to identifiable living natural persons and does not, as a rule, extend to anonymous data. Note that 'genetic data' as a defined legal term should be distinguished from broader technical uses of 'genomic data,' which may describe the structure and function of an organism's genome without necessarily meeting the legal definition; practitioners should assess identifiability and applicability of UK GDPR versus EU GDPR on a case-by-case basis.

Why it matters

Genetic data occupies a uniquely sensitive position in data protection law because it can both uniquely identify an individual and reveal detailed information about their physiology and health. Unlike many other data types, genetic information also carries implications for a person's biological relatives, who may not have participated in the processing yet whose predispositions or characteristics can be inferred from a single individual's DNA or RNA analysis. This relational quality means that a decision to process one person's genetic data can have privacy consequences that extend well beyond the individual data subject, which is a key reason the GDPR treats it as a special category of personal data warranting heightened protection.

Because genetic data is a special category, its processing generally requires more than an ordinary lawful basis: controllers typically need both an Article 6 lawful basis and satisfaction of an additional Article 9 condition. The precise conditions available, and the extent to which member state derogations apply, can vary, so practitioners should verify the position against the current official text and any applicable national implementing law rather than assuming a uniform rule across jurisdictions. Getting this wrong can leave processing without a valid legal foundation.

A further practical concern is the distinction between the legal term 'genetic data' and broader technical uses of 'genomic data.' Genomic data may describe the structure and function of an organism's genome and can support innovation in areas such as vaccine development, pharmaceutical manufacturing, and agriculture, but not all such data necessarily meets the legal definition of genetic data relating to an identifiable natural person. Treating these as interchangeable risks either over-applying special category obligations to non-identifiable material or, more seriously, under-protecting information that does meet the legal threshold.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams must identify when information qualifies as genetic data and ensure that processing rests on both an Article 6 lawful basis and an applicable Article 9 condition. They should verify whether member state derogations or national implementing law affect the available conditions, and confirm whether the UK GDPR or EU GDPR governs a given activity.
Researchers and Genomics Organisations
Organisations working with genomic data for purposes such as vaccine development, pharmaceutical manufacturing, biofuel development, or agriculture should assess whether the data they handle meets the legal definition of genetic data relating to an identifiable natural person. Broader technical genomic data about an organism's genome may not, in itself, satisfy the legal definition, so identifiability must be evaluated case by case.
Lawyers Advising on Special Category Processing
Legal advisers need to distinguish genetic data from other special category and technical data types, and to advise clients on the additional conditions required for lawful processing. Given that conditions and derogations can vary and evolve, advisers should point clients to the current official text and applicable national law rather than treating any single interpretation as settled.
Engineers and Data Architects
Those designing systems that store or analyse DNA or RNA data should build in the heightened safeguards appropriate to special category data and attend closely to identifiability. Because genetic data can reveal information about relatives as well as the data subject, technical measures and access controls should reflect that broader sensitivity.

Inside Genetic Data Definition

Statutory definition (Article 4(13))
Under the GDPR, genetic data means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about that person's physiology or health, and which result in particular from an analysis of a biological sample from the individual.
Inherited or acquired characteristics
The definition captures both genetic characteristics passed on through heredity and those acquired, distinguishing genetic data from other health indicators that do not derive from genetic characteristics.
Derivation from a biological sample
The definition indicates such data results in particular from an analysis of a biological sample, for example through chromosomal, DNA, or RNA analysis, though the phrasing suggests this is a typical rather than an exhaustive source; practitioners should verify the precise text against the current official Regulation.
Special category status (Article 9)
Genetic data is treated as a special category of personal data. Processing is generally prohibited unless an Article 9(2) condition applies, in addition to identifying a lawful basis under Article 6.
Member state derogations
The GDPR permits member states to introduce or maintain further conditions, including limitations, with regard to the processing of genetic data. As a result, the position can vary between member states and should be checked against national implementing law.
Relationship to identifiability
As personal data, genetic data must relate to an identified or identifiable natural person. Data that has been rendered genuinely anonymous falls outside the scope of the GDPR, though anonymisation of genetic data can be difficult to achieve in practice and requires case-by-case assessment.

Common questions

Answers to the questions practitioners most commonly ask about Genetic Data Definition.

Is all genetic data automatically treated as ordinary personal data?
No. Genetic data is a special category of personal data under Article 9 of the GDPR, not ordinary personal data. This means that in addition to identifying an Article 6 legal basis for processing, you must also satisfy a separate Article 9 condition before the processing is lawful. Treating genetic data as if it required only an Article 6 basis is a common misconception that can leave processing without the additional condition it needs.
Does genetic data only refer to a person's DNA sequence?
Not exactly. The concept is broader than a raw DNA sequence. It generally covers personal data relating to inherited or acquired genetic characteristics that give unique information about the physiology or health of an individual, typically resulting from an analysis of a biological sample. Narrowing the term to only sequenced DNA can cause organisations to overlook other data derived from genetic analysis that may fall within the definition. Where the boundary sits in a given case is subject to assessment against the facts.
What should we check before processing genetic data?
In most cases you should confirm two things in parallel: an appropriate Article 6 legal basis and a specific Article 9 condition permitting the processing of this special category. You should also consider whether member state or national implementing law imposes additional or more specific conditions, since the GDPR permits derogations for genetic data that can vary between jurisdictions. Verify the applicable conditions against the current official text and relevant national law before relying on them.
Does processing genetic data typically require a Data Protection Impact Assessment?
Often, yes. Large-scale processing of special category data, including genetic data, is generally the kind of high-risk processing for which a DPIA under Article 35 is expected. Whether a DPIA is required in a specific case is subject to assessment against the risk to individuals and any applicable supervisory authority lists of processing operations that require one. Consult the relevant regulator's guidance, which can differ between member states.
Can we rely on consent as the Article 9 condition for genetic data?
Explicit consent is one of the conditions that can apply, but it is not the only one and is not a universal requirement. Other Article 9 conditions, such as those relating to health or specified public interest purposes, may be more appropriate depending on the context, and national law may restrict or specify which conditions are available for genetic data. Which condition is suitable should be determined case by case rather than defaulting to consent.
How should we distinguish genetic data from anonymous data derived from samples?
The GDPR generally applies to personal data relating to identifiable individuals and does not govern truly anonymous data. Whether data derived from a genetic analysis is anonymous or merely pseudonymised is a factual question that depends on the risk of re-identification, which can be significant given the inherently identifying nature of genetic information. Because the boundary is context dependent and subject to assessment, treating such data as anonymous should not be assumed without a careful evaluation.

Common misconceptions

Genetic data and health data are the same category.
They are distinct concepts under the GDPR, each separately defined. While both are special categories under Article 9 and can overlap, genetic data specifically concerns inherited or acquired genetic characteristics giving unique information about physiology or health, and not all health data is genetic data.
Consent is always required to process genetic data.
Consent is one possible route, but genetic data requires both a lawful basis under Article 6 and a separate condition under Article 9(2). Several Article 9(2) conditions other than explicit consent may apply depending on context, and the appropriate combination should be assessed case by case, taking account of any national derogations.
Genetic data is only covered if a full DNA sequence is processed.
The definition turns on whether the data gives unique information about the individual's physiology or health resulting from analysis, not on the completeness of any sequence. Partial genetic information can still fall within the definition; this should be assessed against the specific data in question.

Best practices

Confirm at the outset whether the data in scope meets the Article 4(13) definition, and document the analysis, since classification as genetic data triggers the Article 9 regime.
Identify and record both an Article 6 lawful basis and an applicable Article 9(2) condition before processing, rather than assuming consent is the only or default route.
Check the relevant member state (or UK) implementing law for additional conditions or limitations on genetic data, as the position can diverge from the baseline GDPR text.
Treat claims of anonymisation for genetic data with caution, assess re-identification risk on a case-by-case basis, and retain the special category safeguards where genuine anonymity cannot be demonstrated.
Consider whether a Data Protection Impact Assessment under Article 35 is warranted, given that large-scale processing of special category data typically indicates higher risk, and verify current supervisory authority guidance.
Verify article numbers, definitional wording, and any national derogations against the current official text before relying on them in a compliance program, and note where regulator guidance or interpretation remains unsettled.