Skip to main content
Category: Special Category Data

Racial or Ethnic Origin

Also known as: Racial Origin, Ethnic Origin
Simply put

Racial or ethnic origin refers to information about a person's race or ethnicity. Race generally relates to physical characteristics such as skin color, while ethnicity generally relates to cultural aspects such as language, traditions, and the group a person's family belongs to. Under EU data protection law, this type of information is treated as particularly sensitive and receives extra protection.

Formal definition

Racial or ethnic origin is one of the categories of special category (sensitive) personal data recognized under the GDPR, and its processing is generally prohibited unless one of the additional conditions applicable to special category data is satisfied, in addition to a lawful basis for processing personal data more broadly. The concepts of 'race' and 'ethnicity' are conceptually distinct in the underlying evidence: a racial group is typically characterized by shared physical characteristics or phenotypes suggesting common genetic heritage, whereas an ethnic group is typically characterized by shared cultural attributes such as language, tradition, history, nationality, or lineage, though the terms are sometimes used interchangeably and their boundaries are contested. Practitioners should note that the specific GDPR article numbers governing special category data and the applicable processing conditions should be verified against the current official text, that national implementing law and member state derogations may affect the position, and that the position under the UK GDPR may diverge from the EU GDPR. This definition addresses the meaning of the concept; it does not itself determine when processing of such data is permissible, which is subject to a separate lawfulness and condition assessment.

Why it matters

Racial or ethnic origin is treated as special category data under EU data protection law, meaning its processing is generally prohibited unless an additional condition applicable to special category data is satisfied, on top of a lawful basis for processing personal data more broadly. This heightened protection reflects the recognized potential for such data to expose individuals to discrimination or unequal treatment. For organizations, the practical consequence is that collecting or using this information cannot rest on an ordinary lawful basis alone; a separate condition and lawfulness assessment is required, and the analysis may differ depending on national implementing law and member state derogations.

The conceptual boundaries of these terms add to the compliance challenge. 'Race' and 'ethnicity' are conceptually distinct but are sometimes used interchangeably, and their boundaries are contested. Race generally relates to shared physical characteristics or phenotypes suggesting common genetic heritage, while ethnicity generally relates to shared cultural attributes such as language, tradition, history, nationality, or lineage. Because ethnicity is sometimes tied to self-identification and can overlap with nationality, data that appears innocuous on its face may in some contexts reveal racial or ethnic origin, expanding the scope of information that warrants the special category treatment.

Given this, controllers should approach data that may reveal racial or ethnic origin with care, mapping where such data enters their processing operations and documenting the condition relied upon. Because the position may diverge between the EU GDPR and the UK GDPR, and because member state derogations can vary the outcome, the applicable rules should be verified against the current official text rather than assumed to be uniform across jurisdictions.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads need to identify where information revealing racial or ethnic origin is collected or inferred across processing operations, and to document both the lawful basis and the additional special category condition relied upon. They should account for the possibility that data which is not overtly about race or ethnicity may nonetheless reveal it, given the overlap with attributes such as nationality and lineage.
Compliance and Legal Teams
Legal and compliance teams advising on processing of this data should verify the applicable article numbers and conditions against the current official text and consider whether national implementing law or member state derogations affect the position. Where an organization operates across the EU and the UK, they should account for potential divergence between the EU GDPR and the UK GDPR.
Engineers and Data Architects
Those designing data systems should be aware that fields capturing self-identification, ethnicity, nationality, or lineage may amount to special category data, and that such data typically warrants additional safeguards and controls. Because the boundaries between race and ethnicity are contested and sometimes used interchangeably, data models and classification schemes should be reviewed with privacy specialists rather than assumed to be non-sensitive.

Inside Racial or Ethnic Origin

Special category data under Article 9
Personal data revealing racial or ethnic origin is listed among the special categories of personal data in Article 9(1) of the GDPR. Its processing is generally prohibited unless one of the specific conditions in Article 9(2) applies, in addition to an Article 6 legal basis.
Data 'revealing' origin
The category covers not only explicit statements of a person's racial or ethnic origin but also data from which such origin may be inferred or revealed. Whether particular data reveals origin is subject to assessment in context, and guidance and case law continue to shape how broadly this is interpreted.
Additional Article 9(2) condition required
Because consent is not a universal requirement, processing may rely on other Article 9(2) conditions (for example, explicit consent, substantial public interest, or employment and social protection law grounds). The available conditions can be shaped by member state derogations, so the position may vary between jurisdictions.
Relationship to an Article 6 legal basis
An Article 9(2) condition does not replace the need for a lawful basis under Article 6. A controller generally must identify both a valid Article 6 basis and an Article 9(2) condition to process this data lawfully.
Scope limited to identifiable individuals
As with all personal data, this category concerns data relating to identified or identifiable living individuals. Genuinely anonymous data generally falls outside the GDPR, and the data of deceased persons is typically outside scope subject to national law.

Common questions

Answers to the questions practitioners most commonly ask about Racial or Ethnic Origin.

Is data revealing racial or ethnic origin banned outright under the GDPR?
No. Data revealing racial or ethnic origin is a special category of personal data whose processing is subject to a general prohibition under Article 9(1), but that prohibition is lifted where one of the exceptions in Article 9(2) applies (for example, explicit consent, or reasons of substantial public interest, subject to conditions). The correct framing is that such processing is restricted and requires an additional condition, not that it is absolutely prohibited. Member state law may also impose further limits or conditions, so the position can vary by jurisdiction.
If we have a legitimate interest, is that enough to process racial or ethnic origin data?
Generally no. A legitimate interest under Article 6(1)(f) may establish a lawful basis for processing personal data in principle, but special category data requires an additional condition under Article 9(2) on top of an Article 6 basis. Article 9(2) does not contain a standalone 'legitimate interests' exception, so you typically need to identify a separate applicable condition such as explicit consent or a substantial public interest condition recognised in EU or member state law. You should assess both layers independently.
How do we determine whether data 'reveals' racial or ethnic origin rather than just being neutral data?
The concept can extend beyond data that expressly states origin to data from which such origin may be inferred. Guidance and case law have indicated that inference can bring data within the special category, though the precise boundary is subject to interpretation and may evolve. In practice, you should assess whether the data, alone or combined with other information you hold, would allow racial or ethnic origin to be deduced, and document that assessment. Where the position is uncertain, treat the data cautiously and verify against current regulatory guidance.
What should we document before processing racial or ethnic origin data?
In most cases you should record the Article 6 lawful basis, the applicable Article 9(2) condition, and, where relevant, the underlying EU or member state provision authorising the processing. You should also consider whether a Data Protection Impact Assessment under Article 35 is required, since processing special category data on a large scale is among the factors typically pointing toward higher risk. Retain records that show how you assessed necessity and proportionality. The specific documentation expectations can be shaped by national implementing law, so confirm local requirements.
Can we rely on explicit consent to collect racial or ethnic origin data from employees or service users?
Explicit consent is one of the Article 9(2) conditions, but its suitability depends on context. Where there is an imbalance of power, such as in some employment relationships, regulators have expressed concern about whether consent can be freely given, so it may not be a robust condition in every case. You should assess whether an alternative condition is more appropriate and ensure any consent meets the applicable standard for validity. Because regulator views and national rules can differ, verify the position for the relevant jurisdiction.
How does this interact with diversity monitoring initiatives?
Diversity monitoring often involves racial or ethnic origin data and therefore engages both an Article 6 basis and an Article 9(2) condition. Some member states provide specific conditions or safeguards for equality and diversity monitoring under national law, so the available route can vary. Practical steps typically include minimising the data collected, considering aggregation or pseudonymisation, being transparent about the purpose, and confirming the applicable condition before collection. Because the enabling provisions differ across jurisdictions, check the relevant national implementing law rather than assuming a uniform EU position.

Common misconceptions

Racial or ethnic origin data can be processed like ordinary personal data as long as there is an Article 6 legal basis.
This data is a special category under Article 9. In addition to an Article 6 basis, an applicable Article 9(2) condition is generally required, and processing is otherwise prohibited by default.
Explicit consent is always required to process racial or ethnic origin data.
Explicit consent is one route under Article 9(2), but it is not the only condition. Other conditions, such as substantial public interest or employment-related grounds, may apply, and their availability can depend on member state law.
Only fields expressly labelled as race or ethnicity fall within this category.
The category extends to data that reveals or allows inference of racial or ethnic origin, so seemingly neutral data may fall within scope depending on the context. This assessment is fact-specific and continues to be shaped by guidance and case law.

Best practices

Confirm both an Article 6 legal basis and an applicable Article 9(2) condition before processing any data that reveals racial or ethnic origin, and document the reasoning.
Assess whether data you hold could indirectly reveal or allow inference of origin, rather than looking only at explicitly labelled fields.
Check whether relevant member state derogations or national implementing law affect the Article 9(2) conditions available in your jurisdiction, and verify against the current official text.
Where processing is high risk, consider whether a Data Protection Impact Assessment under Article 35 is warranted, applying the applicable risk threshold.
Apply data minimisation and access controls so this category is collected and retained only where a valid condition supports it.
Keep monitoring evolving regulatory guidance and case law, since interpretation of what data reveals origin and how conditions apply may develop over time.