Skip to main content
Category: Special Category Data

Sensitive Data

Also known as: Sensitive Information
Simply put

Sensitive data is information that needs protection from unauthorized access or disclosure because its exposure could harm the privacy or security of an individual or organization. It covers a broad range of categories, which can include personal, financial, and other confidential information. In practice, what counts as sensitive depends on the context and the potential impact if the information is exposed or misused.

Formal definition

In general information-security usage, 'sensitive data' (also 'sensitive information') refers to information protected against unwarranted disclosure, where loss, misuse, unauthorized access, or modification could adversely affect an individual or organization. The term is used broadly across categories such as personal, financial, and other confidential data, and its classification is context-dependent, driven by the potential impact of exposure on security, privacy, or integrity. Note that this general usage is distinct from the GDPR concept of 'special category data' (which is a defined subset of personal data subject to additional protective conditions); the evidence packet does not address that regulatory definition, and practitioners should not treat this general definition as coextensive with any specific legal category.

Why it matters

Sensitive data sits at the center of most privacy and security programs because its exposure can adversely affect the security, privacy, or integrity of the individuals or organizations to whom it relates. Loss, misuse, unauthorized access, or modification of such information can cause tangible harm, which is why organizations invest in classification schemes, access controls, and safeguards proportionate to the potential impact of disclosure.

A recurring challenge is that 'sensitive data' as used in general information-security practice is broad and context-dependent, spanning personal, financial, and other confidential information. This general usage should not be confused with more precise regulatory categories. In particular, the GDPR concept of 'special category data' is a defined subset of personal data subject to additional protective conditions, and it is distinct from the wider information-security notion described here. Practitioners who treat the two as interchangeable risk either over-applying strict regulatory requirements to data that is merely confidential, or under-protecting data that triggers specific legal obligations.

Because classification is driven by the potential impact of exposure rather than a fixed list, the boundary of what counts as sensitive can vary between organizations, contexts, and jurisdictions. Teams should document their classification criteria, revisit them as context changes, and verify against applicable legal definitions and current official guidance rather than relying on a single general definition.

Who it's relevant to

Compliance leads and data protection officers
Those responsible for compliance programs need to map how their organization defines and classifies sensitive data, and to distinguish this general information-security usage from precise regulatory categories such as GDPR special category data. This helps ensure that additional legal conditions are applied where required and not misapplied where they are not.
Privacy and technology lawyers
Legal advisers benefit from recognizing that 'sensitive data' in operational and security contexts is broader and more context-dependent than any single statutory definition. They should verify which specific legal category applies before advising on obligations, as the general definition is not coextensive with any particular legal term.
Security engineers and data architects
Engineers implementing classification, access controls, and safeguards rely on impact-based assessment to decide how to protect information from unauthorized access, modification, or disclosure. They should align technical classification schemes with the organization's documented criteria and applicable legal requirements.
Risk and governance teams
Teams overseeing information governance use sensitivity classification to prioritize protective measures according to the potential impact of exposure. Because that impact is context-dependent, they should keep classification criteria under review as business context, data flows, and applicable rules evolve.

Inside Sensitive Data

Special Category Data (Article 9)
Under the GDPR, the term commonly rendered as 'sensitive data' most precisely corresponds to 'special categories of personal data' addressed in Article 9. These generally include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership, as well as genetic data, biometric data processed for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a person's sex life or sexual orientation.
Additional Article 9 Condition Requirement
Processing special category data is generally prohibited unless one of the specific conditions in Article 9(2) applies. This condition is required in addition to a lawful basis under Article 6, so identifying an Article 6 basis alone does not, by itself, permit processing of special category data.
Criminal Offence Data (Article 10)
Personal data relating to criminal convictions and offences is treated separately under Article 10 and is not technically part of the Article 9 special categories, though it is often handled with comparable safeguards. Its processing is subject to specific conditions and, in many cases, official authority or member state law, which can vary by jurisdiction.
Scope Boundaries
These categories concern personal data of identifiable living individuals. Genuinely anonymous data generally falls outside the GDPR, and the position on deceased persons' data can be governed by national law rather than the GDPR itself. Whether particular data reveals a special category can require assessment of context and inference, not just the data field label.

Common questions

Answers to the questions practitioners most commonly ask about Sensitive Data.

Is all personal data that feels private, such as a person's salary or home address, treated as sensitive data under the GDPR?
No. Under the GDPR, the terms typically used are special categories of personal data (Article 9) rather than a general notion of what feels private. Data such as salary or home address is personal data but is not, in itself, a special category unless it reveals one of the enumerated categories (for example, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and the processing of genetic data, biometric data for uniquely identifying a person, health data, or data concerning sex life or sexual orientation). Sensitivity in an ordinary sense does not by itself trigger the Article 9 regime, though such data still requires an Article 6 legal basis and must be handled in line with the other GDPR principles. You should verify the current list against the official text.
Does processing special category data always require the individual's consent?
No. Consent is only one of the conditions available for processing special category data. Article 9 sets out several conditions that may permit such processing, and explicit consent is one of them, but others exist, such as conditions relating to employment and social security obligations, vital interests, or reasons of substantial public interest, among others, and some are subject to member state law. It is important to note that an Article 9 condition operates in addition to, not instead of, an Article 6 legal basis; both are generally required. Which conditions are available and how they are framed can depend on national implementing law, so treating consent as the universal or default route is a common error. Verify the applicable conditions against the current text and relevant national law.
How should an organisation identify whether it processes special category data in practice?
In most cases this involves mapping data flows and reviewing the actual content and purpose of processing rather than relying only on field labels. Data can fall within a special category because it directly states a protected attribute or because it reveals one by inference, so an assessment of context is generally advisable. Free-text fields, images, and combined datasets can contain special category data unintentionally. Where the position is uncertain, organisations typically document their reasoning. This is an operational judgement rather than a fixed rule, and the boundary of what reveals a special category can be a point of interpretation, so it is sensible to check current regulatory guidance.
What should be recorded when relying on an Article 9 condition to process special category data?
Organisations generally document both the Article 6 legal basis and the applicable Article 9 condition, since both are typically needed. Where the chosen condition depends on national implementing law or on an appropriate policy document being in place, that supporting basis is usually recorded as well. Records of processing and, where relevant, the outcome of any assessment can help demonstrate accountability. The specific documentation expectations can vary by member state and by the condition relied upon, so the precise requirements should be confirmed against the current official text and applicable national law.
When does processing special category data indicate that a Data Protection Impact Assessment may be needed?
Processing special category data, particularly on a large scale, is one of the factors commonly associated with higher risk and may point toward carrying out a Data Protection Impact Assessment (Article 35). A DPIA is not automatically required in every instance, and it is a distinct instrument from the documentation of a legal basis or condition; it is a risk assessment tool. Whether one is required depends on the nature, scope, context, and purposes of the processing and, in some cases, on regulator lists of processing types that require or are exempt from a DPIA. These lists can differ between supervisory authorities, so the current position should be checked.
What additional safeguards are typically considered when handling special category data?
Because such data can carry heightened risk to individuals, organisations generally consider measures proportionate to that risk, which may include access controls, data minimisation, and technical and organisational security measures appropriate to the processing. Additional considerations may arise where the data is transferred internationally, since transfer mechanisms and any supplementary measures evolve over time and should be assessed separately. The appropriate safeguards are context and risk dependent rather than a fixed checklist, and there can be divergence in regulator expectations, so specific measures should be assessed for the particular processing and verified against current guidance.

Common misconceptions

Sensitive data always requires the individual's explicit consent to process.
Explicit consent is only one of several conditions in Article 9(2). Other conditions, such as those relating to employment and social security law, vital interests, substantial public interest, or health and social care contexts, may apply subject to their specific requirements and any relevant member state law. Consent is not a universal requirement.
Having a valid Article 6 lawful basis is enough to process sensitive data.
Special category data generally requires both an Article 6 lawful basis and a separate Article 9(2) condition. The two are distinct and must be satisfied together; an Article 6 basis alone is typically insufficient.
Criminal conviction data is part of the special categories under Article 9.
Criminal convictions and offences data is addressed separately under Article 10 rather than Article 9, and its processing conditions differ and can depend on national implementing law. It is often protected with similar rigour but should not be conflated with the Article 9 categories.

Best practices

Confirm both a lawful basis under Article 6 and a specific condition under Article 9(2) before processing any special category data, and document each separately.
Assess data in context rather than by field label alone, since information that indirectly reveals or allows inference of a special category may fall within scope.
Treat criminal offence data under Article 10 separately from Article 9 categories, and verify any applicable national or member state law that governs its processing.
Check whether national implementing law or member state derogations affect the available conditions or add safeguards for the sensitive data you handle, as the position can vary by jurisdiction.
Where consent is relied upon, ensure it meets the explicit consent standard and remains genuinely valid, and identify an alternative condition where consent is not appropriate.
Verify category definitions and any specific conditions against the current official text of the Regulation and applicable guidance, as scope and interpretation can be subject to regulatory clarification.