Article 9 GDPR : Prohibition Principle and Exceptions for Sensitive Data
Article 9 GDPR establishes a general prohibition on processing special categories of personal data (health, biometric, political opinions, religious beliefs, sex life, racial origin), coupled with 10 strict and exhaustive statutory derogations (Art. 9(2)(a) to 9(2)(j)).
Prohibition Principle and Categories of Sensitive Data (Art. 9(1) GDPR)
Article 9(1) formally prohibits the processing of personal data revealing or concerning the following categories:
- Racial or ethnic origin, political opinions, religious or philosophical beliefs;
- Trade union membership;
- Genetic data and biometric data for the purpose of uniquely identifying a natural person;
- Data concerning health, sex life or sexual orientation of a natural person.
The CJEU confirmed (Meta Platforms judgment C-252/21) that aggregating behavioural data from which such sensitive characteristics can be deduced falls directly under this strict prohibition regime.
The 10 Exhaustive Statutory Exceptions (Art. 9(2) GDPR)
Processing sensitive data is lawful only where an express exception under Article 9(2) applies, notably:
- Explicit consent (Art. 9(2)(a)): For one or more specified purposes, unless Union or Member State law prohibits it;
- Employment and social security law (Art. 9(2)(b)): Necessary for complying with employer legal obligations;
- Protection of vital interests (Art. 9(2)(c)): Where the data subject is physically or legally incapable of giving consent;
- Data manifestly made public (Art. 9(2)(e)): By the data subject him- or herself;
- Establishment, exercise or defence of legal claims (Art. 9(2)(f));
- Preventive medicine, medical diagnosis and healthcare (Art. 9(2)(h)): By a professional subject to professional secrecy;
- Reasons of substantial public interest (Art. 9(2)(g)): Laid down by proportionate Union or Member State law.
Processing sensitive data mandatorily requires dual qualification: a lawful basis under Article 6(1) AND an exception under Article 9(2).
Verified Official Sources
General Data Protection Regulation — EU Reference Legal Framework
Consult official source →Publicité personnalisée : rejet de l'exécution contractuelle et de l'intérêt légitime pour le traitement massif croisé sans consentement libre
Consult official source →Traitement de données personnelles dans le cadre du développement de modèles d'IA, évaluation du risque de mémorisation/extraction, anonymisation des pondérations, intérêt légitime et mesures d'atténuation (Avis Art. 64 du CEPD)
Consult official source →Associated Operational Micro-Tools
Methodically assess the 6 legal grounds (contract, legal obligation, consent...) and frame your legitimate interests.
Check whether your project triggers mandatory DPIA requirements or meets the EDPB 9 high-risk criteria.
See Also in the Legal Framework
Article 6 GDPR: The Six Lawful Grounds for Lawful Processing
Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, ...
Article 35 GDPR : Criteria and Methodology of the DPIA
Legal framework of the Data Protection Impact Assessment (Art. 35 GDPR): mandatory cases, WP248 high-risk criteria, asse...
Article 10 GDPR : Criminal Data, Statutory Safeguards and Legal Newsdesk Sweden Ruling
Regime of Article 10 GDPR applicable to criminal convictions, offences and security measures: legal basis, safeguards an...