Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Fiches
  4. Special Categories of Data (Art. 9) & Criminal Offences (Art. 10)
Courses Guides Blog Resources News
Français English Nederlands
Fiche 7/54 Part I — General Introduction Advanced Reviewed 2026-08-23

Special Categories of Data (Art. 9) & Criminal Offences (Art. 10)

Article 9 prohibits by default the processing of data revealing health, biometric traits, political opinions, or racial origin, unless one of 10 exhaustive exceptions is met. Article 10 strictly regul

Open in interactive reader
⚖️ Prohibitive Regime 📋 Strict Interpretation (Art. 9.2)

Special Categories (Art. 9) & Criminal Offences (Art. 10)

⚡ In 30 seconds

Processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data for uniquely identifying a person, health data, or sexual orientation is prohibited by default (Art. 9.1). Processing is lawful only if a standard legal basis (Art. 6) is combined with one of the 10 statutory exemptions in Art. 9(2).

10 Exemptions under Art. 9(2)

1. Explicit consent · 2. Employment & social security law · 3. Vital interests · 4. Legitimate activities of non-profit foundations · 5. Data manifestly made public by data subject · 6. Legal claims / court proceedings · 7. Substantial public interest · 8. Preventive or occupational medicine · 9. Public health · 10. Archiving in the public interest / research.

Article 10 (Criminal Records)

Processing data relating to criminal convictions and offences is restricted: it can only be carried out under the control of official authority, or when authorized by Union or Member State law providing appropriate safeguards.

⚡ Key Takeaways
  • Double-check cumulative basis: Art. 6(1) + Art. 9(2).
  • Standard 'implicit' consent is void; Art. 9(2)(a) mandates 'explicit consent'.
  • National law can impose additional conditions on genetic, biometric, or health data (Art. 9.4).
⚠️ Common Pitfall

Assuming that asking for criminal background checks from job applicants is broadly permitted without national statutory authorisation.

🛠️ In Practice

Conduct a DPIA prior to any systematic collection of biometric or health information in HR or customer platforms.

⚖️ Official Sources: Art. 9 & 10 GDPR · Recitals 51–56 · CJEU C-184/20 Vyriausioji ✓ Legal review: 23 August 2026

✓ Key takeaways

  • Special categories require a cumulative double legal basis: Art. 6 + Art. 9(2).
  • Article 9(2) exceptions are exhaustive and must be strictly interpreted.
  • Criminal convictions and offences (Art. 10) may only be processed under official authority or statutory authorization.

⚠ Common pitfall: Conflating sensitive data under Article 9 with criminal records under Article 10, which operate under separate statutory restrictions.

→ Actionable practice: Map internal health and biometric processing workflows and document the exact Article 9(2) derogation relied upon.

← Data Typology: Anonymous vs Pseudonymous vs Sensitive Data The Concept of Processing (Art. 4.2) →