Special Category Data
Special category data is a type of personal data that is considered especially sensitive and is therefore subject to stronger protections under data protection law. It includes information such as a person's racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership. Because exposing this data could significantly affect an individual's rights, organizations face stricter conditions before they can lawfully process it.
Under the GDPR (specifically Article 9), special category data refers to categories of personal data that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, among other sensitive types. As commonly defined in UK and EU data protection practice, such data is subject to a general prohibition on processing unless a specific lawful condition applies, reflecting its heightened sensitivity and potential to significantly impact data subjects' rights. The term is used interchangeably with 'sensitive personal data' in some contexts; note that the precise enumerated categories and applicable processing conditions are defined by the relevant instrument and jurisdiction (for example, GDPR and UK GDPR), and this entry does not exhaustively list every category or condition.
Why it matters
Special category data carries heightened legal and reputational stakes because its exposure or misuse can significantly affect an individual's fundamental rights and freedoms. Under the GDPR and UK GDPR, processing of this data is subject to a general prohibition unless a specific lawful condition applies, so organizations cannot rely on the same basis they might use for ordinary personal data. For AI systems in particular, this matters because models are frequently trained on, or infer, attributes such as racial or ethnic origin, political opinions, or religious beliefs, and doing so may trigger these stricter conditions even where the sensitive attribute was not directly collected.
The consequences of mishandling special category data are both regulatory and operational. Data protection authorities such as the UK's Information Commissioner's Office treat this data as needing more protection precisely because of its sensitivity, and getting the lawful condition wrong can render processing unlawful. This creates practical friction for AI governance and model risk functions that must document why sensitive data is processed, whether it is strictly necessary, and how it is safeguarded. It is worth noting that the precise enumerated categories and processing conditions are defined by the relevant instrument and jurisdiction, so requirements applicable under the GDPR or UK GDPR should not be assumed to transfer unchanged to other legal regimes.
Because the term overlaps with fairness and bias concerns in AI, professionals frequently conflate two distinct issues: the legal obligation to protect special category data, and the technical goal of building fair or non-discriminatory models. Handling special category data lawfully reduces certain compliance risks but does not by itself guarantee a fair outcome, and conversely, avoiding sensitive attributes does not eliminate the possibility that a model infers them from proxies.
Who it's relevant to
Inside Special Category Data
Common questions
Answers to the questions practitioners most commonly ask about Special Category Data.