Sensitive data is a special category of personal data under the GDPR.

The following types of information fall under this definition:

  • health data
  • racial or ethnic origin
  • religious beliefs
  • sexual orientation
  • trade-union memberships
  • political opinions
  • biometric data

As a Data controller , you must meet the following conditions in order to process sensitive data:

  • You must obtain user consent
  • The processing is necessary to protect the vital interests of the data subject when one is unable to give consent
  • The data subject has revealed the sensitive data publicly
  • It is necessary for claims or in a legal process
  • Processing the data for reasons of substantial public interest on the basis of EU or national law
  • You are processing the data for preventive or occupational medicine
  • The processing is required for public health reasons – preventing epidemics, etc.

For more details we recommend reading this article prepared by the European Commission.

What’s more, such data requires special protection from unauthorized access to ensure that the privacy and security of both individuals and companies is properly guarded. You can read about this here.


  • HIPAA, marketing and advertising: How to run compliant campaigns in healthcare

    Healthcare organizations deal with tons of sensitive information concerning people’s health. It needs to be handled with proper care. In the US, safe parameters for using this kind of data in different contexts, including marketing, are set by HIPAA. Unfortunately, many companies are still unaware of the provisions of the law and the potential consequences…

  • Norwegian DPA warns against EU-US data transfers – what it means for your website analytics

    If your company relies on Google Analytics or other US-based analytics tools, you may soon be putting your data compliance at risk. In February 2025, Norway’s Data Protection Authority (Datatilsynet) issued new guidance on data transfers to the United States, highlighting growing concerns about the legal framework supporting these transfers – the EU-US Data Transfer…