Sensitive data is a special category of personal data under the GDPR.

The following types of information fall under this definition:

  • health data
  • racial or ethnic origin
  • religious beliefs
  • sexual orientation
  • trade-union memberships
  • political opinions
  • biometric data

As a Data controller , you must meet the following conditions in order to process sensitive data:

  • You must obtain user consent
  • The processing is necessary to protect the vital interests of the data subject when one is unable to give consent
  • The data subject has revealed the sensitive data publicly
  • It is necessary for claims or in a legal process
  • Processing the data for reasons of substantial public interest on the basis of EU or national law
  • You are processing the data for preventive or occupational medicine
  • The processing is required for public health reasons – preventing epidemics, etc.

For more details we recommend reading this article prepared by the European Commission.

What’s more, such data requires special protection from unauthorized access to ensure that the privacy and security of both individuals and companies is properly guarded. You can read about this here.


  • Five things every marketer should know about web analytics in 2026

    Web analytics is changing fast. AI is moving from buzzword to actual business impact, privacy rules keep shifting on both sides of the Atlantic, and marketing teams are rethinking their tool stacks. What does this mean for analytics strategy in 2026? We asked industry experts to share their predictions.

  • first party data

    First-party analytics without consent: Your Digital Omnibus compliance guide

    The Digital Omnibus is the European Commission’s simplification initiative to modernize the EU’s digital rulebook and reduce consent fatigue. The framework would enable first-party analytics without consent when specific criteria are met, ending years of uncertainty about the use of legitimate interest for web statistics.