Do you hold special category data?

What is Special Category Personal Data?

Special category data is information about an individual which is particularly sensitive. This includes personal information, such as:

  • race or ethnic origin
  • political opinions
  • religious or philosophical beliefs
  • trade union membership
  • genetic data
  • biometric data for the purpose of uniquely identifying someone
  • physical or mental health
  • sex life or sexual orientation

Further regulations apply to information that relates to an individual’s criminal convictions and offences.

 

What Sort of Organisations Hold Special Category Personal Data?

All sorts of organisations hold this kind of information. If you are an employer, you may have information about your employees’ trade union membership or about their health, such as sick leave. Obviously, if you work in the health industry, whether that be in a hospital where major operations are carried out or a beauty salon providing eyelash extensions, your organisation will hold special category information about your clients. Many other industries also hold large amounts of this kind of data.

 

What Are Your Responsibilities if You Hold Special Category Personal Data?

Firstly, because this data is particularly sensitive you must have both a lawful basis and a separate condition for processing this data under the General Data Protection Regulation (GDPR). Some of the conditions are:

  • You have the individual’s explicit consent
  • The individuals are incapable of giving consent and it is in their vital interest
  •  It is necessary to establish, exercise or defend of legal claims or the courts are acting in their judicial capacity

There are 10 conditions in total – these are just a few examples.

You should determine your condition(s) for processing special category data and very clearly document it in order to comply with the GDPR.

 

Do You Need Additional Security if You Hold Special Category Data?

This data must be kept secure. The ICO recommends a layered approach to data security. For example: locked and alarmed buildings; locked filing cabinets; locked computers; encrypted files; strong passwords which change regularly. A Data Protection Professional can advise on the security measures you should take.

 

Is the Retention Period for Special Category Data Different?

The GDPR says that you should only keep personal information and special category personal data for as long as necessary for the purpose of processing. This means that the retention periods vary and depend on the type of data and why you are processing it. For example, personal data collected in relation to the performance of a contract is often retained for 6 years, whereas personal data relating to births is retained for 25 years. It is important to have a retention schedule setting out the different types of data you hold, and what the retention period is for each type.

 

What Are the Penalties for a Special Category Data Breach?

The penalty for a data protection breach depends on which Article of the GDPR has been breached. However, if the breach involves this type of data then the ICO may treat your organisation more harshly, and issue a higher penalty. These kinds of breaches can also have a negative effect on reputation.

If you are unsure whether you hold this type of data or worry that you may not be adhering correctly to the GDPR, get in touch with our team for support.

You can also find out how we help companies like yourself in managing your special category date by reading our case study.

related posts

Bethany Meredith

Navigating SAR Chaos: Why PDF Conversion and Deduplication Are Your Secret Weapons

When a Subject Access Request lands in your inbox, the one-month clock starts ticking immediately, and the real bottleneck usually isn’t finding the data, it’s wading through duplicate files and endless email threads. Discover why deduplication and PDF conversion aren’t just nice-to-haves but non-negotiable steps in your SAR pipeline: cutting review volume by up to 60%, closing redaction loopholes, and delivering a secure, universally accessible disclosure , all while keeping your compliance team sane and your deadline intact.

Read More »
Alex Haslam

DPAS Data Protection Bulletin – August 2026

Welcome back to our monthly DPAS bulletin, where we cover the latest data protection news and developments from around the world.

Ever wondered how a routine government spreadsheet leak turns into a two-year covert court order? How about why the police might feel your mother-in-law’s contact details were key to national security? Have you ever pondered how many working weeks it takes to read a cookie banner? Whether Wall Street knows about your last GP visit? Or if you’re in Australia (g’day) why an AI is sending notes on your worst rashes to faraway cloud servers?

Read about all this and more in our latest DPAS Data Protection Bulletin.

Read More »
Sophie Costain

Should All My Employees Be Able to Recognise a Subject Access Request?

Data protection is not just about cybersecurity; it relies on your employees recognising Subject Access Requests. The statutory one-month deadline begins the moment a request is received, even informally. Discover why training your entire workforce to instantly spot and escalate these requests is essential to avoid serious regulatory compliance breaches.

Read More »

Get a Free Consultation