For the complete documentation index, see llms.txt. This page is also available as Markdown.

Sensitive Data Collection

Is your business collecting sensitive data?

Certain types of data afford special protections under data protection legislation such as the GDPR, HIPAA, FERPA and COPPA.

If your business collects health data or children’s data it is very likely to be subject to additional legal obligations.

Data about racial or ethnic origins, political opinions, religious or philosophical beliefs, genetics, biometrics and sex life or sexual orientation also hold additional protections under the GDPR. Careful attention to these is necessary in order to maintain regulatory compliance and avoid penalties.

Why does this matter?

The principles of GDPR apply significantly more strictly if your business is processing sensitive data, or ‘special category data’. There are also more limited grounds for the legal processing of special category data. For example, it is far more likely your business will need to get explicit consent from your user before it processes their data if that data is special category data. It is a good idea to seek advice from your DPO or a Privacy Partner before performing any action on the personal data of your users.

Non-compliance also presents financial ramifications. For example, if you collect special category data in the EEA and your business without additional technical and organisational safeguards for special category data, it could be fined up to €20 million, or 4% of worldwide annual turnover (whichever is higher). For example, in the Netherlands in 2024, Clearview AI was fined €30.5 million for unlawfully collecting and processing biometric data without explicit consent. Penalties can also include a ban on processing, regular data protection audits and liability damages to affected users.

Last updated