Special category data is the label European data protection law attaches to a closed list of personal information whose processing is prohibited unless a specific exemption applies. Article 9(1) of the General Data Protection Regulation names the types: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, plus genetic data, biometric data processed to identify someone uniquely, data concerning health, and data concerning sex life or sexual orientation. The default position is a ban. Everything else in the regulation works the other way round, starting from permission subject to conditions.

Advertising collides with the category constantly, and rarely on purpose. Almost no media buyer sets out to record a person's religion. But a bid request carrying the address of a page about depression, or a segment assembled from pharmacy purchases, can amount to processing special category data in law whatever the buyer intended.

What the category covers

The list is exhaustive. Information can be private, embarrassing or commercially valuable without being special category data: an email address or a device identifier sits outside Article 9 however carefully it needs protecting. Criminal conviction data is covered by Article 10 instead.

Processing requires two things stacked on top of each other: a lawful basis under Article 6, and separately one of the ten conditions in Article 9(2). Those run from explicit consent at (a) through employment law, vital interests, not-for-profit bodies, data manifestly made public by the individual, legal claims, substantial public interest, health and social care, public health, and research at (j). Most were written for hospitals, employers and public authorities. In advertising only explicit consent is realistically available, which is why the category functions less as a compliance exercise than as a wall.

Two details carry disproportionate weight. Biometric data falls inside Article 9 only when processed to identify someone uniquely, a distinction that has produced litigation rather than settled it. Article 9(4) lets member states impose further conditions on genetic, biometric and health data, so the rules are not uniform even under a regulation. Breaches sit in the higher penalty tier of Article 83(5), up to 20 million euros or 4% of worldwide annual turnover.

How an ad stack acquires it without asking

The decisive question is not what a controller meant to collect but what the data reveals. On 1 August 2022 the Court of Justice of the European Union ruled in C-184/20 that personal data liable indirectly to disclose a sensitive characteristic falls under Article 9(1). The case concerned a spouse's name in a Lithuanian conflict-of-interest declaration, from which sexual orientation could be deduced. On 4 October 2024, in C-21/23 Lindenapotheke, the court held that order data from an online pharmacy constitutes health data even where no diagnosis is attached. Germany's Administrative Court of Wiesbaden applied that logic to payment records on 28 November 2025, finding that shopping cart contents may qualify as sensitive under the GDPR.

Inference is how the category enters the programmatic pipeline. Bid requests carry content classification fields, and IAB Content Taxonomy 1.0, still widely used in OpenRTB integrations, includes tier-two codes such as IAB7-3 for AIDS/HIV, IAB7-18 for depression, IAB7-28 for incest and abuse support, IAB7-42 for substance abuse, and IAB23 for religion and spirituality. Page addresses, referrers and segment identifiers travel alongside them. None of those fields is labelled sensitive. Each can reveal something that is.

Regulators noticed early. The Information Commissioner's Office published its update report into adtech and real-time bidding on 20 June 2019 and prioritised special category data as one of two systemic concerns. It identified bid request fields covering politics, religion, ethnic groups and mental and physical health, concluded that explicit consent was the only available Article 9 condition, and named the IAB Transparency and Consent Framework and Google's Authorized Buyers protocol as falling short on it. Later ICO guidance set out three requirements for explicit consent: a clear statement rather than an affirmative action, specification of the nature of the data, and separation from any other consent being sought.

Origin and evolution

The idea predates online advertising by decades. Council of Europe Convention 108, opened for signature in 1981, singled out data on race, political opinions, religion, health and sexual life. Directive 95/46/EC carried the concept into EU law as special categories in Article 8. The GDPR, adopted on 27 April 2016 and applicable from 25 May 2018, kept the structure and added genetic and biometric data, neither of which the Directive had covered.

Court interpretation has widened the perimeter since. In C-101/01 Lindqvist, decided on 6 November 2003, the court read health data broadly enough to cover a remark that a colleague had injured her foot. On 4 October 2024 it limited Meta's use of personal data for advertising in C-446/21, holding that a statement about sexual orientation made at a public panel discussion did not license aggregating and analysing other data about that orientation for personalised advertising. The manifestly-made-public exemption is read restrictively.

A second layer arrived with the Digital Services Act. Article 26(3) of Regulation 2022/2065 prohibits providers of online platforms from presenting advertisements based on profiling that uses Article 9(1) data, and the prohibition is absolute rather than consent-based. Guidelines 3/2025, published by the European Data Protection Board on 12 September 2025, state that it applies even where the platform would otherwise hold both an Article 6 basis and an Article 9(2) derogation.

What the category does to campaign configuration

Platform policy translates the legal category into serving rules. Google's personalised advertising policy defines sensitive interest categories including health, negative financial status, relationship hardships, abuse and trauma, commission of a crime, religious beliefs, sexual interests and users under 18. Advertisers in those categories are barred from advertiser-curated audiences, the class covering Customer Match, uploaded data segments, lookalike segments and custom segments, while predefined Google audiences remain available because they are configured without sensitive signals.

That distinction produced a trap. On 3 June 2026 Google confirmed that Discovery and Demand Gen campaigns use advertiser-curated audiences by default, so a regulated advertiser who never changed the setting can find campaigns restricted from serving without an obvious cause. Customer data policies separately exclude conversions in sensitive categories from enhanced conversions and store sales uploads. On the supply side, publisher policies updated in December 2024 prohibit targeting on sensitive user information including health conditions, financial status, racial or ethnic origins and religious beliefs.

Processing at this sensitivity also triggers Article 35. The European Data Protection Board adopted its first standardised impact assessment template on 10 March 2026, Spain's AEPD having noted that deployments involving special categories or profiling at scale would generally require one.

Where the definition is contested

The largest open dispute is whether inference should count at all. The European Commission's Digital Omnibus proposal, tabled on 19 November 2025, would restrict Article 9 to data that directly reveals a characteristic about a specific person, with draft recital 26 confining protection to processing that creates significant risks and concerns an identified individual with certainty. Information derived through comparison, cross-referencing or deduction would fall outside, which is the opposite of C-184/20 and Lindenapotheke. A joint opinion adopted by the European Data Protection Board and the European Data Protection Supervisor on 10 February 2026 rejected the narrowing. The GDPR half of the package remained in negotiation through mid-2026, unlike the AI half, adopted by the Council on 29 June 2026.

Enforcement is uneven meanwhile. Spain's AEPD fined Yoti 950,000 euros in March 2026, 500,000 of it on the Article 9 count, finding a stored facial template used for one-to-one matching to be biometric special category data even though the company argued the purpose was authentication rather than identification. Weeks earlier the same authority fined FC Barcelona 500,000 euros over a facial and voice enrolment campaign but archived the Article 9 count, penalising only the inadequate impact assessment. Two biometric cases, one regulator, two outcomes on the same provision.

Disambiguation

Sensitive interest categories is Google's policy construct, not a legal one. The lists overlap but do not match: negative financial status and gambling are restricted by Google and are not Article 9 data, while trade union membership is Article 9 data and is not a named Google category.

Sensitive category exclusion targeting in Display & Video 360 is brand safety. It governs the content an advertisement appears next to, not the data used to select the audience, and most of it stops being available on 1 October 2026.

Sensitive data in United States law is a different list. The SECURE Data Act introduced in April 2026 would cover citizenship and immigration status and precise geolocation within 1,750 feet, neither of which appears in Article 9.

Recent developments

Enforcement has moved toward inferred health signals. The Dutch Autoriteit Persoonsgegevens set out three requirements for menstruation app providers and warned of a possible investigation, noting that while cycle data was not shared for advertising, advertising identifiers and device data were. California fined a Texas data broker 45,000 dollars on 30 December 2025 over lists organised by health condition, including records for 435,245 people classified by Alzheimer's disease.

The bidstream is being reworked by litigation. A federal judge granted final approval on 26 March 2026 to a settlement requiring an RTB Control that strips identifiers from Google bid requests, in a case whose record documented identifiers tied to health conditions, religion, ethnicity and sexual orientation. Yoti has said it will halt its Digital ID app in Spain on 10 September 2026 rather than rebuild the biometric step the AEPD objected to, while accepting that a retained facial template is Article 9 data.

Timeline

  • 28 January 1981: Council of Europe Convention 108 opened for signature, naming sensitive categories of data
  • 24 October 1995: Directive 95/46/EC adopted, establishing special categories in Article 8
  • 6 November 2003: CJEU decides C-101/01 Lindqvist, reading health data broadly
  • 27 April 2016: GDPR adopted, adding genetic and biometric data to the list
  • 25 May 2018: GDPR becomes applicable
  • 20 June 2019: ICO publishes its update report into adtech and real-time bidding
  • 1 August 2022: CJEU rules in C-184/20 that indirectly revealing data falls under Article 9
  • 19 October 2022: Digital Services Act adopted, including the Article 26(3) advertising prohibition
  • 4 July 2023: CJEU delivers C-252/21 on profiling by a social network
  • 17 February 2024: DSA obligations apply to all online platforms
  • 4 October 2024: CJEU decides C-446/21 Schrems and C-21/23 Lindenapotheke
  • 12 September 2025: EDPB publishes Guidelines 3/2025 on the DSA and GDPR interplay
  • 19 November 2025: European Commission tables the Digital Omnibus proposal
  • 28 November 2025: Administrative Court of Wiesbaden rules on shopping cart data
  • 30 December 2025: California announces its first Delete Act fine over health condition lists
  • 10 February 2026: EDPB and EDPS adopt a joint opinion opposing the narrowing of Article 9
  • 26 March 2026: Federal judge approves the Google RTB settlement
  • 3 June 2026: Google clarifies sensitive category restrictions for Demand Gen and Discovery
  • 29 June 2026: Council adopts the AI half of the Digital Omnibus, leaving the GDPR half open

Summary

Who. European legislators defined the category; national supervisory authorities and the Court of Justice enforce and interpret it; publishers, demand-side platforms, exchanges, data brokers and advertisers are the parties whose systems keep touching it.

What. A closed list of eight kinds of personal information, set out in Article 9(1) of the GDPR, whose processing is prohibited unless one of ten conditions in Article 9(2) applies on top of an ordinary Article 6 lawful basis.

When. In EU law since Directive 95/46/EC, in current form since 25 May 2018, and under active revision through the Digital Omnibus proposal tabled on 19 November 2025.

Where. In content classification fields, page addresses and audience segments carried through bid requests, in advertiser-curated audience uploads, and in the platform policies that block both.

Why. The category is the one place in European data protection law where the starting point is prohibition rather than permission, and inference means an advertising system can enter it without any party choosing to.