Skip to main content
Category: Consent Principles

Article 9 Conditions

Also known as: Article 9(2) conditions, special category data conditions, conditions for processing special category data
Simply put

Article 9 conditions are the specific exceptions under EU and UK data protection law that allow organisations to process especially sensitive personal data, which is otherwise generally prohibited. This sensitive data includes information such as health, biometric, or genetic data, and each condition sets out a particular situation in which processing is permitted. Meeting one of these conditions is separate from, and additional to, the general legal basis needed to process any personal data.

Formal definition

Under Article 9 of the GDPR (and the UK GDPR), the processing of special categories of personal data is subject to a general prohibition, with Article 9(2) providing an exhaustive list of conditions that lift that prohibition. Examples cited by the ICO include employment, social security and social protection (Article 9(2)(b)), health or social care (Article 9(2)(h)), and public health. An Article 9 condition does not replace the requirement for a separate Article 6 lawful basis; controllers processing special category data must generally satisfy both an Article 6 lawful basis and an Article 9 condition. Member States may maintain or introduce further conditions, including limitations, in relation to certain data such as genetic, biometric, and health data, so the precise scope and any additional requirements can vary by jurisdiction. This entry addresses the conditions at a general level; the specific supplementary safeguards, national derogations, and (in the UK) any associated conditions under domestic legislation are out of scope and should be verified against the applicable framework.

Why it matters

Special category data, information such as health, biometric, or genetic data, is subject to a general prohibition on processing under Article 9 of the GDPR and the UK GDPR precisely because misuse can cause serious harm to individuals. For organisations, the practical consequence is that handling this data is not permitted unless one of the specific conditions in Article 9(2) applies. Treating sensitive data as though it were ordinary personal data is a common compliance error, and getting this wrong can expose an organisation to regulatory scrutiny and enforcement action.

A point that is frequently misunderstood is that meeting an Article 9 condition does not, on its own, make processing lawful. Controllers must generally satisfy both a general Article 6 lawful basis and a separate Article 9 condition. Failing to identify both, or assuming that consent or contract necessity covers everything, leaves the processing without a complete legal foundation. This two-part requirement matters most at the point where organisations design a processing activity, because the appropriate condition must typically be identified before processing begins rather than reconstructed afterwards.

The conditions also matter because their scope can vary by jurisdiction. Member States, and the UK under its domestic framework, may maintain or introduce further conditions and limitations in relation to certain data such as genetic, biometric, and health data. As a result, satisfying Article 9(2) at the level of the Regulation may not be the end of the analysis; additional national safeguards or conditions may apply, and these need to be checked against the relevant framework rather than assumed.

Who it's relevant to

Data protection officers and privacy teams
DPOs and privacy professionals are typically responsible for confirming that any processing of health, biometric, genetic, or other special category data is supported by a valid Article 9(2) condition alongside an Article 6 lawful basis. They generally need to document which condition applies and check whether additional national safeguards are triggered.
Legal counsel and compliance functions
Legal and compliance teams advise on whether a chosen condition genuinely fits the processing and on how Member State or UK-specific derogations affect the analysis. Because the list of conditions is exhaustive and national requirements can vary, their role often involves verifying scope against the applicable framework rather than relying on a single condition in isolation.
Organisations processing sensitive data through web technologies
Where cookies, pixels, SDKs, or similar technologies may capture data that reveals special categories of information, those responsible for consent and data collection need to be aware that Article 9 imposes an additional layer of restriction. Whether a given tracking activity implicates special category data depends on the specific facts and should be assessed carefully, separately from the ePrivacy consent obligations that govern placing information on a device.

Inside Article 9 Conditions

Special Categories of Personal Data
Article 9 of the GDPR addresses processing of special categories of personal data, which includes data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and the processing of genetic data, biometric data for uniquely identifying a person, data concerning health, or data concerning a person's sex life or sexual orientation. Where cookies or similar technologies collect or infer such data, the heightened Article 9 conditions may apply in addition to the ordinary GDPR requirements.
General Prohibition and Exceptions
Article 9 sets out a general prohibition on processing special category data, subject to a limited set of exceptions or conditions listed in the Article. In a cookie context, the most commonly relevant exception is typically the data subject's explicit consent, though other exceptions exist that may or may not apply depending on the facts.
Explicit Consent Standard
Where explicit consent is relied on, it must meet the general GDPR standard of being freely given, specific, informed, and unambiguous through a clear affirmative action, and additionally reach the higher bar of being explicit. This is a distinct and more demanding standard than the consent that may otherwise suffice for ordinary personal data.
Interaction with the ePrivacy Rules
The ePrivacy Directive and its national implementations govern the placing of and access to information on a user's device, while Article 9 GDPR governs the processing of any special category personal data that follows. Consent for setting a cookie under ePrivacy does not automatically satisfy the Article 9 explicit consent condition, and both may need to be addressed separately.
Inference and Profiling Considerations
Special category data can arise not only from directly collected fields but also from inferences drawn through profiling, tracking pixels, SDKs, fingerprinting, or combined data sets. Whether inferred data triggers Article 9 can depend on the facts and remains an area of evolving regulatory interpretation.

Common questions

Answers to the questions practitioners most commonly ask about Article 9 Conditions.

Does the GDPR's Article 9 mostly concern cookies and tracking technologies?
No. Article 9 of the GDPR governs the processing of special categories of personal data (such as data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or sexual orientation) and is not a cookie-specific provision. The placing of and access to cookies is primarily governed by the ePrivacy Directive and its national implementations, while the GDPR governs any personal data processing that follows. Article 9 becomes relevant to cookies only where the data actually processed through a cookie or similar technology falls within a special category, which depends on the specific facts of the processing.
If I have valid consent to place a cookie, does that automatically satisfy Article 9?
Not necessarily. Consent to store or access information on a device under the ePrivacy rules addresses a different legal question from the lawful processing of special category data under Article 9. Where processing involves special categories of data, you generally need to identify an applicable Article 9 condition (for example, explicit consent under Article 9(2)(a)) in addition to a lawful basis under Article 6 and, where relevant, valid ePrivacy consent. These requirements should be assessed separately rather than assumed to be met by a single consent action.
How do we determine whether a cookie or tracking technology triggers Article 9 conditions?
The relevant question is whether the data actually processed reveals or infers information falling within a special category, not simply what the technology is called. This typically requires reviewing what data the cookie, pixel, SDK, or fingerprinting technique collects, how it is combined with other data, and whether any inferences about health, beliefs, or similar characteristics result. Because this is fact-specific and interpretations can vary between data protection authorities, a data mapping exercise and legal assessment are generally advisable rather than a technology-by-technology assumption.
Which Article 9 condition is most commonly relied on in an online, consent-driven context?
In many online contexts involving special category data, organisations rely on explicit consent under Article 9(2)(a), which imposes a higher standard than ordinary GDPR consent and typically calls for a clear, specific statement of agreement to the processing of that special category data. Other conditions may apply depending on the circumstances, but they are often narrower and context-dependent. Whether any given condition is available depends on the facts, and this definition does not determine which condition applies to a particular processing activity.
What should we record to demonstrate a valid Article 9 condition for tracking that involves special category data?
As a general matter of accountability, organisations typically maintain records showing which Article 9 condition was relied on, the corresponding Article 6 lawful basis, and, where explicit consent is used, evidence of what the user was told and how their affirmative agreement was captured. Consent management platforms and consent logs can support this record-keeping, but they support rather than guarantee compliance and do not replace a legal assessment of whether the condition is genuinely met. Specific retention and record-keeping expectations may vary by jurisdiction and regulator guidance.
Does Article 9 apply the same way outside the EU, for example under US state privacy laws?
No. Article 9 is a provision of the EU GDPR and, in materially similar form, the UK GDPR. US state privacy frameworks such as the CCPA and CPRA in California use their own concepts of sensitive personal information with different definitions, obligations, and often an opt-out rather than opt-in model. You should not assume that meeting Article 9 conditions satisfies obligations in other jurisdictions, or vice versa, and cross-border processing may need to address multiple regimes separately.

Common misconceptions

Obtaining cookie consent under the ePrivacy rules automatically satisfies Article 9.
Consent to place or access information on a device under the ePrivacy Directive is a separate matter from the Article 9 GDPR condition of explicit consent for processing special category data. Satisfying one does not automatically satisfy the other, and both may need to be addressed where special category data is involved.
Ordinary cookie consent is sufficient when tracking technologies handle sensitive data.
Where processing falls within Article 9, the applicable consent must generally be explicit, which is a higher standard than the consent that may suffice for ordinary personal data. Standard consent mechanisms may not meet this bar.
Article 9 only applies to data a user directly and knowingly provides.
Special category data may also arise through inference or profiling from tracking technologies such as pixels, SDKs, or fingerprinting. Whether such inferred data triggers Article 9 can depend on the specific facts and is an area subject to evolving interpretation.

Best practices

Map whether any cookies, pixels, SDKs, or similar technologies collect or could infer special category data, and treat those flows as potentially subject to Article 9 conditions in addition to ordinary GDPR and ePrivacy requirements.
Where an Article 9 condition such as explicit consent is relied on, design consent mechanisms to meet the higher explicit standard rather than assuming standard cookie consent is sufficient.
Address the ePrivacy and GDPR obligations separately, obtaining valid consent for placing or accessing information on the device as well as any explicit consent needed for processing special category data.
Document the legal analysis and the specific Article 9 exception being relied on, and maintain consent records that reflect the explicit nature of any consent obtained.
Seek qualified legal advice for processing that may involve inferred or profiled special category data, given that whether Article 9 applies can depend on the facts and remains an area of evolving regulatory interpretation.
Confirm the geographic and legal scope of your processing, since Article 9 is a GDPR concept and obligations may differ under the UK regime, US state privacy laws, or other frameworks.