Article 9 Conditions
Article 9 conditions are the specific exceptions under EU and UK data protection law that allow organisations to process especially sensitive personal data, which is otherwise generally prohibited. This sensitive data includes information such as health, biometric, or genetic data, and each condition sets out a particular situation in which processing is permitted. Meeting one of these conditions is separate from, and additional to, the general legal basis needed to process any personal data.
Under Article 9 of the GDPR (and the UK GDPR), the processing of special categories of personal data is subject to a general prohibition, with Article 9(2) providing an exhaustive list of conditions that lift that prohibition. Examples cited by the ICO include employment, social security and social protection (Article 9(2)(b)), health or social care (Article 9(2)(h)), and public health. An Article 9 condition does not replace the requirement for a separate Article 6 lawful basis; controllers processing special category data must generally satisfy both an Article 6 lawful basis and an Article 9 condition. Member States may maintain or introduce further conditions, including limitations, in relation to certain data such as genetic, biometric, and health data, so the precise scope and any additional requirements can vary by jurisdiction. This entry addresses the conditions at a general level; the specific supplementary safeguards, national derogations, and (in the UK) any associated conditions under domestic legislation are out of scope and should be verified against the applicable framework.
Why it matters
Special category data, information such as health, biometric, or genetic data, is subject to a general prohibition on processing under Article 9 of the GDPR and the UK GDPR precisely because misuse can cause serious harm to individuals. For organisations, the practical consequence is that handling this data is not permitted unless one of the specific conditions in Article 9(2) applies. Treating sensitive data as though it were ordinary personal data is a common compliance error, and getting this wrong can expose an organisation to regulatory scrutiny and enforcement action.
A point that is frequently misunderstood is that meeting an Article 9 condition does not, on its own, make processing lawful. Controllers must generally satisfy both a general Article 6 lawful basis and a separate Article 9 condition. Failing to identify both, or assuming that consent or contract necessity covers everything, leaves the processing without a complete legal foundation. This two-part requirement matters most at the point where organisations design a processing activity, because the appropriate condition must typically be identified before processing begins rather than reconstructed afterwards.
The conditions also matter because their scope can vary by jurisdiction. Member States, and the UK under its domestic framework, may maintain or introduce further conditions and limitations in relation to certain data such as genetic, biometric, and health data. As a result, satisfying Article 9(2) at the level of the Regulation may not be the end of the analysis; additional national safeguards or conditions may apply, and these need to be checked against the relevant framework rather than assumed.
Who it's relevant to
Inside Article 9 Conditions
Common questions
Answers to the questions practitioners most commonly ask about Article 9 Conditions.