Blog guideUpdated 2026-05-146 min readBy HubSecure Editorial TeamReviewed by workflow reviewers

Short summary

Certain types of personal data carry elevated risk of harm if mishandled — so GDPR imposes an additional layer of protection. Processing any special category data without the right basis is a direct violation, regardless of your Article 6 lawful basis.

  • What the compliance workflow needs to prove.
  • Which controls and evidence buyers should check.
  • How HubSecure fits without replacing legal advice.

Special Category Data Under GDPR: What It Is and How to Handle It

Certain types of personal data carry elevated risk of harm if mishandled — so GDPR imposes an additional layer of protection. Processing any special category data without the right basis is a direct violation, regardless of your Article 6 lawful basis.

Written byHubSecure Editorial Team

Practical guides for secure client portals, RBAC, onboarding and regulated client operations.

Reviewed byHubSecure Security & Compliance Review

Reviewed for security positioning, workflow accuracy and implementation clarity.

Last updatedMay 7, 2026

Checked against the current HubSecure marketing site and product positioning.

TL;DR

Special category data is personal data that relates to particularly sensitive aspects of an individual's life — aspects where misuse could cause serious harm including discrimination, violence, or significant financial or social damage. GDPR Article 9 establishes a default prohibition on processing special category data, with a closed list of exceptions.

Related HubSecure buying path

Compliance CRM guidecompliance CRM for growing companiesCRM moduleHubSpot comparisoncompliance CRM guideGuide Librarybook a workflow demo

Related security, privacy and governance resources

Continue with HubSecure security and trust center, data processing agreement, subprocessors, compliance workflows, governed AI operator.

Related use case

This guide belongs to the Workspace Alternatives and Tool Consolidation Guides cluster. Continue with the product hub for workspace alternatives and tool consolidation.

What counts as special category data

The following categories are defined in Article 9(1):

Criminal conviction and offence data is addressed separately under Article 10 and is subject to similar restrictions — processing is only permitted under official authority or as authorised by national law.

Note: The category is triggered by the nature of the information, not how you obtained it or what you intend to do with it. A client disclosure that incidentally reveals a health condition or religious affiliation means you now hold special category data — even if you did not seek it.

The Article 9 conditions for processing

Processing special category data requires one of the following conditions to be met (in addition to an Article 6 lawful basis):

Practical examples for regulated businesses

Law firms

Client matters involving personal injury, immigration, employment discrimination, or family law often involve health data, racial origin data, or data about sex life. Process under Article 9(2)(f) (legal claims) with explicit consent as a secondary basis where appropriate. Ensure matter files with special category data are subject to enhanced access controls.

Healthcare providers

Health data is the core of the business. The Article 9(2)(h) condition (medical purposes, professional secrecy) covers most clinical processing. Systems must enforce strict role-based access and comprehensive audit trails.

Employers

Processing employee health data for sickness absence, disability accommodations, or occupational health assessments typically relies on Article 9(2)(b) (employment law obligations). Do not routinely collect health information beyond what is required for specific employment purposes.

Additional requirements for special category data

If a client mentions their health condition in passing, do we hold special category data?

Yes, if it is recorded. A note in a CRM or file that references a client's health condition means your record now contains special category data. Review whether you need to retain that information for the matter or whether it can be removed. If retained, ensure the appropriate Article 9 condition applies.

Does criminal record data fall under Article 9?

Criminal conviction and offence data is covered by Article 10 rather than Article 9, but is subject to similar restrictions. Processing is only permitted under official authority or specifically authorised by national law. AML-related criminal record checks may be authorised under national AML legislation.

Field-level controls for sensitive data

HubSecure Vault supports enhanced access restrictions per field and record type — so sensitive client data is only visible to those with a legitimate need.

Book a demo

Reviewed for regulated teams

Prepared by the HubSecure editorial team for operators, compliance leaders and IT reviewers evaluating secure client operations software.

Authors · Reviewers · Editorial policy

Next useful pages

Continue the workflow evaluation

These links connect this page to the most relevant buyer, migration, template and signup paths.

secure client portalsecure document collectioncompliance crm for growing companiesmodules / sentinelguides
Canonical hubs

Source-of-truth pages for this topic

These hub pages tell buyers and search engines how this page fits into the wider HubSecure information architecture.

Recommended next step

Continue the evaluation path

The next page should move the buyer from information to comparison, workflow review, template use or private rollout readiness.