If your business holds information about someone’s health, religion, sexual orientation, trade union membership, or biometric details, you’re handling special category data. It sits under a stricter set of rules than ordinary personal data, and a lot of businesses don’t realise they’re collecting it until something goes wrong. A GP’s admin system, a law firm’s client files, an HR department tracking sick leave, all of these routinely touch special category data without anyone flagging it as a separate problem to solve.
What Counts As Special Category Data
The list is specific rather than a general “sensitive information” catch-all. It covers data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership. It also covers genetic data, biometric data used to identify someone, health data, and data about someone’s sex life or sexual orientation. Criminal offence data is handled separately but sits under a similarly tight regime.
What trips people up is how ordinary this data can look on the surface. A diversity monitoring form, a photo used for a staff ID badge that doubles as facial recognition, a note in a client file about a medical condition that affects scheduling. None of these feel dramatic, but all of them can fall into the special category bracket.
Why The Extra Protection Exists
Ordinary personal data, like someone’s name or email address, can cause harm if mishandled, but special category data can cause a different kind of harm. If it’s exposed or misused, it can lead to discrimination, exclusion, or danger to the person it belongs to. That’s the reasoning behind the tighter rules, and it’s worth holding onto because it explains why the bar for processing this data is set higher than for everything else.
The Two-Step Test You Need To Pass
Handling special category data lawfully means clearing two separate hurdles, not one. You need a lawful basis for processing personal data generally, and you need a separate condition specifically for the special category element. These two don’t have to match up or relate to each other, but you need both in place before you start, and you should write down which ones you’re relying on.
It’s worth reading the ICO’s guidance on the rules for special category data, which sets out the ten conditions available under Article 9, from explicit consent through to conditions tied to employment law or substantial public interest. Several of these conditions only apply if your processing also has a basis in UK law, set out in the Data Protection Act 2018, so it’s not enough to pick a condition that sounds close enough.
Where Legal And Professional Practices Get Caught Out
Law firms are a good example of a sector that handles special category data constantly without always treating it as a distinct compliance task. Case files might reference a client’s health or criminal history, and the criminal history sits under its own tight regime. Employment disputes often involve details about disability or religious belief. None of this is avoidable, it’s the nature of the work, but it does mean the firm needs a documented condition for processing, not just a general sense that client confidentiality covers it.
Protecting that data technically is a separate job, and our guide to cyber security standards for law firms covers that side. The technical controls matter, but so does knowing which files inside those systems carry the extra legal weight.
Building The Paperwork Around The Processing
For most of the Schedule 1 conditions, you also need something called an appropriate policy document in place before you process the data. Treat it as a working document that explains how you’ll comply with data protection principles and how long you’ll keep the information. If your processing is likely to be high risk, a data protection impact assessment is also required, which means thinking through the risks before you start rather than after a complaint lands.
In practice, the policy and documentation side often gets less attention than the technical side, even though a regulator will ask for both, which is where specialist cybersecurity support for legal practices tends to earn its keep.
When The Worst Happens
A breach involving special category data carries more weight than a breach involving names and addresses alone, both in terms of regulatory response and real harm to the people affected. Knowing in advance which systems hold this kind of data, and having a plan for how to respond if they’re compromised, makes a material difference to how quickly a business can contain the damage. Planning for that scenario is exactly what incident response support is built around, rather than trying to work it out for the first time during an actual breach.
If your business handles sensitive client or employee data and you’re not sure your incident response plan accounts for it, get in touch about incident response planning before you need it.