With the final approval of the EU-U.S. Data Privacy Framework, data can once again flow across the Atlantic. Learn more about the new rules at TrueVault.
GDPR restricts how special categories of personal data can be processed. The core principles for data processing as defined by Article 6 still apply, but there are stricter rules of processing special categories of personal data, and additional grounds for processing must be met in order for processing to be lawful.
Article 9.1: There are strict rules for processing special categories of personal data, these categories include:
Article 9.2: At least one of these grounds for processing must be met in order for the above categories of special data to be processed lawfully.
Specific EU or national laws can also be grounds for lawful processing.
There is considerable overlap between the standard six grounds for processing (Article 6) and the grounds for processing special categories of personal data.
If the data subject gives explicit consent for processing and/or if the data subject cannot offer consent but processing is in his/her vital interests, then processing is lawful. Processing is also lawful in most cases of legal obligations and/or with official authority, but neither the performance of a contract nor the organization’s legitimate interests are sufficient grounds for lawful processing of these special categories of data.
Disclaimer: This content is provided for general informational purposes only and does not constitute legal or other professional advice. Without limiting the foregoing, the content may not reflect recent developments in the law, may not be complete, and may not be accurate or relevant in an applicable jurisdiction. This content is not a substitute for obtaining legal advice from a qualified licensed attorney in the applicable jurisdiction. The content is general in nature and may not pertain to specific circumstances, so it should not be used to act or refrain from acting based on it without first obtaining advice from professional counsel qualified in the applicable subject matter and jurisdictions.
Get monthly updates on the latest updates on policy & the shifting privacy landscape.
Dive into a world of knowledge, trends, and industry updates on the TrueVault blog.