// THREAT DETECTION AND DATA PRIVACY TERM

Special Category Data

Special category data is a specific set of personal information that is considered more sensitive and therefore needs a higher level of protection under privacy laws like GDPR. This includes information about a person's race, political opinions, religious beliefs, health, sex life, or sexual orientation.

Special Category Data — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Special Category Data, as defined under Article 9 of the GDPR, is a classification of sensitive personal information whose processing is prohibited unless specific legal conditions, such as explicit consent or substantial public interest, are met. This category encompasses data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for unique identification, health data, and data concerning a person's sex life or sexual orientation.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • sensitive personal data
  • sensitive personal information (SPI)
  • Article 9 data
  • protected characteristics data
  • special categories of personal data

USAGE NOTE

Organizations must identify a specific, lawful basis separate from their standard data processing grounds to legally handle this type of information.

DEVELOPERS

Organizations developing technology related to Special Category Data.

  • BigID

    Develops a data intelligence platform that uses machine learning for automated discovery, classification, and governance of sensitive information, including special category data, to help organizations comply with privacy regulations like GDPR.

  • OneTrust

    Provides a widely used privacy, security, and governance platform that helps organizations manage user consent, automate data subject rights requests, and maintain compliance with regulations governing special category data.

  • Varonis

    Offers a data security platform specializing in the protection of sensitive data from insider threats and cyberattacks by mapping, analyzing, and controlling access to information, including special category data.

  • Privitar

    Specializes in Privacy-Enhancing Technologies (PETs), providing a software platform that de-identifies and protects sensitive datasets, including special category data, to enable safe data analysis and sharing while maintaining privacy.

  • Forcepoint

    A cybersecurity company that develops Data Loss Prevention (DLP) solutions designed to discover, classify, and protect special category data from accidental or malicious leakage across networks, endpoints, and the cloud.

  • Immuta

    Provides an automated data access and security platform that enables granular policy enforcement for sensitive data. The technology is used to secure special category data within cloud data platforms for analytics and AI workloads.

  • Enveil

    Develops Privacy-Enhancing Technologies powered by homomorphic encryption, allowing organizations to securely process and analyze encrypted special category data without ever exposing the content, protecting it even while in use.

  • Securiti.ai

    Offers an AI-powered platform for unified data controls across privacy, security, and governance. It automates the discovery of special category data and the fulfillment of data subject rights.

RELATED TERMS IN COMPLIANCE & PRIVACY