More data sets are being interpreted as ‘Special Category’
31st August 2022
Allow us to explain why more data sets are being interpreted as ‘Special Category’.
Firstly, we should say that this is a ruling where language such as ‘indirect’, ‘implication’ and ‘deduction’ abound. In other words, it is not clear cut. However, it is very significant.
What is Special Category Data?
The GDPR defines Special Category data is the type of data that is considered sensitive and therefore requires more protection. It includes:
- personal data revealing racial or ethnic origin;
- personal data revealing political opinions;
- personal data revealing religious or philosophical beliefs;
- personal data revealing trade union membership;
- genetic data;
- biometric data(where used for identification purposes);
- data concerning health;
- data concerning a person’s sex life; and
- data concerning a person’s sexual orientation.
And in addition, within the UK Data Protection Act, we also include any actual or alleged criminal behaviour, activity, or records.
What did the European Court of Justice (CJEU) rule?
It wasn’t as simple as the European Court simply interpreting more data sets as ‘Special Category’.
The ruling was based on a scenario that happened in Lithuania where public officials must reveal the name of their spouses as part of anti-corruption legislation. These names are then published online, alongside the name of the public official. These records are made publicly available.
The dispute ended up in Court because of the conflict between the Lithuanian law protecting the public interest and the GDPR protecting the processing of personal data that falls under the definition of ‘special category’.
The case centred around the issue that by naming a spouse potentially enables a person to deduce the sexuality of the individual.
The reason for the conflict is that an applicant to public office in Lithuania failed to file a declaration and the individual was sanctioned.
This case is so significant not because of the sanctioning of the individual and the referral to the CJEU, but because of the implied far-reaching consequences that can be inferred from the decision that significantly expands the scope of the Special Category data legislation.
The CJEU judgement stated that the processing of any data that is “liable indirectly (emphasis added) to reveal sensitive information concerning a natural person, is subject to the prohibition from processing under Article 9(1) GDPR, unless an exception under Article 9(2) applies”
What does indirectly mean?
This is a key question, and the Judgement doesn’t make it clear. However, it raises many practical considerations. For example, cookies on a health-related website, CCTV from a Church, donations to certain charities – do these allow people to make deductions that indirectly reveal sensitive information? What could be inferred? and it could it be considered sensitive?
Are you processing any kind of data that could be open to interpretation in a ‘sensitive context’? If so, you should keep abreast of this issue, because under the GDPR there are only a few very specific ways that you can legally process Sensitive Category data without explicit consent.
Balancing the rights of the individual with the rights of a business
As with so much data governance legislation, there are two sides to the coin. Privacy on the one side with commerce on the other.
Businesses find themselves having to be mindful of red tape and who have for a long time been able to use data freely – now have had their wings cut right back. Or to put it more strongly:-
“The ruling is another blow to companies whose business models rely on large data troves, even if they don’t primarily make money off sensitive data. You have this ecosystem where everything has been about collecting as much data as possible. Now we see if you have a lot of data, it’s turning into a massive liability.”
Tobias Judin, Norwegian Data Protection Authority as quoted in the Wall Street Journal.
It is more important than ever, that as a business you are aware of exactly what data you process and how. If you have large data sets, think about whether anything contained within them could infer anything that directly or INDIRECTLY contains sensitive information.
If you are unsure and would like some advice, or if you feel your organisation would benefit from a data audit, please do get in touch with the data protection specialists here at the Griffin House Consultancy, we are here to help.
Take the first step towards peace of mind and book your complimentary consultation today.