Personal Data vs Sensitive Data – What’s the Difference?
9th October 2024
Personal data and sensitive data might sound like they refer to the same thing, but there are several important distinctions between the two that you should be aware of. All personal data should be protected and processed according to the UK GDPR and other data protection laws, but sensitive data, aka special category of data, has more rules regarding its collection and processing.
What is Personal Data?
According to the GDPR, personal data is defined as any information relating to an identified or identifiable natural person. The UK Data Protection Act specifies that personal data refers to that of living individuals. So basically, any piece of information that can be used to identify an individual.
The definition of personal data is extremely wide, and ranges from names, email addresses, phone numbers, ID numbers, and IP addresses, to less clearly defined elements such as property address, car number plate, photographs, CCTV, voice recordings, nicknames, descriptions and digital fingerprints (a combination of information about a user’s browser and device to build a unique digital identifier).
Bottom line, if you can follow a breadcrumb trail to a specific individual, or even a small group of individuals, the information will be considered ‘personal data’.
What is Sensitive Data?
Sensitive data, technically referred to in data protection legislation as special category data, are characteristics or behaviours which are known about an identified or identifiable person.
According to Article 9 of the UK GDPR, special category data is information that reveals a person’s race or ethnic origins, political beliefs, religious beliefs, trade union membership, health, sex life, sexual orientation, genetic data and biometric data (which when processed could uniquely identify someone).
The UK Data Protection Act 2018 added another category to the list of special category elements: any information relating to actual or alleged criminal offences, records and convictions. While separate rules apply to criminal convictions, from a layperson’s perspective, and criminal records are absent from UK GDPR Article 9, they should be treated as special category data and subject to tighter controls.
Most special category data is considered sensitive because it could potentially cause harm or discrimination to an individual if it is disclosed intentionally, by accident, or accessed unlawfully, e.g. as part of a data breach.
The Difference Between Personal Data and Sensitive Data
All types of personal data, whether sensitive or not, are protected by the UK GDPR and other data protection laws. Organisations must have a lawful basis for processing personal data and follow the principles of data protection. Special category data however is subject to more stringent rules, and processing of sensitive data can only be done if a second condition is also met as per Article 9 of the UK GDPR or under Schedule 1 of the Data Protection Act 2018.
Rules for Processing Sensitive Data
The conditions for processing special category data under Article 9 are:
a) Explicit consent – i.e. the individual has given explicit rather than implicit or implied consent to process their sensitive information.
b) The processing is necessary for employment, social security and social protection laws.
c) You are protecting the vital interests of the data subject or another natural person where they are incapable of giving consent, e.g. in a life-or-death medical emergency.
d) The processing is carried out in the course of the legitimate activities by a not-for-profit body that has appropriate safeguards in place, for example, the British Heart Foundation will process medical data for their members to help support them.
e) The data is made public by the data subject, e.g. someone who has publicly discussed their health condition. That said, just because information has been made public does not automatically mean you can capture this, you still need to follow Principles 2 and 3, i.e. that of purpose limitation and data minimisation.
f) Legal claims and judicial acts, where data is processed to establish, exercise or defend legal claims or a court of law is acting in its judicial capacity.
g) Substantial public interest, the criteria of which are set out in Section 10(3) of the Data Protection Act 2018.
h.) Health or social care including medical diagnosis, treatment and the provision of social care, further details are included in Schedule 1, condition 2 of the DPA 2018.
i) Public health, when the processing is “necessary for reasons of public interest in the area of public health, such as protecting against serious cross-border threats to health or ensuring high standards of quality and safety of health care and of medicinal products or medical devices” – Article 9(2)(i) UK GDPR
This processing must be carried out by a health professional or by someone who owes a legal duty of confidentiality.
j) Archiving, research and statistics, when it can be demonstrated that the processing is in the public interest, and is a reasonable and proportionate way of achieving these goals. Anonymised or pseudonymised data should be used wherever possible and this research must not be used to make decisions on specific individuals, or in a way that would cause them any detriment.
Organisations that are relying on conditions b, h, i or j should also meet the conditions set out in Part 1 of Schedule 1 of the DPA 2018.
An appropriate policy document (APD) may be required for processing special category data or criminal offence data under the DPA 2018. This document should show which conditions have been fulfilled to ensure the processing of the data is compliant with the law. A template APD is available from the ICO website. You must also perform a Data Processing Impact Assessment (DPIA) before processing any data that may pose a high risk to individuals. If you are or are considering processing special category data, then by its very nature it will always be considered high-risk processing. See more on DPIAs on the ICO website.
Fulfilling Your Lawful Responsibilities When Processing Sensitive Data
To summarise, organisations should avoid collecting and processing any special category data unless they can identify a lawful basis for doing so, and at least one condition from Article 9 of the UK GDPR or Schedule 1 of the DPA 2018 is fulfilled. They should also complete an appropriate policy document and a DPIA – for more guidance on special category data processing, get in touch with us here at Griffin House Consultancy for expert advice.
Author: Mike Martin LLM
Mike is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.