Frameworks / GDPR / GDPR-Art.9 GDPR
Chapter II - Principles
GDPR GDPR-Art.9: Processing of special categories of personal data Do not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orientation, unless one of the Article 9(2) conditions applies: explicit consent, employment and social security law obligations, vital interests where the data subject cannot consent, the legitimate activities of a not-for-profit body, data manifestly made public by the data subject, legal claims or courts acting judicially, substantial public interest under Union or Member State law, preventive or occupational medicine and health or social care under an obligation of professional secrecy, public health, or archiving, research and statistics under Article 89(1). The condition applies in addition to an Article 6 lawful basis, never in place of it.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 19 August 2026 What else in your programme already covers this This control maps to 361 controls across 140 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
22 Art. 22 Process special categories only under an exception of the GDPR or the UAVG 23 Art. 23 Rely on the national general exceptions for special categories only in their cases 24 Art. 24 Meet all four conditions before processing special categories for research or statistics 25 Art. 25 Process data revealing racial or ethnic origin only for identification or preferential-treatment policies, within limits 26 Art. 26 Process data revealing political opinions only for requirements of public-body functions 27 Art. 27 Process religious or philosophical data for spiritual care only absent written objection, and do not disclose it 28 Art. 28 Process genetic data only about the person it was obtained from, or on the strict research or medical grounds 29 Art. 29 Use biometric identification (fingerprint or face) only where necessary for authentication or security for a weighty public-interest access need 30(1) Art. 30(1) Process employee health data only as necessary for statutory, pension or collective-agreement entitlements or for reintegration 30(2) Art. 30(2) Process health data in schools, probation, child protection and custody only as necessary for their tasks 30(3) Art. 30(3) Process health data in care and insurance only as necessary for treatment, management, risk assessment or policy administration 30(4) Art. 30(4) Ensure health data are processed only by persons bound to confidentiality 30b Art. 30b Transfer medical records held by non-care providers only to a care provider that will keep them s22 s 22 Process special categories only on a listed national ground and with specific safeguards s26-3 s 26(3) Process employees' special category data only for labour and social law duties, or on explicit consent s27 s 27 Research and statistics: balance interests, safeguard, anonymise early and separate identifiers s28 s 28 Archiving in the public interest: safeguard special categories and record counter-statements s48 s 48 Process special categories only where strictly necessary and with safeguards NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-7 Data Protection Assessments and Processor Contracts NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-7 Cross-Border Data Transfers and International Cooperation APPI-A20 Proper Acquisition and Special Care Required Personal Information APPI-A23 Security Control Measures APPI-A24 Supervision of Employees APPI-A33 Request for Disclosure of Retained Personal Data 5(a) 5(a) Special categories: an Article 9 exception plus an Article 6 basis, never 'manifestly made public' 5(c) 5(c) An employer must not use footage of a demonstration to identify strikers 5.1(a) 5.1(a) Biometrics: assess first, and know when Article 9 applies 5.1(b) 5.1(b) Biometrics: never capture people who have not consented; separate entrances and user-triggered capture UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7) SOC2-P3.1 P3.1 Collecting personal information consistent with objectives SOC2-P3.2 P3.2 Explicit consent before collecting information that requires it SOC2-P4.3 P4.3 Securely disposing of personal information SOC2-P6.1 P6.1 Disclosure to third parties with consent TANZANIA-1 Scope, Registration, Lawful Basis TANZANIA-3 Data Subject Rights TANZANIA-4 Security and Cross-Border TANZANIA-5 DPO, Governance, Breach TRINIDAD-1 Scope, Definitions, Commission TRINIDAD-3 Data Subject Rights TRINIDAD-4 Security, Accuracy TRINIDAD-5 Enforcement and Sanctions Standard 13 Nudge Techniques Standard 14 Connected Toys and Devices Standard 5 Detrimental Use of Data Standard 8 Data Minimisation MYHR-CUD-1 Authorised collection, use and disclosure only MYHR-CUD-3 Use limited to My Health Record purposes MYHR-CUD-6 Prohibition on use for a prohibited purpose APP-1 APP 1 - Open and transparent management of personal information APP-3 APP 3 - Collection of solicited personal information APP-5 APP 5 - Notification of the collection of personal information AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement) AT-DSG-13 Section 36 - Scope of law enforcement processing AT-DSG-14 Section 38 - Lawfulness of law enforcement processing AZ-DPA-12 Article 13 - Cross-border transfer AZ-DPA-14 Article 16 - Liability for violations AZ-DPA-15 Article 17 - Dispute resolution BB-DPA-14 Section 15 - Right to Data Portability BB-DPA-16 Section 22 - General Principle for Transfers BB-DPA-21 Sections 61-69 - Data Privacy Officer BW-DPA-s20 Prohibition for processing of sensitive personal data BW-DPA-s21 Safeguards for processing sensitive personal data BW-DPA-s25 Processing of genetic and biometric data PIPL-Art28 Sensitive PI Definition and Threshold PIPL-Art29 Separate Consent for Sensitive PI PIPL-Art32 Sectoral and Administrative Restrictions IVDR-Art.102_103_104 Confidentiality, data protection and Medical Device Coordination Group cooperation (Articles 102-104) IVDR-Art.4 Genetic information, counselling and informed consent for genetic tests (Article 4) IVDR-Art.59_60_61_62 Informed consent + protection of subjects + emergency situations (Articles 59-62) EPDPA-1 Scope of Regulation (§1) EST-IKS-§14-21 Principles of processing by law enforcement authorities EST-IKS-§6 Processing for scientific and historical research and official statistics 29100-6.10 Information security 29100-6.5 Use, retention and disclosure limitation 29100-6.9 Accountability 29134-1 Scope 29134-3 Terms and definitions 29134-9.1 PIA report structure IsraelPPL-CrossBorder-Transfer-Sec36-EU-Adequacy-Israel-Adequacy-SCCs-Reciprocity-Foreign-Recipient Israel POPL Cross-Border Transfer + Section 36 + Privacy Protection (Transfer of Data to Databases Abroad) Regulations 5761-2001 + EU Adequacy Decision (2011) + SCCs + Foreign Recipient Obligations + Reciprocity IsraelPPL-DataSubjectRights-Access-Correction-Information-Delivery-Sec13-14-23A-23C-Subject-Notification Israel POPL Data Subject Rights - Section 13 Right of Access + Section 14 Right of Correction + Section 23A-C Prohibition on Information Delivery + Notice Obligation + Right to Object + Amendment 13 Enhancements IsraelPPL-Database-Registration-Definition-Document-Security-Level-Classification-Sec7-8-PPA-Registry Israel POPL Database Registration + Section 7 Database Definitions + Section 8 Registration Requirement + Database Definition Document + Security Level Classification + PPA Public Registry + Amendment 13 Threshold Changes Art. 2-septies(1) Art. 2-septies(1) Process genetic, biometric and health data only under an art. 9(2) condition and the Garante's safeguard measures Art. 2-septies(8) Art. 2-septies(8) Never disseminate genetic, biometric or health data Art. 2-sexies Art. 2-sexies Process special categories for substantial public interest only where law specifies the safeguards MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Data-Subject-Rights-Access-Correction-Portability-Withdraw-Consent-Prevent-Marketing-Sections-30-43 Malaysia PDPA Subject Rights + Access + Correction + Portability + Withdraw Consent + Prevent Marketing + Sections 30 to 43 MY-PDPA-Seven-Personal-Data-Protection-Principles-General-Notice-Choice-Disclosure-Security-Retention-Data-Integrity-Access Malaysia PDPA Seven Principles + General + Notice and Choice + Disclosure + Security + Retention + Data Integrity + Access NISTSP122-4 PII Minimisation, Purpose Limitation, and Pseudonymisation NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-6 PII Breach Response and Incident Handling NHPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NGOB-1 Open Banking Registry Participation, Tiered Categorisation, and KYP NGOB-2 Customer Consent Management and Lifecycle NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs SASB-4 Social Capital (SC) SASB-SC-1 Customer Privacy and Data Security SASB-SOC-2 Customer Privacy SA-PDPL-13 Encryption of personal data SA-PDPL-15 Access control for personal data SA-PDPL-22 Privacy by design and default ISMSP-PI-01 Personal Information Collection ISMSP-PI-04 Cross-Border Transfer ISMSP-SYS-02 Encryption Implementation SWE-1 Scope and Purpose SWE-11 Integritetsskyddsmyndigheten (IMY) SWE-2 Relationship to GDPR UK-DPA18-GEN-04 UK-Specific Exemptions UK-DPA18-LE-02 Data Subject Rights (Law Enforcement) UK-DPA18-LE-03 International Transfers (Law Enforcement) AL-DPA-12 International Data Transfers AL-DPA-4 Sensitive Data 5.4.4 5.4.4 Wearables: health and activity data stay with the employee 5.6 5.6 Video monitoring: no video analytics of expressions or movements, no facial recognition BE-DPA-5 Processing of special categories for substantial public interest BE-DPA-6 Genetic, biometric and health data safeguards ACC-1 ACC-1 Do not use biometric or photo-taking time clocks to control working hours ACC-8 ACC-8 Use biometric access control only as a subsidiary measure, justified, with the template held on an individual medium MDR-Art.109_110_111_112_113_115 Confidentiality, data protection, funding, civil liability and penalties (Articles 109-115) MDR-Art.61_62 Clinical evaluation and clinical investigations general requirements (Articles 61-62) EGY-PDPL-Art.12 Processing of sensitive personal data and children's data EGY-PDPL-Art.41 Penalty for unlawful sensitive-data processing FDBR-ControllerObligations-DPA-Notice Controller + Processor Obligations + Data Protection Assessments (Fla. Stat. 501.707, 501.708, 501.71, 501.711) FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704) 6.5 6.5 No data on sex life, beliefs or convictions, save exceptionally 6.7 6.7 Medical data only as needed and lawful 6.5.2 Information classification 7.2.2 Identify lawful basis 27400-5.4 Data and privacy risks 27400-7.3 Data minimization and purpose limitation 27557-3 Terms and definitions 27557-4.3 Individual impact consideration Art. 5 Art. 5 Do not check workers' health or sickness directly Art. 8 Art. 8 Do not investigate workers' opinions or facts irrelevant to their professional aptitude MU-DPA-Data-Subject-Rights-Sections-26-33-Access-Rectification-Erasure-Restriction-Portability-Objection Mauritius DPA Subject Rights + Sections 26 to 33 + Access + Rectification + Erasure + Restriction + Portability + Objection MU-DPA-Seven-Principles-Section-21-Lawfulness-Purpose-Minimisation-Accuracy-Storage-Integrity-Accountability Mauritius DPA Seven Principles + Section 21 + Lawfulness + Purpose + Minimisation + Accuracy + Storage + Integrity + Accountability MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent MN-CDPA-Enforcement-AG-Ellison-Section-325O-10-USD-7500-Per-Violation-Data-Broker-Registration-325O-13-Sunset-25-Jan-2026 Minnesota CDPA Enforcement + AG Ellison + Section 325O.10 + USD 7,500 Per Violation + Data Broker Registration + Sunset 25 January 2026 MN-CDPA-Processor-Contract-Security-Section-325O-08-Pseudonymisation-Section-325O-09-De-Identification Minnesota CDPA Processor + Section 325O.08 + Security + Pseudonymisation + Section 325O.09 + De-Identification MT-CDPA-Privacy-Notice-MCA-30-14-2806-Categories-Purposes-Rights-Email-Online-Mechanism-Appeal Montana CDPA Privacy Notice + MCA 30-14-2806 + Categories + Purposes + Rights + Online Mechanism + Appeal MT-CDPA-Scope-SB-384-Gianforte-19-May-2023-Effective-1-October-2024-MCA-30-14-2801-AG-Knudsen-50K-Threshold Montana CDPA Scope + SB 384 + Gianforte 19 May 2023 + Effective 1 October 2024 + MCA 30-14-2801 + AG Knudsen + 50K Threshold NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information NIST800-PT-7 PT-7 Specific Categories of Personally Identifiable Information NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs PDPASG-2 Notification, Consent, Purpose Limitation, and Lawful Basis PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-5 Security Measures and Data Protection PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement POPIASA-3 Data Subject Rights (Access, Correction, Objection), Automated Decisions POPIASA-4 Special Personal Information, Children, Information Quality, Documentation NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement PERU-2 Consent, Privacy Notice, Sensitive Data PERU-5 Security of Personal Data and Processor Agreements NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design QATAR-3 Data Subject Rights QATAR-7 DPO, Records, Retention, Marketing, Training RO-LAW190-001 Lawful Basis for Processing Genetic, Biometric and Health Data RO-LAW190-003 Processing of Personal Data by Political Parties and Non Profits SSAE18-P1.1 P1.1 - Privacy Notice SSAE18-P1.2 P1.2 - Choice and Consent TAIWAN-2 Consent, Notice, Sensitive Data TAIWAN-3 Data Subject Rights UKGDPRREG-2 Data Subject Rights (Articles 12-22) UKGDPRREG-3 Controller and Processor (Articles 24-43) UGA-13 Unlawful Obtaining or Disclosure UGA-15 Unauthorized Sale of Data URUGUAY-1 Scope, Lawful Basis, Consent URUGUAY-5 Database Registration with AGESIC URCDP UZB-DPL-08 Sensitive Categories of Personal Data UZB-DPL-09 Biometric Data Protection AUCDR-PS-9 Privacy Safeguard 9 - Adoption or disclosure of government related identifiers DS-2 Ensure software supply chain security BA-DPA-9 Processing of Special Categories of Personal Data §1798.121 Right to Limit Use and Disclosure of Sensitive Personal Information CA-10 Selects and Develops Control Activities CR-8968-Art.9 Categorias particulares de los datos (datos sensibles) DK-502-§7 Sensitive and special categories of data RDCOC-LAW-01 Lawful Basis for Research DGA-Art.5_6 Conditions for re-use and fees (Articles 5-6) PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) IEEE7000-Values-Elicitation-Prioritisation-IEEE7000Family-Bias-Privacy-Transparency IEEE 7000 Clauses 6 + 6.1 - Ethical Values Elicitation + Prioritisation + IEEE 7000 Family Integration (Bias + Privacy + Transparency + Wellbeing) ISO23894-A.5 Privacy and Data Protection in AI INCDPA-Controller-PrivacyNotice-PurposeLimitation-DataMinimisation-Transparency-LawfulBasis Indiana CDPA Controller Obligations - Privacy Notice + Purpose Limitation + Data Minimisation + Transparency + Lawful Basis + Reasonable + Adequate + Relevant + Limited to What is Necessary JP-AIG-Data-Governance-Training-Data-Quality-Provenance-Lineage-Copyright-APPI-Personal-Information-Protection Japan AI Guidelines Data Governance + Training Data Quality + Provenance + Lineage + Copyright Act 2018 Article 30-4 Text Data Mining Exception + APPI 2022 Amendment + Personal Information Protection + Privacy Principle LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response NAIC-6 Cybersecurity Event Investigation and Notification - Sections 6 and 7 NISTAI600-7 Confabulation, Bias, Information Integrity, Privacy, IP (Risks 2, 4, 5, 6, 7, 8, 10, 11) NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NGNDPR-2 Governing Principles, Lawful Basis, and Consent under NDPR Section 2.1-2.3 AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OWASPLLM-3 Sensitive Information Disclosure and Privacy (LLM02) OMANCS-4 Data Protection, Cryptography, and Privacy Alignment RCEPEC-1 Online Personal Information Protection (12.13) RIDTPPA-11 Data Minimisation and Purpose Limitation SOC-CY-DC2 Nature of Sensitive Information SAPAIA-4 Information Regulator Cooperation and Appeals PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37 STUDPRV-2 Data Subject Rights for Students and Parents TISAXASS-3 Prototype Protection and Confidentiality 503.001(b)(2) 503.001(b)(2) Obtain the individual's consent before capture TEXASTDPSA-3 Sensitive Data, Children, Sale Notice TURKEYKVKK-2 Information Notice and Data Subject Rights UKAI-2 Sector-Specific Regulator Engagement OB-CX.2 Granular Consent Management UNICEFAI-4 Transparency, Explanation, Adult Capacity VIETNAMPDP-1 Scope, Categorisation, Lawful Basis VIRGINIAVCDPA-1 Scope, Applicability, Definitions SO3.2 Regulatory frameworks for digital health ZDPA-04 Sensitive Information Processing Safeguards Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Chapter II - Principles You are reading one control. How much of GDPR have you already done? GDPR GDPR-Art.9 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.
Query this from an agent The graph holds this control, the 361 it maps to, and the evidence behind each claim, over MCP and REST.