Phoenix PDP essentials #5
Today’s focus: sensitive data, can we really collect it freely?
Certain types of personal data benefit from enhanced protection. Their processing is not prohibited in principle, but it remains strictly regulated.
1️⃣ What is sensitive data?
These are special categories of personal data whose use may adversely affect individuals’ rights and freedoms or lead to discrimination:
👉 Racial or ethnic origin
👉 Political opinions
👉 Religious or philosophical beliefs
👉 Trade union membership
👉 Genetic, biometric or health data
👉 Data concerning a person’s sex life
2️⃣ The principle
The processing of sensitive data is prohibited in principle. It is only permitted in the specific cases provided for by law.
3️⃣ Processing may notably be permitted when:
👉 the data subject has given their explicit consent
👉 the data has been manifestly made public by the data subject
👉 it is necessary to protect the vital interests of a person who is physically or legally incapable of giving consent
👉 it is necessary for healthcare purposes (preventive medicine, occupational medicine, healthcare, medical diagnosis, management of healthcare systems, public health)
👉 it is necessary for the establishment, exercise or defence of legal claims
👉 it is necessary for employment, social security or social protection purposes
👉 it is justified by an important public interest
👉 it is carried out by certain institutions as part of their activities (religious, philosophical, political, humanitarian or trade union organisations)
👉 it is carried out for scientific or historical research purposes, statistical purposes or archiving purposes in the public interest
👉 it concerns biometric data where its use is strictly necessary for access controls implemented by the employer
👉 it is carried out by certain competent organisations or authorities (IMSEE, administrative and judicial authorities) as part of their statutory duties.
4️⃣ Key point to keep in mind
The processing of sensitive data should never become an automatic practice.
The data controller must always be able to demonstrate:
👉 the necessity of the processing
👉 its proportionality
👉 the implementation of enhanced confidentiality and security measures
When it comes to sensitive data, the principle is therefore not to collect it simply because it is possible, but only when it is necessary and legally justified.
In practice, such processing requires particular attention in the records of processing activities and in risk assessments.




