Privacy Principles

What is Sensitive Personal Information?

Sensitive personal information is the class of personal data that laws single out for stronger protection — such as health, biometric, precise geolocation, racial or ethnic origin, religious beliefs, and sexual orientation data — typically requiring opt-in consent or offering a right to limit its use.

Every major privacy law draws a line around data whose misuse cuts deepest. GDPR Article 9 calls them 'special categories' and prohibits processing them outright except under enumerated conditions (explicit consent chief among them): racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, and data concerning sex life or sexual orientation.

US state laws draw the line differently but firmly. The CPRA's 'sensitive personal information' adds government identifiers, account credentials, precise geolocation, and message contents to the familiar categories, and grants a right to limit use rather than requiring consent. Virginia, Colorado, Connecticut, and most other state laws go further than California, requiring opt-in consent before processing sensitive data — and Washington's My Health My Data Act builds an entire statute around one sensitive category, consumer health data, with a private right of action attached.

The trap is that sensitivity is contextual and inferential. Data need not be a diagnosis to be health data: purchase history (prenatal vitamins, glucose monitors), search terms, and app usage support health inferences that regulators and MHMD expressly treat as sensitive. Precise geolocation becomes sensitive because of what places reveal — clinics, places of worship, protests. Enforcement has focused on exactly these flows: pixels on health-related pages, location data sold to brokers, advertising categories built on inferred conditions.

Operationally, sensitive data demands a separate track: identify where it can arise (including by inference), apply the stricter basis (consent or limit-use handling), exclude it from advertising flows, and minimize aggressively — the best sensitive-data strategy is not holding it.

Why it matters for eCommerce

Stores wander into sensitive territory through the catalog: supplements, intimate products, religious goods, and health-adjacent categories all generate inference-laden purchase data. The high-risk pattern is letting product-level behavioral data flow to ad platforms — that is how a checkout becomes a health disclosure. Segment what your pixels and feeds share, and treat health-adjacent categories with MHMD-grade care.

Frequently asked questions

What counts as sensitive personal information?
Under GDPR: racial or ethnic origin, political opinions, religious beliefs, union membership, genetic and biometric data, health data, and sex life or sexual orientation. The CPRA adds government IDs, account credentials, precise geolocation, and message contents. Definitions vary by law — check each statute you are subject to.
Do I need consent to process sensitive data?
Under GDPR, processing special categories generally requires explicit consent or another Article 9 condition. Virginia, Colorado, Connecticut, and most newer state laws require opt-in consent; California instead gives consumers the right to limit use and disclosure. Washington's MHMD requires consent for consumer health data specifically.

Related terms

Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.

Check health-data exposure on your site

← Back to all glossary terms