Privacy

Explained Clearly - Personal Sensitive Data GDPR

Taras Shynkarenko
Taras Shynkarenko
•Updated: •6 min read
Explained clearly - Personal sensitive data GDPRExplained clearly - Personal sensitive data GDPR

TL;DR, Quick Answer

6 min read

Cookie and analytics data can become sensitive under GDPR when it reveals or enables inference about special categories such as health, politics, religion, sexuality, or trade union membership.

Here, the topic Personal sensitive data GDPR is covered with practical examples. A cookie ID on its own looks purely technical, but personal sensitive data GDPR rules can attach the moment that ID is tied to visits about cancer treatment, union organising, religious services or fertility care.

GDPR calls these "special categories of personal data." Article 9 covers data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation (GDPR Article 9).

Why Web Analytics Can Create Sensitive Data

Web analytics often records:

  • Page URLs.
  • Search terms.
  • Referrers.
  • Campaign parameters.
  • Cookie or device IDs.
  • IP-derived location.
  • Click and conversion events.
  • Account IDs or email hashes in some implementations.

On an ordinary product page, that may be low risk. On a mental health clinic website, a reproductive health resource, a political campaign site, a religious community site, or an employment dispute page, the same data can reveal sensitive information about the visitor.

The risk increases when analytics data is linked across pages, sessions, accounts, or third-party platforms.

Same Data, Different Risk
Ordinary Product Page
  • Page URLs and referrers collected
  • Cookie or device IDs recorded
  • Low risk under GDPR Article 9
Mental Health Clinic Page
  • Same page URLs and cookie IDs
  • Data reveals health status
  • Special category risk under Article 9
The same analytics fields carry different GDPR risk depending on what the page is about.

A laptop screen showing a website cookie consent prompt, the kind of ordinary tracking moment that can turn into special category data once linked to a sensitive page.

The Meta/Bundeskartellamt Warning

The Court of Justice of the European Union addressed special category concerns in the Meta Platforms v Bundeskartellamt judgment. The court found that visiting websites or apps related to special category topics can reveal sensitive data, and that processing such data can fall under Article 9 depending on the circumstances (CJEU case C-252/21).

The practical lesson is not limited to social networks. If tracking systems collect page-level behavior that reveals sensitive interests, organisations need to treat that data with heightened care.

Examples for Analytics Teams

High-risk examples:

  • A health clinic sends page URLs about specific conditions to a third-party analytics vendor.
  • A nonprofit tracks visitors to domestic violence resources with persistent IDs.
  • A political campaign shares event attendance pages with ad platforms.
  • A union organizing site retargets visitors based on viewed pages.
  • A mental health app records therapy-topic pageviews in a general marketing stack.

Lower-risk examples:

  • Aggregate page counts with no persistent identifiers.
  • Server-side logs with short retention and IP minimisation.
  • Event counts that avoid sensitive page titles or query strings.
  • Country-level reporting without user-level histories.

Context matters. The same analytics event can be harmless on a generic blog and sensitive on a healthcare page.

Compliance Implications

Special category processing is generally prohibited unless an Article 9 exception applies, such as explicit consent or another specific legal basis. Ordinary consent for analytics cookies may not be enough if the processing involves sensitive data and third-party profiling.

Teams may also need:

  • A data protection impact assessment.
  • Stronger access controls.
  • Shorter retention.
  • Vendor restrictions.
  • Explicit consent where appropriate.
  • A ban on advertising use.
  • Careful privacy disclosures.
  • Review of international transfers.

For health-related sites in the United States, HIPAA may also apply if the organisation is a covered entity or business associate. HHS has issued guidance and enforcement attention around online tracking technologies used by HIPAA-regulated entities (HHS online tracking technologies guidance). Important 2024 caveat: HHS notes that a federal court vacated the bulletin to the extent it treated an IP address plus a visit to certain unauthenticated public health pages as automatically triggering HIPAA obligations. That does not remove risk for portals, appointment, intake, payment, authenticated, or PHI-disclosing workflows.

Practical Risk Reduction

Use a sensitive-context analytics checklist:

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

  1. Identify pages that reveal health, religion, politics, sexuality, union status, children, or other sensitive topics.
  2. Disable advertising pixels on those pages.
  3. Avoid session replay and heatmaps on sensitive flows.
  4. Strip query strings before analytics collection.
  5. Do not send page titles that include sensitive terms if aggregate categories will do.
  6. Avoid persistent identifiers where possible.
  7. Keep reports aggregate.
  8. Restrict access.
  9. Shorten raw-data retention.
  10. Review vendors and subprocessors.

Privacy-First Measurement

Privacy-first analytics is especially valuable in sensitive contexts. A clinic, nonprofit, advocacy group, or public service can answer operational questions without tracking identifiable journeys.

Useful low-risk metrics include:

  • Total visits to a resource category.
  • Referrer domains in aggregate.
  • Device class for usability checks.
  • Search terms only when anonymised and reviewed.
  • Conversion counts for non-sensitive actions.

If a question cannot be answered without collecting sensitive behavior, ask whether the question is worth the risk. In many cases, a less detailed metric, survey, or server-side operational record is safer and more respectful.

Red Flags in Event Design

Review event names and properties before launch. Events such as depression_quiz_started, union_contact_form_submitted, or pregnancy_help_clicked may be useful internally, but they can expose sensitive meaning if sent to general analytics or advertising tools.

Use neutral categories where possible, restrict access, and keep sensitive analytics out of third-party ad ecosystems. In sensitive contexts, "more granular" is often not better.

Safer Naming Examples

Event naming can reduce risk without making reports useless. Instead of sending pregnancy_options_page_viewed, send resource_category_viewed with a broad category visible only in aggregate. Instead of therapy_for_grief_video_75_percent, send video_progress with a non-sensitive content ID that only a restricted internal table can interpret.

The same principle applies to URLs. Avoid paths and query strings that expose diagnosis, legal status, or personal concerns when a simpler page structure will do. If sensitive words must appear for usability or SEO, configure analytics to strip the path or report at a broader category level. The goal is not to hide the service from users; it is to avoid broadcasting sensitive meaning to general-purpose analytics systems.

Renaming Events To Cut Exposure
Risky Event Names
  • pregnancy_options_page_viewed
  • therapy_for_grief_video_75_percent
Safer Event Names
  • resource_category_viewed, broad category in aggregate
  • video_progress, non-sensitive content ID
Renaming events strips sensitive meaning without losing the ability to measure engagement.

Sensitive-Context Review

Before tracking sensitive pages, document the page category, event names, URL behavior, identifiers, vendors, retention, access controls, and whether Article 9 or another sector law could apply. Then test the page in a clean browser profile and inspect network calls, cookies, storage, and server-side events.

If analytics still sends condition names, sensitive search terms, persistent IDs, or advertising calls from sensitive pages, the issue is not wording in the privacy notice. The data design needs to be narrowed.

Frequently Asked Questions

What counts as special category data under GDPR Article 9?

GDPR Article 9 covers data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, and trade union membership. Article 9 also covers genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation. A cookie ID by itself is not sensitive, but it can fall under these rules once it is tied to visits about cancer treatment, union organising, religious services, or fertility care.

A cookie ID becomes sensitive once it is linked to browsing that reveals health, political, religious, or sexual information. That risk grows further when analytics data gets linked across pages, sessions, accounts, or third-party platforms.

What did the CJEU rule in the Meta/Bundeskartellamt case?

In case C-252/21, the Court of Justice of the European Union found that visiting websites or apps related to special category topics can reveal sensitive data. Processing such data can fall under Article 9 depending on the circumstances. The ruling reaches beyond social networks to any tracking system that collects page-level behavior revealing sensitive interests.

A doctor reviewing patient records at a desk, representing the healthcare workflows where HIPAA obligations still apply to online tracking.

HIPAA can still apply if the organization is a covered entity or business associate. A federal court vacated the part of HHS guidance that treated an IP address plus a visit to certain unauthenticated public health pages as automatically triggering HIPAA obligations, but portals, appointment, intake, payment, authenticated, and PHI-disclosing workflows still carry risk.

Ordinary consent for analytics cookies may not cover processing that involves sensitive data and third-party profiling. Special category processing is generally prohibited unless an Article 9 exception applies, such as explicit consent or another specific legal basis.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Which analytics fields turn risky on a sensitive page?

Page URLs, search terms, referrers, cookie or device IDs, IP-derived location, and account IDs or email hashes can all turn risky on a sensitive page. The risk comes from the page they sit on: health, politics, religion, or sexuality. The same fields stay low risk on an ordinary product page.

What is a data protection impact assessment for in this context?

A data protection impact assessment documents the risk before sensitive analytics tracking goes live, alongside stronger access controls, shorter retention, vendor restrictions, explicit consent, and a ban on advertising use. It gives teams a record of what was considered instead of a reaction written after a complaint.

Should advertising pixels run on health or union pages?

The risk reduction checklist calls for disabling advertising pixels on pages that reveal health, religion, politics, sexuality, or union status. Session replay and heatmaps should also stay off those same flows.

What metrics can a clinic or nonprofit use without tracking identifiable journeys?

Total visits to a resource category, referrer domains in aggregate, device class for usability checks, anonymised and reviewed search terms, and conversion counts for non-sensitive actions cover most operational questions. A clinic, nonprofit, advocacy group, or public service can answer what it needs to know without tracking identifiable journeys.

Why do event names like depression_quiz_started create risk?

Event names such as depression_quiz_started, union_contact_form_submitted, or pregnancy_help_clicked expose sensitive meaning the moment they reach general analytics or advertising tools, even though they read as ordinary product events internally. Neutral categories and restricted access cut that exposure while keeping the underlying measurement.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Articles