Special category data is personal data that UK GDPR treats as especially sensitive, because misusing it could cause serious harm or discrimination. It covers health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation, genetic data, and biometric data used to identify someone.
How special category data works
To use ordinary personal data, you need a lawful basis under Article 6 of UK GDPR. For special category data you need that and one of the conditions in Article 9 as well. For most marketing uses, the realistic condition is explicit consent: a clear, specific statement the person actively agrees to, such as an unticked box reading “I agree to the clinic using the health information in this form to reply to my enquiry”. Other conditions, such as providing health care, cover clinical work, and some rely on the Data Protection Act 2018, which can require an appropriate policy document.
The category also catches inferences. Data that never mentions health can still reveal it. A list of people who booked a fertility consultation, a retargeting audience built from visitors to a hair-loss treatment page, or an email segment called “IBS patients” all disclose health information about the people in them. The ICO’s view is that if you can infer a special category characteristic with reasonable certainty, or you use data to treat people differently on that basis, you are processing special category data.
Higher risk brings extra work. A data protection impact assessment is usually needed for large-scale use or profiling, and security must match the sensitivity of the data.
Why it matters
Many businesses handle it without realising. Private clinics, dentists, pharmacies, physiotherapists, counsellors and aesthetics businesses collect health information through enquiry forms every day. Faith organisations, charities serving particular communities and dating services touch other categories.
The marketing risk is in the tools. An ad pixel on a condition-specific page can pass the page address, and with it a health inference, to an ad platform. Uploading a clinic’s patient list as a custom audience tells the platform that everyone on it is a patient. The platforms set their own limits: Meta’s health and body image policy stops ads implying knowledge of a person’s health, and its terms forbid sending it sensitive health information. Do not confuse special category data with Meta’s special ad categories, a separate platform rule that restricts targeting for ads about housing, employment, financial products and services, and social issues, elections or politics, whatever data is involved.
Common mistakes
- Free-text enquiry fields that invite people to describe symptoms, with no explicit consent and no thought about where submissions are stored.
- Pixels and analytics tags that send condition-specific page addresses or form answers to ad platforms.
- Uploading patient or client lists to ad platforms for targeting or lookalike audiences.
- Ad copy that implies the reader has a condition, such as “Struggling with your anxiety?”, which also breaks platform policies.
- Form submissions emailed to personal inboxes or kept in an unprotected spreadsheet.
How to act on it
Map where sensitive data enters your marketing: forms, booking tools, chat widgets, call recordings and lead ads. Ask only for what you need to respond, and move detailed health questions to the consultation rather than the enquiry form. Where you do collect health information, use a separate, unticked explicit consent statement and explain the use in your privacy notice.
Then check what your tags send. Exclude condition pages and form fields from ad platform tracking, and do not build audiences from patient data. When I build Facebook lead ad campaigns for clinics, the instant form asks for contact details and a preferred time only, and the clinical conversation happens later with the practitioner.
