AI
GDPR Article 9: Running AI on Sensitive Data | Xinity
Most AI compliance reviews we see focus on security controls, certifications and processor agreements. Those matter. None of them answers the question Article 9 GDPR asks, which is whether the processing is permitted at all.
This article sets out what Article 9 requires, how it applies when the processing is done by an AI system, and what that means for where inference runs. It is written for legal, compliance and data protection teams. It is general information understood by the Xinity team, not legal advice.
Summary
Article 9(1) prohibits processing of eight categories of personal data by default. Article 9(2) lists ten exceptions. One of them must apply, and an Article 6 legal basis is needed in addition.
Data from which a special category can be inferred is itself special category data. The Court of Justice has confirmed this twice. AI systems infer routinely.
The controller carries the Article 9 obligation. A processor does not supply a legal basis. An AI provider that uses input data for its own purposes is a controller for that processing and needs its own basis.
Sending special category data to a provider outside the EEA raises a separate Chapter V question. The EU-US Data Privacy Framework is in force but under active challenge.
Running inference on infrastructure the controller operates removes the third party from the inference path and removes the transfer question for that step. It does not create a legal basis. Article 9 still has to be satisfied.
1. The prohibition
Article 9(1) prohibits the processing of personal data revealing:
racial or ethnic origin
political opinions
religious or philosophical beliefs
trade union membership
and the processing of:
genetic data
biometric data for the purpose of uniquely identifying a natural person
data concerning health
data concerning a natural person's sex life or sexual orientation
The structure matters. This is a prohibition with exceptions, not a permission with conditions. The default answer is no.
Article 9 sits on top of Article 6. A controller processing special category data needs both a lawful basis under Article 6(1) and a condition under Article 9(2). Fines for Article 9 breaches fall under Article 83(5): up to EUR 20 million or 4% of worldwide annual turnover, whichever is higher.
2. The exceptions
Article 9(2) lifts the prohibition in ten situations. In summary:
(a) the data subject has given explicit consent for one or more specified purposes, unless Union or Member State law says consent cannot lift the prohibition
(b) processing is necessary under employment, social security or social protection law
(c) processing is necessary to protect vital interests where the data subject cannot consent
(d) processing by a not-for-profit body with a political, philosophical, religious or trade union aim, relating to its members
(e) the data were manifestly made public by the data subject
(f) processing is necessary for legal claims or court proceedings
(g) processing is necessary for reasons of substantial public interest, on the basis of law
(h) processing is necessary for preventive or occupational medicine, medical diagnosis, or the provision of health or social care, subject to professional secrecy under Article 9(3)
(i) processing is necessary for reasons of public interest in public health
(j) processing is necessary for archiving, scientific or historical research, or statistics under Article 89(1)
Two points follow for AI deployments.
First, for most commercial AI use cases outside healthcare, employment law and research, the realistic candidates are (a) explicit consent and, less often, (e). Legitimate interest is not on the list. It cannot lift the Article 9 prohibition.
Second, Article 9(4) allows Member States to add further conditions for genetic, biometric and health data. A deployment that is compliant in one Member State might face additional national conditions in another.
3. What counts as special category data when AI is involved
The list in Article 9(1) is about what data reveal, not what field they sit in. The Court of Justice has held that data from which a special category can be indirectly deduced are themselves special category data. In Case C-184/20 (1 August 2022) the Court found that publishing the name of a person's partner could reveal sexual orientation and fell under Article 9. In Case C-252/21, Meta Platforms v Bundeskartellamt (4 July 2023), the Court applied the same reasoning to data collected when users visit websites or apps relating to special categories.
For AI this is significant. Large language models and classifiers infer. A support ticket, an HR note, a free-text form field or a document set can contain or generate health, religious, political or sexual orientation information without any field being labelled as such. The controller does not avoid Article 9 by not intending the inference. If the system processes data revealing a special category, Article 9 applies.
Where processing of special categories is on a large scale, Article 35(3)(b) requires a data protection impact assessment, and Article 37(1)(c) requires a data protection officer where large-scale processing of special categories is a core activity.
4. Controllers, processors and AI providers
The original argument that a cloud AI provider needs its own explicit consent for every input is not how the GDPR allocates responsibility. It is worth being precise, because the precise version is the stronger one.
The controller determines purposes and means and carries the Article 9 obligation. A processor processes on the controller's documented instructions under an Article 28 contract. The controller's Article 9(2) condition has to cover the whole processing it instructs, including the part carried out by the processor. If the controller relies on 9(2)(a), the explicit consent has to be specific about the purposes, and the data subject has to have been told that the data will be processed by a named category of third-party provider. Consent obtained for internal handling does not automatically extend to disclosure to an external AI system.
The second point is where cloud AI models usually fail the test. Many providers process inputs for their own purposes: abuse monitoring, service improvement, model evaluation, or training unless the customer opts out. For that processing the provider is not acting on the controller's instructions. It is a controller in its own right. It therefore needs its own Article 6 basis and its own Article 9(2) condition for any special category data it retains and uses. In practice, a provider has no relationship with the end data subject and no realistic route to explicit consent. The EDPB has set out the criteria for distinguishing controllers from processors in its Guidelines 07/2020, and a provider deciding to use inputs for its own aims is on the controller side of that line.
A Data Processing Agreement does not resolve this. It governs the processor role. It cannot convert a provider's own-purpose processing into processing on instructions.
5. Transfers outside the EEA
If the provider, or any sub-processor, is outside the EEA, Chapter V applies in addition to the Article 9. The controller needs a transfer mechanism under Articles 44 to 49 and, for transfers on standard contractual clauses, a transfer impact assessment.
For the United States the position at the time of writing is as follows. The Court of Justice invalidated Privacy Shield in Case C-311/18, Schrems II, on 16 July 2020. The Commission adopted a new adequacy decision for the EU-US Data Privacy Framework on 10 July 2023 (Implementing Decision (EU) 2023/1795). On 3 September 2025 the General Court dismissed the first direct challenge to that decision in Case T-553/23, Latombe v Commission. That judgment has been appealed to the Court of Justice as Case C-703/25 P. The appeal is pending. Separately, in June 2026 the privacy organisation noyb asked the Commission to withdraw the adequacy decision following a US Supreme Court judgment on the removability of Federal Trade Commission commissioners.
The Data Privacy Framework is therefore valid and can be relied on today. It is also the third transatlantic framework in a row to face a challenge before the Court that struck down the previous two. A controller sending special category data to a US provider is taking a transfer risk on top of an Article 9 risk, and should document that it has considered both.
6. Security is necessary, not sufficient
Encryption in transit, isolated tenancy, SOC 2 reports and "we do not train on your data" statements are Article 32 measures. They address the security of processing. They do not address its lawfulness. A controller can have exemplary security and still be processing special category data without an Article 9(2) condition. Article 9 is not about breaches. It is about whether the processing may take place.
7. Anonymisation
Anonymised data are not personal data and fall outside the GDPR. The threshold is high. The EDPB's Opinion 28/2024 on AI models (17 December 2024) states that a model trained on personal data can only be treated as anonymous where the likelihood of extracting personal data, directly or through queries, is insignificant, assessed against all means reasonably likely to be used, in line with Recital 26. The Opinion expressly excludes special category data from its scope, so it sets a floor rather than a ceiling for Article 9 purposes. Given that AI systems infer sensitive attributes from apparently innocuous inputs, a controller relying on anonymisation should be able to show, not assert, that re-identification and inference risks are negligible.
8. Interaction with the EU AI Act
Regulation (EU) 2024/1689 does not displace Article 9. It adds one narrow permission. Article 10(5) allows providers of high-risk AI systems to process special category data where strictly necessary for detecting and correcting bias, subject to safeguards including that the data cannot be processed by other means, that access is restricted, and that the data are deleted once the bias has been corrected or the retention period has ended. Outside that specific situation, the Article 9 analysis is unchanged.
9. What legal and compliance teams should do
Map data flows to every AI system in use, including tools adopted by individual teams. Identify where special category data are input, inferred or output.
For each flow, record the Article 6 basis and the Article 9(2) condition. If the answer is "the DPA covers it", the answer is incomplete.
Where the condition is explicit consent, check that the consent text names the purpose and the disclosure to an external AI provider. If it does not, the consent does not cover that processing.
Review the provider's terms for own-purpose processing: training, evaluation, abuse monitoring, retention. Each of those makes the provider a controller for that processing.
If the provider or its sub-processors are outside the EEA, document the Chapter V mechanism and the transfer impact assessment, and note the pending challenges to the Data Privacy Framework.
Where processing of special categories is large-scale, complete the DPIA under Article 35 and confirm the DPO requirement under Article 37.
Check for Member State conditions under Article 9(4) in each jurisdiction where data subjects are located.
10. Where infrastructure fits
Xinity provides software that runs AI inference on the customer's own servers. Here is what that does and does not change for the Article 9 analysis.
It removes the third party from the inference path. Prompts, documents and model outputs are processed on infrastructure the controller operates. There is no external provider acting as processor for inference, and no provider processing inputs for its own purposes. The controller-processor questions in Section 4 do not arise for that step.
It removes the Chapter V question for inference. No personal data leave the controller's environment to be processed by a model, so there is no transfer for that step.
It supports accountability. Inference requests are logged on the controller's systems, which gives the DPIA and any supervisory authority enquiry a single audit trail under the controller's control.
It does not create a legal basis. Running a model locally does not supply an Article 9(2) condition. The controller still needs one, and still needs the Article 6 basis, the DPIA where required, and any Member State conditions. On-premise inference narrows the set of questions a controller has to answer. It does not answer Article 9 for them.
For controllers handling health, biometric or other special category data at scale, that narrowing is often the difference between a compliance position that can be documented and one that depends on assurances from a provider that has no relationship with the data subject.
Sources
Regulation (EU) 2016/679 (General Data Protection Regulation), in particular Articles 6, 9, 28, 32, 35, 37, 44 to 49 and 83, and Recitals 26 and 51: https://eur-lex.europa.eu/eli/reg/2016/679/oj
Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 10(5)
Court of Justice of the European Union, Case C-311/18, Data Protection Commissioner v Facebook Ireland and Maximillian Schrems (Schrems II), judgment of 16 July 2020
Court of Justice of the European Union, Case C-184/20, OT v Vyriausioji tarnybinės etikos komisija, judgment of 1 August 2022
Court of Justice of the European Union, Case C-252/21, Meta Platforms and Others v Bundeskartellamt, judgment of 4 July 2023
General Court of the European Union, Case T-553/23, Latombe v Commission, judgment of 3 September 2025, press release No 106/25: https://curia.europa.eu/jcms/upload/docs/application/pdf/2025-09/cp250106en.pdf
Court of Justice of the European Union, Case C-703/25 P, Latombe v Commission, appeal lodged 31 October 2025, pending
European Commission, Implementing Decision (EU) 2023/1795 of 10 July 2023 on the adequate level of protection of personal data under the EU-US Data Privacy Framework
European Data Protection Board, Guidelines 07/2020 on the concepts of controller and processor in the GDPR
European Data Protection Board, Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models, 17 December 2024: https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf
This article is general information about EU data protection law. It is not legal advice and does not create a lawyer-client relationship. Obtain advice on your specific circumstances from qualified counsel.
Updated 9 September 2026: restructured for legal readers, sources added, the controller and processor analysis corrected, and the transfer section updated to reflect the EU-US Data Privacy Framework and the pending appeal in Latombe v Commission.
This article was drafted with AI assistance and reviewed, fact-checked, and edited by the Xinity team, which takes full editorial responsibility for its content.