← Glossary·Privacy

Sensitive Personal Information (SPI)

GDPRCCPA

Special category of personal data — health, biometrics, race, religion, sexual orientation, precise geolocation, etc.

SPI (CCPA/CPRA) and Special Category Data (GDPR Art. 9) cover personal data warranting heightened protection: racial/ethnic origin, political opinions, religious beliefs, trade-union membership, genetic/biometric data, health data, sex life or orientation, and (under CPRA) SSN, driver's license, financial account, precise geolocation, contents of communications.

Why it matters
Processing SPI typically requires explicit consent or another narrow lawful basis — and triggers a right-to-limit-use under CCPA/CPRA.

Related terms

Personal Data (GDPR)
Any information relating to an identified or identifiable natural person (data subject) — Art. 4(1).
Lawful Basis (Legal Basis for Processing)
One of six GDPR Art. 6 grounds that must apply for personal data processing to be lawful.
CCPA / CPRA
California's omnibus consumer privacy law, expanded by CPRA; enforced by the CPPA.

Does your program actually cover Sensitive Personal Information (SPI)?

Run a free ComplianceIQ audit against GDPR and we'll surface every gap on this — and the other controls auditors flag — with the exact clause references to fix.

Free GDPR auditBack to glossary