Key points at a glance
- Article 9 GDPR prohibits the processing of sensitive data. It is only permitted under one of the exceptions set out in Article 9 (2) GDPR, in practice mostly only with explicit consent.
- Article 9 GDPR bars recourse to Article 6 GDPR. A „legitimate interest“ is not sufficient for sensitive data.
- The provider's intent does not matter. Sensitive data obtained unintentionally or indirectly also falls under the prohibition.
- The Regional Court of Cologne (33 O 120/24) applied these principles to an AI chatbot for the first time and prohibited Snapchat from processing without consent.
- The AI Act complements the GDPR: It prohibits certain AI practices involving sensitive data and establishes a narrowly defined permission for bias correction in Article 4a of the AI Act.
- The GDPR applies directly in Austria. The Data Protection Authority (DSB) has confirmed that Art. 9 para. 2 GDPR must additionally be fulfilled for sensitive data in AI systems.
What is sensitive data according to Art. 9 GDPR?
Article 9 paragraph 1 GDPR covers eight exhaustively listed categories: data revealing racial and ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation. The provision specifies a prohibition of informational discrimination and is closely related to Article 21 CFR (Charter of Fundamental Rights of the European Union.
The CJEU interprets the term broadly. The decisive factor is not whether information explicitly states a sensitive characteristic, but whether that characteristic can be derived from it. In a judgment dated August 1, 2022 (C-184/20), the CJEU ruled that data from which sexual orientation can be inferred by means of „intellectual combination or deduction“ also fall under Article 9 of the GDPR. The initial case concerned the naming of a domestic partner in a public statement. The name itself is not sensitive data, but it allows conclusions to be drawn about the gender of the partner and thus about sexual orientation.
The ECJ continued along this line in its judgment of October 4, 2024 (C-21/23, Lindenapotheke). Personal data in online orders of pharmacy-only medicines are considered health data if they allow conclusions to be drawn about a person's state of health. This classification applies regardless of whether the order is placed for the user themselves or for a third party. It is sufficient that the state of health can be deduced from the name, delivery address, and ordered product through mental combination.
This case law is central to AI systems. Sensitive characteristics can be inferred with a high degree of probability from text inputs, images, location data, or user behavior. The EDPB states in its opinion 28/2024 that the ability to draw conclusions is an essential feature of AI systems. What the CJEU describes as a „mental combination“ is the core function in the case of AI.
The blocking effect: Why Art. 6 GDPR does not help
The most important mechanism for practice is the blocking effect of Art. 9 GDPR. As a lex specialis, Art. 9 has a blocking effect vis-à-vis Art. 6 para. 1 GDPR. Recourse to the general lawfulness provisions is excluded if the exceptions in Art. 9 para. 2 and 3 GDPR are not applicable. This also applies when sensitive and non-sensitive data are collected together. In case C-252/21 (Meta Platforms/Bundeskartellamt, judgment of 04.07.2023), the ECJ confirmed that a dataset as a whole must be measured against Art. 9 GDPR as soon as it contains even a single piece of sensitive information.
For AI providers, this means: Anyone relying on a legitimate interest pursuant to Art. 6(1)(f) GDPR must first ensure that no sensitive data is processed. If this cannot be achieved, in most cases the only remaining option is explicit consent pursuant to Art. 9(2)(a) GDPR or a technical solution that removes the personal reference.
The Decision of the Regional Court of Cologne (33 O 120/24): Snapchat „My AI“
In a judgment dated September 17, 2026, the Regional Court of Cologne applied these principles to an AI chatbot. The Federation of German Consumer Organizations (vzbv) brought an action for injunctive relief against Snap Group Limited, a subsidiary of the US-based company Snap Inc. and the contractual partner of German Snapchat users. The central focus was the AI chatbot „My AI,“ which allows users to communicate with artificial intelligence. Before first-time use, Snapchat informed users that the information entered in the chat could be used, among other things, for personalizing advertising. This notice merely had to be acknowledged by clicking „OK.“.
In addition, the vzbv criticized the pre-selected checkmarks for ad preferences as well as the default selection of the „alcohol“ and „gambling“ topics in minors' user accounts.
The result
The Regional Court of Cologne fully granted the claim and ordered the defendant to cease and desist as well as to pay the warning costs. The chatbot processed personal data, some of which was sensitive, without the explicit consent required under Art. 9 (2) GDPR. The pre-checked boxes for ad preferences did not constitute valid consent. Furthermore, the pre-selection of the advertising topics „alcohol“ and „gambling“ for minors violated youth media protection and gambling laws.
The core arguments
The court considered the scope of application of Article 9 of the GDPR to be triggered because the chatbot positively encourages users to disclose personal—including sensitive—information. Although a subpage of the „Privacy and Safety Hub“ advises against sharing confidential or sensitive information, this was merely a non-binding recommendation rather than a prohibition, which, moreover, the majority of users would not take note of. Of particular weight was the fact that the service is also directed at minors aged 13 and older.
Snap argued that sensitive data was not collected intentionally, but rather was „forced upon“ it. The court did not follow this reasoning. According to the case law of the CJEU, the prohibition under Article 9(1) GDPR applies regardless of whether the controller intends to obtain sensitive information. The chamber was not convinced by Snap's argument that it only used the data for „contextual“ rather than personalized advertising. Snap explicitly reserved the right to use the data for personalized advertising in its terms of service and also presented it as such in its privacy policy.
In the alternative, the court examined Article 6 of the GDPR. Neither consent nor a legitimate interest pursuant to Article 6(1)(f) of the GDPR existed, since Snap did not provide users with the necessary information at the time of data collection. The court relied on ECJ C-394/23 (judgment of January 9, 2025), according to which legitimate interests must already be communicated at the time of collection.
Classification
The judgment is the first published decision to consistently apply the blocking effect of Article 9 of the GDPR to the use of AI chatbots. What is new is the idea that a chatbot which invites the disclosure of personal information thereby triggers the scope of application of Article 9 of the GDPR itself. The consequence for providers is that they must either obtain explicit consent or technically prevent sensitive inputs from being stored and evaluated.
Sensitive data in AI training: The Meta case
Another constellation was addressed by the Higher Regional Court of Cologne in the proceedings 15 UKl 2/25 (judgment of May 23, 2025). Meta wanted to use public posts by adult Facebook and Instagram users to train its language models. The Higher Regional Court of Cologne acknowledged that the training dataset also includes personal data of third parties and sensitive data pursuant to Art. 9 GDPR. As a justification, the court invoked Art. 9 para. 2 lit. e GDPR: Sensitive data may be processed if the data subject has „manifestly made it public.“ However, this only applies to data that the affected user has made public themselves.
The application for interim relief by the Consumer Protection Association of North Rhine-Westphalia was unsuccessful. However, the decision demonstrates the limits: The exception under Article 9(2)(e) of the GDPR only applies to data that the data subject has consciously made public themselves. For this, the CJEU requires that the data subject intended to make the data accessible to the general public expressly and through a clear affirmative action. This exception does not apply to sensitive data of third parties, to private chats, and to inputs into chatbots.
What do the regulators say?
EDPB Opinion 28/2024
On December 17, 2024, the European Data Protection Board published its Opinion 28/2024 on AI models. It explicitly excludes the processing of special categories of personal data, but highlights them as a key area that developers and operators must consider. The EDPB also points out that AI models trained on personal data cannot be readily considered anonymous. Therefore, even after training is complete, a model may still contain and reproduce sensitive data.
German Data Protection Conference and LfDI Baden-Württemberg
In its orientation guide dated May 6, 2024, the DSK emphasizes that both during the input, processing, and output of specially protected data, it must be examined whether an exception under Art. 9(2) GDPR is met. For the medical sector, the DSK notes that informed explicit consent pursuant to Art. 9(2)(a) GDPR is an option, which must be preceded by information about the specific functioning of the AI application. The LfDI Baden-Württemberg considers the legal basis of vital interests to be applicable only to the use of AI in emergency situations for short-term measures to protect the vital interests of the data subject.
The Austrian Data Protection Authority
The Austrian Data Protection Authority (DSB) stated in its information paper on the relationship between the GDPR and the AI Act: Insofar as personal data is processed during the (further) development and use of AI systems, at least one justification under Art. 6 (1) GDPR must apply. Insofar as special categories of personal data are processed, the requirements of Art. 9 (2) GDPR must additionally be met. At the same time, the DSB clarifies that the GDPR does not hinder the development of new technologies, as Art. 5 and Art. 6 (1) GDPR provide sufficient possibilities to develop and operate new technologies in compliance with the GDPR.
The AI Act: Prohibitions and a new permission
The Artificial Intelligence Act (Regulation (EU) 2024/1689) does not replace the GDPR. Pursuant to Article 2(7) of the AI Act, the GDPR remains fully applicable. However, it supplements the protection of sensitive data in two ways.
Prohibited Practices (Art. 5 AI Act)
Since February 2, 2025, the absolute prohibitions of Article 5 of the AI Act have been applicable, and the fine rules since August 2, 2025. Two of these prohibitions directly affect sensitive data:
- Emotion recognition (Art. 5 para. 1 lit. f AI Act): The use of AI systems to infer emotions of a natural person in the workplace and in educational institutions is prohibited, unless the system is used for medical or safety reasons. The reason lies in the particular power imbalance in these contexts. Outside of the workplace and education, emotion recognition is not prohibited, but is considered high-risk AI. According to the Commission's guidelines, the determination of physical states such as fatigue does not count as emotion recognition.
- Biometric categorization (Art. 5 para. 1 lit. g AI Act): Systems that categorize natural persons based on their biometric data in order to deduce their race, political opinions, trade union membership, religious or philosophical beliefs, sex life, or sexual orientation are prohibited. The prohibition does not apply to the labeling or filtering of lawfully acquired biometric datasets.
Consent does not help with these prohibitions either. They apply equally to providers and operators. Violations cost up to 35 million euros or 7 % of annual global turnover, whichever is higher. The European Commission published guidelines on the prohibited practices in February 2025.
Bias Detection (Art. 4a AI Act)
The Digital Omnibus Regulation on AI (Regulation (EU) 2026/1744) was published in the Official Journal of the EU on July 24, 2026, and entered into force on July 27, 2026. The previous Article 10(5) of the AI Act was deleted and replaced by a standalone Article 4a. A key new feature is the expansion of the user base: the legal basis is available not only to providers of high-risk AI, but pursuant to Article 4a(2), also to deployers of high-risk AI systems as well as providers and deployers of other AI systems and models, insofar as this is strictly necessary for the detection and correction of bias.
The permission is subject to strict conditions. It requires that the detection and correction of bias cannot be effectively carried out through the processing of other data, including synthetic or anonymized data. Also required are pseudonymization, strict access controls, a prohibition on transmission to third parties, an obligation to delete after bias correction, and a documented justification in the records of processing activities. Article 4a of the AI Act is thus a narrowly tailored instrument for specific and documented bias testing. A blanket permission for the precautionary collection of sensitive data cannot be derived from it.
Outlook: The GDPR Omnibus
On November 19, 2025, the European Commission also proposed amendments to the GDPR. According to the draft, the processing of personal data for the development and operation of AI systems is to qualify as a legitimate interest within the meaning of Art. 6 (1) (f) GDPR. A new exception in Art. 9 (2) (k) draft GDPR is intended to permit the „residual“ processing of sensitive data during the development and operation of an AI system. In addition, the special categories under Art. 9 GDPR are to be defined more narrowly: protection would only apply to data that directly reveal sensitive information.
These proposals are controversial. They contradict the case law of the CJEU, which has confirmed a broad definition of sensitive data and explicitly stated that derived information also falls under Article 9 of the GDPR. Until adoption, the GDPR applies in its current version. Companies should not base their compliance on a potential future relaxation.
What companies in Austria need to check now
The legal situation can be summarized at three levels: input, processing, and output.
Upon input: Where users can enter free text, sensitive data must be expected. Those who do not want to process it must ensure this technically, for example through filters that detect sensitive content and do not save it. A notice in the terms of use is not sufficient.
During processing: If chat histories are saved, transmitted to model providers, or evaluated for training or advertising, explicit consent is required for sensitive data. This must be given actively. Preset checkboxes and confirmation clicks on notice texts are not sufficient.
At the output: The derivation or generation of sensitive statements by the AI system is also a processing activity. Anyone who predicts health risks or political leanings from customer data is processing sensitive data, even if the input data was innocuous.
Furthermore:
- For AI applications involving sensitive data, a data protection impact assessment pursuant to Article 35 GDPR is regularly required.
- For data transfers to providers outside the EU, the requirements of Articles 44 et seq. of the GDPR must be complied with.
- The use of existing inventory data for new AI purposes is a change of purpose that must be examined separately.
- Violations of Article 9 of the GDPR can be punished with fines of up to 20 million euros or 4 % of total worldwide annual turnover.
Legal protection for those affected
Data subjects whose sensitive data has been processed by an AI system without a legal basis can request information pursuant to Article 15 of the GDPR, demand erasure pursuant to Article 17 of the GDPR, lodge a complaint with the data protection authority, and claim damages pursuant to Article 82 of the GDPR.
In addition, the case law of the ECJ opens up another avenue: In the Lindenapotheke case, the ECJ confirmed that Member States may permit competitor lawsuits based on competition law for GDPR violations. Competitors can take legal action against a violation of data protection regulations as an unfair business practice. For Austria, this means: Anyone operating AI systems in violation of Article 9 of the GDPR not only risks proceedings before the Data Protection Authority (DSB), but also injunctive relief claims from competitors under the Austrian Act against Unfair Competition (UWG) as well as representative actions by qualified entities.
Your next step
Whether an AI system processes sensitive data determines the legal basis, documentation effort, and liability risk. The IT law and data protection specialists at ATB.LAW review your AI application for GDPR and AI Act compliance, draft consents and data protection impact assessments, and represent data subjects regarding access, erasure, and damages claims.
Write to us: Dr. Stefan Knotzer LL.M. (knotzer@atb.law) / Mag. Roman Taudes, LL.M. (taudes@atb.law)
FAQ:
Do unintentionally received sensitive data fall under Article 9 GDPR?
Yes. According to the case law of the ECJ, the prohibition under Article 9(1) GDPR applies regardless of whether the controller intends to obtain sensitive information. The Regional Court of Cologne confirmed this for AI chatbots.
Is a legitimate interest sufficient for the processing of sensitive data by AI?
No. Article 9 GDPR bars recourse to Article 6 GDPR. In the case of sensitive data, an exception under Article 9(2) GDPR must apply, in practice usually explicit consent.
What did the Cologne Regional Court decide regarding Snapchat „My AI“?
The Regional Court of Cologne (judgment of September 17, 2026, 33 O 120/24) prohibited Snap from processing sensitive data via the chatbot without express consent. A warning notice on a subpage and an explanatory text to be confirmed by clicking „OK“ were not sufficient. The judgment is not legally binding.
May sensitive data be used for bias correction of AI systems?
Yes, but only under the strict conditions of Article 4a of the AI Act: the correction must not be possible using synthetic or anonymized data, the data must be pseudonymized, secured, and deleted after completion, and the necessity must be documented.
Does German case law also apply in Austria?
German judgments are not binding on Austrian courts. However, the argumentation is based on the GDPR and CJEU case law, which apply directly in Austria. The Austrian Data Protection Authority takes the same line.
Does the Digital Omnibus change the rules for sensitive data?
The AI Act has already been amended (Art. 4a AI Act). The proposed amendments to the GDPR, including a narrower definition of sensitive data and a new AI exception in Art. 9(2), are not yet in force.