ClairaClaira Help Desk
AI ReviewPromptingTemplatesInvestigations

Special category data (GDPR Article 9)

Other languages

Special category data (GDPR Article 9)

Use this template to decide which documents contain the sensitive categories of personal data that Article 9 of the GDPR singles out for extra protection.

PromptingTemplate PickerSpecial category data (GDPR Article 9)

When you select this template, Claira displays the prompt configuration panel. Map the output to a Text or Memo review field. Restrict field visibility and follow your organization's data-handling policy: the output names the sensitive categories a document contains.

Special category dataTextclaira-art9-01

What this prompt is for

This is a classification task, not an extraction sweep. Where Comprehensive PII (surface forms) lists every written form of every identifier, this template answers a narrower and more consequential question: does this document touch any of the categories that Article 9 protects, and which ones?

Those categories carry a higher processing bar under the GDPR, so knowing which documents contain them drives redaction, access restriction, retention and DSAR scoping decisions. Run the two templates together when you need both the inventory and the sensitivity flag.

The prompt judges content rather than vocabulary, which is the difference that matters in practice: a sick note is health data whether or not the word "health" appears in it.

Step-by-step in Claira

  1. Open Prompting > Template picker in your case.
  2. Under Investigations, select Special category data (GDPR Article 9) and map the output to a Text or Memo review field.
  3. Run a 10 to 25 document sample first and check the label assignments against your own reading: the category boundaries are judgement calls, and a sample tells you whether the model's line matches yours.
  4. Adjust field permissions and workflow settings outside the prompt body, then extend to bulk review.

The prompt

Decide whether this document contains special category personal data as defined by Article 9 of the GDPR, and report which categories are present.

The Article 9 categories are: racial or ethnic origin; political opinions; religious or philosophical beliefs; trade union membership; genetic data; biometric data processed to uniquely identify a person; data concerning health; and data concerning a person's sex life or sexual orientation.

Judge the content, not the vocabulary. A sick note, a workplace accommodation request, a dietary requirement that reveals a religion, or a photograph described as used for identity matching all count, whether or not the document uses the words above. A passing mention of a public figure's known affiliation, in a document that is not about that person's data, does not.

Report Article 10 data (criminal convictions and offences) under the label CRIMINAL when present. It is not an Article 9 category, but most reviews treat it alongside them.

Output format:
- One line. Start with the applicable category labels, comma-separated, from this closed list: RACIAL_ETHNIC, POLITICAL, RELIGIOUS_PHILOSOPHICAL, TRADE_UNION, GENETIC, BIOMETRIC, HEALTH, SEX_LIFE_ORIENTATION, CRIMINAL.
- Then a pipe character, then one sentence naming the passage that supports each label. Do not quote more of the document than is needed to identify the passage.
- Do not add headings, bullets, counts, or commentary.

If none of the categories are present, output exactly: NO SPECIAL CATEGORY DATA
  • Run this as a Multi-Code scan, one field per category, when a matter needs the categories separated for filtering or reporting rather than combined on one line. The label list is closed, which makes it a clean fit.
  • Drop CRIMINAL from the prompt if your matter has no Article 10 dimension and the label is adding noise.
  • Narrow to the categories your matter actually turns on (health alone, for an occupational injury case) when a full nine-category sweep produces more flags than the review can act on.
  • State the controller's own definitions in workflow instructions where your organization draws a category line differently from the default reading.

Worked example

Input excerpt

Occupational health report for M. Okonjo, prepared following the lifting incident on
14 March. Recommends a phased return with a 10 kg lifting limit for eight weeks. Ms
Okonjo asked that her Unite branch representative attend the review meeting.

Expected output shape

HEALTH, TRADE_UNION | An occupational health report on the named employee's lifting injury and phased return, and a request that her Unite branch representative attend the review meeting.

Two categories, one line, and the supporting passage named rather than quoted at length: the output identifies where to look without reproducing the sensitive content into a review field.

Troubleshooting

  • If everything comes back flagged, the model is likely reading passing mentions as subject data. Restate in workflow instructions that the document must be about the person's data, not merely mention a category.
  • If labels appear that are not in the list, restate that the list is closed and that no other label may be emitted.
  • If the supporting sentence quotes too much of the document, say explicitly that it must name the passage rather than reproduce it.
  • Article 9 boundaries are judgement calls at the margin. Treat the output as a triage signal for human review, not as a legal determination.

Was this page helpful?

Need more help?

Contact our support team at support@claira.to — we are here to help.