Genetic Data (Article 4(13) GDPR)
Genetic data are personal data relating to the inherited or acquired genetic characteristics of a person that give information about physiology or health and warrant special protection.
Genetic data capture the inherited and acquired genetic constitution of a natural person. Because they permit unique inferences about physiology and state of health, they rank among the most sensitive categories of personal data of all. Data protection law therefore treats them with a general prohibition of processing.
Key takeaways
- Genetic data are personal data relating to the inherited or acquired genetic characteristics that give unique information about physiology or health and result, in particular, from an analysis of a biological sample (Article 4(13) GDPR).
- They are typically obtained through chromosomal, DNA or RNA analysis or equivalent methods (Recital 34 GDPR).
- Genetic data belong to the special categories under Article 9 GDPR; their processing is prohibited in principle and permitted only where one of the exceptions in Article 9(2) GDPR applies.
- Member States may introduce additional conditions and limitations for genetic data, biometric data and data concerning health (Article 9(4) GDPR); in Germany, the German Genetic Diagnostics Act (Gendiagnostikgesetz, GenDG) applies in particular.
- In criminal proceedings, DNA analysis is limited to the identification pattern and sex (Section 81g(2) of the German Code of Criminal Procedure (StPO)).
1. Overview
Article 4(13) GDPR defines genetic data as personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.
Recital 34 GDPR clarifies that this analysis may result, in particular, from chromosomal, deoxyribonucleic acid (DNA) or ribonucleic acid (RNA) analysis, or from the analysis of another element enabling equivalent information to be obtained (Recital 34 GDPR).
A characteristic feature of genetic data is their uniqueness: they are individual to each person and at the same time partly shared with blood relatives. A test result may therefore reveal information not only about the data subject but also about their family members.
2. Scope of the Definition
2.1 Coding and Non-Coding DNA
The definition covers both the coding and the non-coding region of the genome. The non-coding region was long classified as biologically meaningless; in fact, however, it allows inferences about age, external features such as eye, hair and skin color, and geographic origin. Such data give unique information about a person's physiology and thus fall within the definition of Article 4(13) GDPR.
2.2 Analysis of a Biological Sample
The starting point for obtaining the data is regularly a biological sample, such as blood, saliva or tissue material. The sample can be analyzed in various ways: classic chromosomal analysis, DNA sequencing or RNA-based methods, as well as other procedures that yield equivalent genetic information.
It is not the mere taking of a biological sample, but only the analysis from which genetic information is obtained, that establishes the connection to Article 4(13) GDPR. As long as a sample is stored without being analyzed, there is not yet any genetic datum within the meaning of the provision.
2.3 Distinction from Related Data Categories
Genetic data are closely related to biometric data and data concerning health; together with other sensitive categories, all three make up the level of protection under Article 9 GDPR. The following table shows the essential differences:
| Feature | Genetic data | Biometric data | Data concerning health |
|---|---|---|---|
| Basis | Inherited/acquired genetic characteristics | Physical/physiological/behavior-based features | Physical/mental state of health |
| Typical source | Analysis of a biological sample (DNA, RNA) | Fingerprint, iris, face, voice | Medical findings, lab values, diagnosis |
| Family relevance | Yes, partly shared with relatives | No (individual) | No (individual) |
| Standalone GDPR definition | Article 4(13) | Article 4(14) | Article 4(15) |
3. Classification as a Special Data Category
Genetic data are special categories of personal data under Article 9(1) GDPR. Their processing is prohibited in principle. Processing is permitted only where one of the exhaustively enumerated exceptions in Article 9(2) GDPR applies, such as explicit consent, a substantial public interest or the necessity for medical purposes.
Article 9(4) GDPR gives Member States the option of introducing or maintaining, for genetic data, biometric data and data concerning health, additional conditions and limitations beyond the level of protection required under Union law (Article 9(4) GDPR). Germany has made use of this opening clause: the Gendiagnostikgesetz (GenDG) governs genetic testing and the handling of genetic data in medical, insurance and employment-law contexts (GenDG). For an overview of the Member State opening clauses, see 1.3.12.3 Opening Clause for Member State Law.
4. Special Feature in Criminal Proceedings
Criminal procedure law contains a sector-specific rule: under Section 81g(2) StPO, molecular genetic testing carried out as part of identification-service measures may be used exclusively to establish the DNA identification pattern and the sex of the data subject (Section 81g StPO). Any findings going beyond this are expressly impermissible. This limitation prevents DNA samples obtained in criminal proceedings from being used for further phenotypic or health-related analyses.
Article 4(13) GDPR
Full text of the legal definition of genetic data.
Article 9 GDPR
Prohibition of processing and exceptions for special categories.
Biometric Data
Article 4(14) GDPR: definition and distinction.
Data Concerning Health
Article 4(15) GDPR: health-related data.
Personal Data
Article 4(1) GDPR: the basic term as the overarching category.
Sensitive Data Categories
Overview of Article 9 GDPR: the system of special categories.
Member State Opening Clause
Article 9(4) GDPR: national supplementary rules.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Personal Data Breach (Article 4(12) GDPR)
What a data breach means under the GDPR, which three types of breach are distinguished, and which obligations to notify the supervisory authority and data subjects are triggered.
Biometric Data (Article 4(14) GDPR)
Biometric data are characteristics of a person resulting from specific technical processing (fingerprint, facial image, voice and others) that allow their unique identification and that, as a special category under Article 9 GDPR, are subject to a general prohibition of processing.