# Genetic Data (Article 4(13) GDPR)

Genetic data are personal data relating to the inherited or acquired genetic characteristics of a person that give information about physiology or health and warrant special protection.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/begriffe-und-definitionen/1.2.13-genetische-daten
> Sprache: en



Genetic data capture the inherited and acquired genetic constitution of a natural person. Because they permit unique inferences about physiology and state of health, they rank among the most sensitive categories of personal data of all. Data protection law therefore treats them with a general prohibition of processing.

<Callout type="info">
  **Key takeaways**

  * Genetic data are personal data relating to the inherited or acquired genetic characteristics that give unique information about physiology or health and result, in particular, from an analysis of a biological sample (Article 4(13) GDPR).
  * They are typically obtained through chromosomal, DNA or RNA analysis or equivalent methods (Recital 34 GDPR).
  * Genetic data belong to the special categories under Article 9 GDPR; their processing is prohibited in principle and permitted only where one of the exceptions in Article 9(2) GDPR applies.
  * Member States may introduce additional conditions and limitations for genetic data, biometric data and data concerning health (Article 9(4) GDPR); in Germany, the German Genetic Diagnostics Act (Gendiagnostikgesetz, GenDG) applies in particular.
  * In criminal proceedings, DNA analysis is limited to the identification pattern and sex (Section 81g(2) of the German Code of Criminal Procedure (StPO)).
</Callout>

## 1. Overview [#1-overview]

Article 4(13) GDPR defines genetic data as personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.

Recital 34 GDPR clarifies that this analysis may result, in particular, from chromosomal, deoxyribonucleic acid (DNA) or ribonucleic acid (RNA) analysis, or from the analysis of another element enabling equivalent information to be obtained ([Recital 34 GDPR](https://dsgvo-gesetz.de/erwaegungsgruende/nr-34/)).

A characteristic feature of genetic data is their uniqueness: they are individual to each person and at the same time partly shared with blood relatives. A test result may therefore reveal information not only about the data subject but also about their family members.

## 2. Scope of the Definition [#2-scope-of-the-definition]

### 2.1 Coding and Non-Coding DNA [#21-coding-and-non-coding-dna]

The definition covers both the coding and the non-coding region of the genome. The non-coding region was long classified as biologically meaningless; in fact, however, it allows inferences about age, external features such as eye, hair and skin color, and geographic origin. Such data give unique information about a person's physiology and thus fall within the definition of Article 4(13) GDPR.

### 2.2 Analysis of a Biological Sample [#22-analysis-of-a-biological-sample]

The starting point for obtaining the data is regularly a biological sample, such as blood, saliva or tissue material. The sample can be analyzed in various ways: classic chromosomal analysis, DNA sequencing or RNA-based methods, as well as other procedures that yield equivalent genetic information.

<Callout type="info">
  It is not the mere taking of a biological sample, but only the analysis from which genetic information is obtained, that establishes the connection to Article 4(13) GDPR. As long as a sample is stored without being analyzed, there is not yet any genetic datum within the meaning of the provision.
</Callout>

### 2.3 Distinction from Related Data Categories [#23-distinction-from-related-data-categories]

Genetic data are closely related to [biometric data](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.14-biometrische-daten) and [data concerning health](/docs/dsgvo-hub/begriffe-und-definitionen/1.2.15-gesundheitsdaten); together with other sensitive categories, all three make up the level of protection under Article 9 GDPR. The following table shows the essential differences:

| Feature                    | Genetic data                               | Biometric data                                 | Data concerning health                  |
| -------------------------- | ------------------------------------------ | ---------------------------------------------- | --------------------------------------- |
| Basis                      | Inherited/acquired genetic characteristics | Physical/physiological/behavior-based features | Physical/mental state of health         |
| Typical source             | Analysis of a biological sample (DNA, RNA) | Fingerprint, iris, face, voice                 | Medical findings, lab values, diagnosis |
| Family relevance           | Yes, partly shared with relatives          | No (individual)                                | No (individual)                         |
| Standalone GDPR definition | Article 4(13)                              | Article 4(14)                                  | Article 4(15)                           |

## 3. Classification as a Special Data Category [#3-classification-as-a-special-data-category]

<Callout type="warn">
  Genetic data are special categories of personal data under Article 9(1) GDPR. Their processing is prohibited in principle. Processing is permitted only where one of the exhaustively enumerated exceptions in Article 9(2) GDPR applies, such as explicit consent, a substantial public interest or the necessity for medical purposes.
</Callout>

Article 9(4) GDPR gives Member States the option of introducing or maintaining, for genetic data, biometric data and data concerning health, additional conditions and limitations beyond the level of protection required under Union law ([Article 9(4) GDPR](https://dsgvo-gesetz.de/art-9-dsgvo/)). Germany has made use of this opening clause: the Gendiagnostikgesetz (GenDG) governs genetic testing and the handling of genetic data in medical, insurance and employment-law contexts ([GenDG](https://www.gesetze-im-internet.de/gendg/)). For an overview of the Member State opening clauses, see [1.3.12.3 Opening Clause for Member State Law](/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.3-oeffnungsklausel-fuer-mitgliedstaatliches-recht).

## 4. Special Feature in Criminal Proceedings [#4-special-feature-in-criminal-proceedings]

Criminal procedure law contains a sector-specific rule: under Section 81g(2) StPO, molecular genetic testing carried out as part of identification-service measures may be used exclusively to establish the DNA identification pattern and the sex of the data subject ([Section 81g StPO](https://www.gesetze-im-internet.de/stpo/__81g.html)). Any findings going beyond this are expressly impermissible. This limitation prevents DNA samples obtained in criminal proceedings from being used for further phenotypic or health-related analyses.

<Cards>
  <Card title="Article 4(13) GDPR" href="https://dsgvo-gesetz.de/art-4-dsgvo/" description="Full text of the legal definition of genetic data." />

  <Card title="Article 9 GDPR" href="https://dsgvo-gesetz.de/art-9-dsgvo/" description="Prohibition of processing and exceptions for special categories." />

  <Card title="Biometric Data" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.14-biometrische-daten" description="Article 4(14) GDPR: definition and distinction." />

  <Card title="Data Concerning Health" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.15-gesundheitsdaten" description="Article 4(15) GDPR: health-related data." />

  <Card title="Personal Data" href="/docs/dsgvo-hub/begriffe-und-definitionen/1.2.1-personenbezogene-daten" description="Article 4(1) GDPR: the basic term as the overarching category." />

  <Card title="Sensitive Data Categories" href="/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.1-sensible-datenkategorien" description="Overview of Article 9 GDPR: the system of special categories." />

  <Card title="Member State Opening Clause" href="/docs/dsgvo-hub/einzelthemen/besondere-kategorien-personenbezogener-daten/1.3.12.3-oeffnungsklausel-fuer-mitgliedstaatliches-recht" description="Article 9(4) GDPR: national supplementary rules." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.