DPE-2026-0019

Special-category data in an event

An event sent to a third party reveals health, belief or sexuality through its name, path or parameters.

In het NederlandsBijzondere gegevens in een gebeurtenisWat vraag ik hierover, en hoe herken ik een ontwijkend antwoord?
Data webapp status active
Not a vulnerabilityNothing is exploited. The event is defined by the builder and fires as intended; what it discloses is a consequence of how it was named and what was attached to it.

What it is

A measurement or advertising component sends structured events. The event name, the address of the screen or page it fired on, or a parameter attached to it corresponds to something the person did that falls in a special category: a symptom logged, a condition read about, a support group opened, a triage question answered. No free text is needed; the label alone carries the meaning.

Why it is a separate entry

The person filled in a questionnaire or read a page, not a disclosure form. What reaches the recipient is a categorised fact about their health, belief or sexuality, attached to an identifier, in a stream built to be joined with other streams. Unlike a sentence in a message, a labelled event is immediately machine-usable.

How it arises

Not to be confused with

Text the person typed appearing verbatim in a request is User input to third parties. Here nothing typed needs to travel: the name of the event or the address of the screen is enough. Ordinary page-view measurement on a neutral page is also not this entry; what makes it one is that the value maps to a special category.

How to establish it

A request to a host under a different registrable domain containing an event name, screen address or parameter value that corresponds to a special category, alongside an identifier. The correspondence must be readable from the value itself, not inferred from context.

method network-with-identifierQoD 88

Requirements on the measurement

What would refute it

Where this plugs into existing processes

The one question that surfaces itPrint the list of event names you send outside the organisation and read it out loud.
In a DPIA, verify this

Verify the actual event names and screen addresses that leave, against the categories the assessment claims are not processed.

As a procurement clause

No event name, screen address or parameter transmitted to a third party discloses a special category, verified from a capture of a representative walkthrough.

With a complaint, hand over

A capture of a deliberate walkthrough, the events it produced, and the mapping from each value to the action that caused it.

Reproduction

Legal framing

Objections, and the answer

“We do not send health data, only usage statistics.”

The category follows from the content of the message, not from the label on the pipeline. An event named after a symptom is data about health however the stream is described internally.

“The data is pseudonymous.”

It travels with an identifier, which is what makes it useful to the recipient. The prohibition in the regulation is not lifted by pseudonymisation.

“The recipient is in the EU.”

That answers a different question. A special category reaching a party that has no role in the care or the service is the finding, wherever that party sits.

What this does not establish

Related

How to cite this entry

In text
DPE-2026-0019 (Special-category data in an event)
URL
https://totaledigitalewaarborging.nl/register/DPE-2026-0019
Machine
https://totaledigitalewaarborging.nl/register/DPE-2026-0019/index.json
Full
DPE Catalogue. DPE-2026-0019: Special-category data in an event. Schema 2.0, entry status active. Retrieved from https://totaledigitalewaarborging.nl/register/DPE-2026-0019
Measurement
When you publish a finding, cite the method version alongside the entry: “DPE-2026-0019, established under DPE Measurement Method 1.0”

Identifiers are permanent and are never reused. An entry that is deprecated keeps its number and its address, with the reason attached, because references to it exist elsewhere.