Special-category / financial PII unprotected
Part of the GDPR & privacy check · fix arrives as a guide
What it is
Columns holding special-category data under GDPR — health, biometric, racial or ethnic origin, political or religious belief, sexual orientation — or financial data, are stored without additional protection.
Why it matters
Article 9 sets a higher bar for these categories, and supervisory authorities weight breaches involving them accordingly. Storing them like ordinary columns means they inherit only whatever protection the table already had.
How to fix it
Confirm you have a lawful basis for holding each category, then add column-level encryption or tokenisation and restrict access to the roles that genuinely need it. Where the data is not necessary, deleting it removes the obligation.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.