Source code Security & compliance

Special-category / financial PII unprotected

Part of the GDPR & privacy check · fix arrives as a guide

What it is

Columns holding special-category data under GDPR — health, biometric, racial or ethnic origin, political or religious belief, sexual orientation — or financial data, are stored without additional protection.

Why it matters

Article 9 sets a higher bar for these categories, and supervisory authorities weight breaches involving them accordingly. Storing them like ordinary columns means they inherit only whatever protection the table already had.

How to fix it

Confirm you have a lawful basis for holding each category, then add column-level encryption or tokenisation and restrict access to the roles that genuinely need it. Where the data is not necessary, deleting it removes the obligation.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.