Apply the harm test, not only the examples
Article 28's examples are representative categories, not a complete field dictionary. Classify the actual information and processing context by asking whether leakage or illegal use could readily cause either kind of statutory harm. A field that looks ordinary in isolation may become sensitive when combined with other data or used to infer health, identity, movements, finances, or another protected condition.
The category includes all personal information of a child under 14, even if the same field would not be sensitive for an adult. For example, a child's basic account identifier falls within the child-specific rule because of the person's age.
- Biometric identification, religious belief, and specific identity are express statutory examples; record the exact information and how it is used.
- Medical and health information and financial account information are express statutory examples; apply the harm test to the fields, inferences, and processing context.
- Location-tracking information is an express statutory example; record what the information reveals, how long it is retained, and who can access it.
- Other information can qualify when it meets the statutory harm test even if it does not fit one of the named examples.
Article 28 supplies the harm test, representative categories, and the rule for children under 14.