Your wearable's health data isn't covered by the law you think protects it
An audit of 17 manufacturers' privacy policies found transparency the weakest area, with wide variation between brands. The data these devices generate largely falls outside HIPAA and GDPR's clinical protections.
The heart-rate, sleep, glucose and location data a consumer wearable collects is among the most intimate information a person generates — and in most jurisdictions it sits outside the laws that protect the same information when a doctor records it. Two 2026 reviews document the gap: an audit of 17 wearable manufacturers found transparency the weakest dimension of their privacy policies, and a review of glucose-monitor and health-app data concluded that consumer devices largely fall through the holes in the United States' HIPAA and the European Union's GDPR [s1][s2].
This is the mirror image of the regulatory story we told about the FDA's general-wellness guidance: the same "wellness device, not medical device" classification that frees a wearable from device review also frees the data it collects from clinical privacy rules.
What the policy audit found
A living systematic analysis in npj Digital Medicine evaluated the privacy policies of 17 leading wearable manufacturers against a rubric of 24 criteria across seven dimensions — transparency, data collection purposes, data minimisation, user control and rights, third-party sharing, security, and breach notification [s1]. High-risk ratings were most common for transparency reporting (76% of manufacturers) and vulnerability disclosure (65%) [s1]. Some areas fared better: identity policy was low-risk for 94% of manufacturers and data access for 71% [s1].
The variation between brands was wide. Xiaomi, Wyze and Huawei carried the highest cumulative risk scores, while Google, Apple and Polar ranked lowest [s1]. The authors' conclusion was that data governance is inconsistent across the industry and that sector-specific privacy standards are needed — the policies are not uniformly bad, but a buyer has little way to tell a careful custodian from a careless one without reading 24 criteria of fine print [s1].
Why the clinical laws don't reach it
The second review, focused on continuous glucose monitors and mobile health apps, explains the structural problem [s2]. HIPAA in the US governs data held by healthcare providers and their business associates; GDPR in the EU gives health data special-category protection. But consumer-grade devices and direct-to-consumer apps often operate outside the traditional healthcare data-protection frameworks entirely, leaving significant regulatory gaps [s2]. A glucose reading taken through a clinic is protected; the same reading taken through a wellness app a person bought themselves may not be, a tension that runs right through the direct-to-consumer glucose-monitor market.
Data ownership is the deeper ambiguity. The review notes that in most jurisdictions it is legally unsettled who owns wearable-generated health data, with patients, providers, manufacturers and app developers all holding competing claims [s2]. That unsettled ownership is what makes secondary use — repurposing the data for research or commercial ends — both possible and contested, raising questions about consent, de-identification and the boundary between care and commercial exploitation [s2].
What might close the gap
The glucose-monitor review points to emerging approaches that could reconcile data utility with individual rights: the European Health Data Space, and privacy-preserving techniques such as federated learning and differential privacy that let data be analysed without being centrally exposed [s2]. It recommends changes to regulation, industry practice and consent models rather than any single fix [s2]. The wearables audit, for its part, is designed as a living review precisely because policies change, and it argues for standards specific to the sector rather than reliance on general consumer law [s1].
The business model is the risk
Underneath the policy language is an incentive. A company that sells a device once has reason to build a recurring business on the data that device generates — subscriptions, analytics, partnerships — and the audit's finding that transparency and vulnerability disclosure were the weakest dimensions is consistent with an industry that treats data practices as a competitive matter rather than a disclosed one [s1]. The wide spread between the best- and worst-rated manufacturers reinforces that this is a choice, not a technical necessity: some firms scored low-risk on the same criteria where others scored high [s1].
The glucose-monitor review frames the sharpest version of the problem as secondary use — data collected for one purpose being repurposed for research or commercial ends [s2]. It notes this could genuinely advance care, which is what makes the governance question hard rather than one-sided: the same data that a company might sell could, under the right consent and privacy-preserving methods, improve the very conditions the devices are meant to help manage [s2]. The unresolved issue is who decides, and on what terms — and today, the review concludes, the answer is largely left to the fine print rather than the law [s2].
What it means for a user
Read a wearable's data practices as a purchasing decision, not an afterthought. The evidence shows brands differ sharply, that transparency is where they are weakest, and that the protection a person assumes from medical-privacy law generally does not apply to a consumer device [s1][s2]. The practical levers are the ones the policies expose: whether data is shared with third parties, whether it can be deleted, and whether the company discloses breaches — the dimensions the audit found most uneven [s1]. Until sector-specific standards exist, the safeguard is at the point of purchase and in the settings, because the law is not yet standing behind it.
Sources
- Privacy in consumer wearable technologies: a living systematic analysis of data policies across leading manufacturers — npj Digital Medicine , June 14, 2025
- Data Privacy, Ownership, and Secondary Use of Clinical Data Generated by Continuous Glucose Monitors and Mobile Health Applications: A Review — Journal of Diabetes Science and Technology , June 7, 2026
What consumer DNA health reports can predict — and the BRCA blind spot
23andMe's cleared BRCA report reads 3 of more than 1,000 mutations, so a negative result is not the all-clear it looks like — and the firm's bankruptcy has put customers' genetic data in play.
Wearables can estimate blood pressure without FDA review. They cannot say what it means
The FDA's revised general wellness policy lets non-invasive devices infer blood pressure, glucose and other physiologic parameters. The regulated line is no longer the measurement — it is the sentence next to it.
Remote patient monitoring is booming in Medicare. The evidence lags the billing
Medicare paid over $500 million for remote monitoring in 2024, but a watchdog found 43% of patients didn't get the full service — and rigorous evidence that it improves outcomes remains limited.
Patient portals help a little — and now test results reach patients before the doctor
Reviews find portals may improve awareness and the patient–doctor relationship, with unclear effect on efficiency. Under new US rules, patients now see 40% of results before their clinician does.