EXPLAINER

Your wearable's health data isn't covered by the law you think protects it

An audit of 17 manufacturers' privacy policies found transparency the weakest area, with wide variation between brands. The data these devices generate largely falls outside HIPAA and GDPR's clinical protections.

The heart-rate, sleep, glucose and location data a consumer wearable collects is among the most intimate information a person generates — and in most jurisdictions it sits outside the laws that protect the same information when a doctor records it. Two 2026 reviews document the gap: an audit of 17 wearable manufacturers found transparency the weakest dimension of their privacy policies, and a review of glucose-monitor and health-app data concluded that consumer devices largely fall through the holes in the United States' HIPAA and the European Union's GDPR [s1][s2].

This is the mirror image of the regulatory story we told about the FDA's general-wellness guidance: the same "wellness device, not medical device" classification that frees a wearable from device review also frees the data it collects from clinical privacy rules.

What the policy audit found

A living systematic analysis in npj Digital Medicine evaluated the privacy policies of 17 leading wearable manufacturers against a rubric of 24 criteria across seven dimensions — transparency, data collection purposes, data minimisation, user control and rights, third-party sharing, security, and breach notification [s1]. High-risk ratings were most common for transparency reporting (76% of manufacturers) and vulnerability disclosure (65%) [s1]. Some areas fared better: identity policy was low-risk for 94% of manufacturers and data access for 71% [s1].

The variation between brands was wide. Xiaomi, Wyze and Huawei carried the highest cumulative risk scores, while Google, Apple and Polar ranked lowest [s1]. The authors' conclusion was that data governance is inconsistent across the industry and that sector-specific privacy standards are needed — the policies are not uniformly bad, but a buyer has little way to tell a careful custodian from a careless one without reading 24 criteria of fine print [s1].

Why the clinical laws don't reach it

The second review, focused on continuous glucose monitors and mobile health apps, explains the structural problem [s2]. HIPAA in the US governs data held by healthcare providers and their business associates; GDPR in the EU gives health data special-category protection. But consumer-grade devices and direct-to-consumer apps often operate outside the traditional healthcare data-protection frameworks entirely, leaving significant regulatory gaps [s2]. A glucose reading taken through a clinic is protected; the same reading taken through a wellness app a person bought themselves may not be, a tension that runs right through the direct-to-consumer glucose-monitor market.

Data ownership is the deeper ambiguity. The review notes that in most jurisdictions it is legally unsettled who owns wearable-generated health data, with patients, providers, manufacturers and app developers all holding competing claims [s2]. That unsettled ownership is what makes secondary use — repurposing the data for research or commercial ends — both possible and contested, raising questions about consent, de-identification and the boundary between care and commercial exploitation [s2].

What might close the gap

The glucose-monitor review points to emerging approaches that could reconcile data utility with individual rights: the European Health Data Space, and privacy-preserving techniques such as federated learning and differential privacy that let data be analysed without being centrally exposed [s2]. It recommends changes to regulation, industry practice and consent models rather than any single fix [s2]. The wearables audit, for its part, is designed as a living review precisely because policies change, and it argues for standards specific to the sector rather than reliance on general consumer law [s1].

The business model is the risk

Underneath the policy language is an incentive. A company that sells a device once has reason to build a recurring business on the data that device generates — subscriptions, analytics, partnerships — and the audit's finding that transparency and vulnerability disclosure were the weakest dimensions is consistent with an industry that treats data practices as a competitive matter rather than a disclosed one [s1]. The wide spread between the best- and worst-rated manufacturers reinforces that this is a choice, not a technical necessity: some firms scored low-risk on the same criteria where others scored high [s1].

The glucose-monitor review frames the sharpest version of the problem as secondary use — data collected for one purpose being repurposed for research or commercial ends [s2]. It notes this could genuinely advance care, which is what makes the governance question hard rather than one-sided: the same data that a company might sell could, under the right consent and privacy-preserving methods, improve the very conditions the devices are meant to help manage [s2]. The unresolved issue is who decides, and on what terms — and today, the review concludes, the answer is largely left to the fine print rather than the law [s2].

What it means for a user

Read a wearable's data practices as a purchasing decision, not an afterthought. The evidence shows brands differ sharply, that transparency is where they are weakest, and that the protection a person assumes from medical-privacy law generally does not apply to a consumer device [s1][s2]. The practical levers are the ones the policies expose: whether data is shared with third parties, whether it can be deleted, and whether the company discloses breaches — the dimensions the audit found most uneven [s1]. Until sector-specific standards exist, the safeguard is at the point of purchase and in the settings, because the law is not yet standing behind it.

Sources

  1. Privacy in consumer wearable technologies: a living systematic analysis of data policies across leading manufacturersnpj Digital Medicine , June 14, 2025
  2. Data Privacy, Ownership, and Secondary Use of Clinical Data Generated by Continuous Glucose Monitors and Mobile Health Applications: A ReviewJournal of Diabetes Science and Technology , June 7, 2026
Related coverage