
Your smartwatch may look like a simple fitness tool, but every day it can build a detailed record of your routines, movements, and physical signals.
Depending on the device and services connected to it, that record can include heart rate, sleep patterns, exercise, location, weight, menstrual-cycle information, and other health-related details. Some platforms can also combine information entered manually with data collected from connected apps and devices.
The privacy question is not simply whether a watch collects data. It is what happens to that information after collection, what conclusions can be drawn from it, where it is stored, and who can receive it. A wearable can turn a stream of measurements into scores and predictions about a person's wellbeing.
Privacy rules also vary depending on the company, the service, and the country involved. In the US, many consumer health apps and fitness trackers are not covered by HIPAA, while UK data protection rules can treat health information, including certain inferences, as specially protected data.
What Your Wearable Can Learn About You
The most obvious information collected by a smartwatch is often the least surprising. Steps, exercise duration, heart rate and sleep information are now standard features across many wearable platforms.
Fitbit, for example, says its services can collect steps, distance, calories burned, heart rate, sleep stages and active minutes, alongside information supplied by users and data obtained from connected services.
The information can extendbeyond health measurements. Fitbit's current privacy policy says its services may also process account details, precise location when permission is granted, IP addresses, device identifiers, usage information and information received from connected third-party services.
Garmin similarly describes the processing of location information and activity data, such as routes, timestamps, elevation, speed, and distance, for compatible services.
Samsung's consumer health data statement goes further in describing the range of information that can enter its health ecosystem.
It includes bodily functions and vital signs, reproductive health information, health conditions, treatments, diagnoses, and medication information that users choose to store. The company also says it may process inferred or derivative information created through algorithms or machine learning.
That last category is important because the information generated by a wearable is not always a direct measurement.
'The most sensitive thing a wearable holds is usually not a reading. It is an inference,' said Benoit Tanguay, founder of Auromone, Montreal.
Tanguay points to the difference between a measurement and the conclusion a device makes from that measurement.
A watch can record heart rate and movement, for example, then use those signals to produce a stress or wellness score. The number displayed on the screen may look as definite as a step count, even though it is based on an interpretation of several pieces of information.
'Your watch does not measure your stress. It infers it, generally from heart rate and movement, and then presents the result as a finding,' Tanguay said. 'A step count is a fact about your body. A stress score is a claim about your mind, produced without your knowledge and kept with the same permanence as the step count.'
The distinction is also relevant to privacy law. The UK's Information Commissioner's Office says health data can include information that reveals something about a person's health, and its guidance on consumer Internet of Things products specifically notes that health information can be generated through inference.
It gives the example of a fitness tracker producing a wellness score from multiple measurements.
That does not mean every step count or heart-rate reading automatically receives the same legal treatment everywhere. Context matters. The ICO notes that a step count by itself may not reveal a person's health status, while the same information could become health data when combined with other measurements to produce an assessment of health.
For consumers, this means the data trail can be larger than the list of numbers visible on a watch face.
Who Can Access and Share The Data?
The next question is what happens once the information reaches the company operating the wearable's app or cloud service.
Privacy policies differ considerably. Fitbit's current policy says it does not sell users' personal information, while also describing circumstances in which information can be shared. These include situations where a user directs the company to share information, such as connecting a third-party application or participating in an employee wellness programme.
Google says health and wellness data from Fitbit users is not used for Google Ads. Its current Google Health privacy guidance also says that, following the move from Fitbit accounts to Google Accounts, Fitbit data associated with a Google Account is handled under Google's privacy framework.
Apple takes a different approach in several areas. It says HealthKit data is controlled through user permissions and that apps accessing health information must provide privacy policies. Apps using HealthKit are also prohibited from using or disclosing HealthKit data for advertising or data-mining purposes.
Apple also says that some health processing can happen on the device rather than being sent to a server. With appropriate security settings, the company says Health app data can be protected by end-to-end encryption in a way that prevents Apple from reading it.
Other manufacturers provide different choices. Samsung says consumer health information may be collected from devices, connected third-party apps and service providers, and says it may share consumer health data in circumstances described by its applicable privacy policies. It also provides rights to access and delete certain consumer health data.
Garmin, meanwhile, says some activity data can be shared with connected third-party websites when users link their Garmin Connect account to those services. Depending on the activity, that information can include performance measurements, location and heart-rate data.
The legal protections around this information are another reason consumers should not assume that a wearable is automatically treated like a doctor's office.
'When it comes to wearables, depending on the company, it can collect significant personal information like heart beat, sleep cycles, blood pressure, information that a user can add like specific medications, health conditions, menstrual cycles, and more.' said Jodi Daniels, Red Clover Advisors.
Daniels also highlighted a common misunderstanding about HIPAA in the US.
'A private company in many states can use this information however it wants to. It's most often not covered by HIPAA,' she said. 'Consumers often think that if it's health-related information that HIPAA applies, and that's just not true and a false sense of understanding.'
US Department of Health and Human Services guidance confirms that HIPAA does not generally apply to health information held by consumer apps that are not covered entities or business associates. Once information is sent, at the user's direction, to an app outside the HIPAA framework, the HIPAA protections may no longer apply to that information.
That does not mean consumer health information has no protection. The Federal Trade Commission's Health Breach Notification Rule applies to certain companies outside HIPAA and was updated to clarify its application to health apps, connected devices, and similar technologies.
There have also been enforcement cases showing why privacy policies matter. The FTC said Flo Health shared sensitive health information with marketing and analytics companies, including Facebook and Google, despite promises to keep the information private. The resulting settlement required affirmative consent before certain future sharing.
The issue is not confined to the US. Under the UK GDPR, health information is classed as special category data and receives additional protection. The ICO also states that inferences about health can fall within that category, depending on the circumstances.
For users, one of the most important questions is therefore not simply whether a company 'sells' data. It is whether information is shared with service providers, connected apps, research programmes, advertisers, employers, insurers or other organisations, and under what conditions.
'Consumers really need to read the company privacy policy, FAQ section and consider carefully what information it's sharing with a wearable,' Daniels said.
Tanguay recommends asking similarly direct questions about where the information is stored and how closely it is tied to a person's identity.
'Where the data physically lives, because jurisdiction decides who can compel access to it,' Tanguay said. 'And whether the health record sits linked to a name and email or is held apart from it, because that decides what a breach actually exposes.'
Deletion is another issue worth checking. Tanguay argues that consumers should ask what happens not only to the original readings but also to information derived from them.
'If a user erases their readings but the derived profile survives, or the model trained on those readings survives, they have not actually left,' Tanguay said.
Different companies offer different deletion and data-management tools. Garmin says users can access, export, correct or delete their data through its account-management system. Samsung provides mechanisms for users to request access and deletion of consumer health data, while Google says users can manage, export and delete information associated with its health services.
That leaves smartwatch owners with a practical lesson: the privacy question starts before the watch is put on the wrist. Checking what a device collects, which permissions it requests, what its app connects to, where information is stored and what happens when an account is deleted can reveal far more than the marketing description of a fitness feature.
A smartwatch may only show a handful of numbers at a time, but the information behind those numbers can tell a much fuller story about its wearer. The more useful question is therefore not simply whether the device is watching, but what it can infer, who can receive those inferences, and how long they remain part of your digital record.
Frequently Asked Questions
- What kind of data can a smartwatch collect?A smartwatch can collect data such as heart rate, sleep patterns, exercise, location, weight, menstrual-cycle information, and other health-related details.
- How is the data from smartwatches used?The data can be used to generate scores and predictions about a person's wellbeing, and it may be shared with third-party services depending on the privacy policy of the company.
- Are smartwatches covered by HIPAA in the US?Many consumer health apps and fitness trackers are not covered by HIPAA, meaning the data may not have the same protections as information held by healthcare providers.
- What should consumers consider regarding smartwatch data privacy?Consumers should read the privacy policy, understand what data is collected, how it is shared, and what rights they have to access and delete their data.




