Guides for HR and Corporate Health
Employee wearables and health data: privacy questions
Connecting a device does not provide unrestricted access to personal data. The purpose, lawful basis, recipients and actual reporting determine what is appropriate.
Quick answer
Can employers use wearable data?
There is no blanket permission. Personal data requires an appropriate lawful basis; health data is also subject to Article 9 GDPR. The dependence inherent in employment makes voluntary consent difficult. Review the specific data flow with your data protection specialists and ask whether the employer needs personal data at all.
Distinguish the device, platform and employer
Map the flow: what data is generated on the device? What reaches the platform through a connected service? What can the individual, a challenge team and an administrator see? A technical connection does not establish who is entitled to receive data.
With FIT-UP, employers cannot see personal health data; reporting uses aggregated results. Still, discuss the specific scope, roles and protection for small groups before rollout. Connecting a wearable does not give the employer access to its entire history.

Assess the legal basis against the specific purpose
The European Data Protection Board explains that sensitive data requires additional conditions alongside a lawful basis. Health data is included. Whether activity data reveals health in a particular context depends on how it is used and combined. Data types cannot always be classified independently of context.
The Board also emphasizes the difficulty of voluntary consent in an employment relationship. A checkbox alone does not resolve this. Review applicable national employee data protection rules and employee representation. The legal assessment concerns the actual project, not just the software’s name.
- Document the purpose and necessary data before launch.
- List data categories, recipients and lawful bases separately.
- Arrange non-participation and withdrawal without disadvantages.
- Have specialists assess whether a data protection impact assessment is required.
Questions for a data flow review
This table supports a discussion. Record answers with the people responsible and add unresolved points. State which details still need technical or legal review. An unanswered question should not be replaced by a general statement such as “it is anonymous”.
| Area | Question to resolve |
|---|---|
| Access | Who needs which role, and how is access revoked? |
| Connections | Which services are connected and which data is transferred? |
| Purpose | Do we need this information for the agreed activity? |
| Retention | When is data deleted and how is withdrawal implemented? |
| Evaluation | Could filters, small teams or free text make individuals identifiable? |
| Information | How will employees learn about data flows and their rights before joining? |
Aggregated does not automatically mean anonymous
A group result may identify someone when the group is very small or when filters and time periods can be combined. Define reporting rules and safeguards before use. This guide does not prescribe a universal minimum group size that automatically makes every report safe.
Workplace wellbeing reporting often needs information about access and use rather than private measurements. Separate organizational decisions from health data and explain the actual reporting to employees. Confirm FIT-UP integrations and reporting scope during the technical review.
- Do not use personal measurements for performance reviews.
- Do not expose small groups through freely combinable filters.
- Do not reuse existing data for another purpose without a fresh assessment.
Scope and limitations
- This page provides general review questions, not legal advice for a specific workplace.
- Pseudonymized data remains personal data. Anonymity must be assessed against the actual possibility of reidentification.
Frequently asked questions
Is every step count health data?
Classification depends on context and use. Assess whether the information alone, or combined with other data, reveals health.
Is employee consent sufficient?
Not automatically. Voluntary participation, purpose, information and additional requirements for health data must be assessed in the specific case.
Can HR analyze individual HRV or sleep measurements?
A general wellbeing program does not establish such access. Personal health data is not a tool for performance assessment; have specialists review any specific processing purpose.
Are aggregated reports always anonymous?
No. Small groups, filters and combined information can make people identifiable. Reporting rules must account for that context.
Explore related insights
Sources
- European Data Protection Board: Lawful processing and sensitive data
- European Data Protection Board: Guidelines 05/2020 on consent
- GDPR: Articles 5, 6 and 9, and Recital 43 in particular
Published by FIT-UP GmbH, Linz, Austria — a Corporate Health platform provider for organizations in Austria and Germany. Last updated: 2026-10-04.
Your needs. The right combination.
The entire FIT-UP platform is modular. We discuss which digital offers, on-site services and personal support fit your organization.