Tag: health app data privacy uk

  • Data Brokers, Health Apps and Your Medical Privacy: What UK Law Says and What It Fails to Prevent

    Data Brokers, Health Apps and Your Medical Privacy: What UK Law Says and What It Fails to Prevent

    Most people assume that because a health app is on their phone, and because they vaguely clicked “I agree” at some point, their data is reasonably safe. It is not. Health app data privacy in the UK sits in a genuinely uncomfortable gap between legislation that sounds robust and enforcement that has, so far, been remarkably light. I’ve spent time digging through ICO decisions, GDPR guidance and academic research on this, and the picture is not reassuring.

    Woman reviewing health app data privacy settings on her smartphone
    Photo by Lisa Fotios on Pexels

    What counts as health data under UK GDPR?

    Under the UK GDPR, health data is classed as “special category” data, meaning it attracts stronger legal protections than ordinary personal data. The definition is broader than most people realise. It covers data relating to the physical or mental health of a natural person, including information that reveals their health status. That language matters because it pulls in inferred data, not just data you consciously entered.

    A period tracker that records your cycle dates is processing health data. A fitness app that logs your resting heart rate over time could reveal a cardiac condition. A sleep app that notices you are waking at 3am every night is generating a dataset from which mental health inferences can reasonably be drawn. The app companies know this. What their privacy policies often obscure is what happens to that data after it leaves your phone.

    How health apps actually monetise your data

    The phrase “we may share your data with trusted third parties” is doing a lot of heavy lifting. In practice, the data supply chain from a consumer health app can involve advertising technology platforms, data analytics firms, research organisations and, yes, data brokers who aggregate and resell profiled datasets. The legal mechanism that makes much of this possible is “legitimate interests” under Article 6 of the UK GDPR, combined with consent that was obtained through a consent management platform buried three taps deep in settings.

    Period and cycle tracking apps have received particular scrutiny. A 2021 investigation by Privacy International found that several popular apps were sharing intimately personal data with Facebook’s advertising SDK at the point of app launch, before users had any chance to interact with a consent screen. Some of those apps are still widely used in the UK. The ICO acknowledged concerns about advertising technology broadly in its 2019 report on real-time bidding, but substantive enforcement against health-specific apps has been sparse.

    Digital lock icon representing health app data privacy UK concerns
    Photo by Ann H on Pexels

    What the ICO has and has not enforced

    The ICO has real powers. Under the UK GDPR and the Data Protection Act 2018, it can issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher. It has used those powers against companies including British Airways and Marriott, though both fines were substantially reduced on appeal. For health app data privacy in the UK specifically, the enforcement record is thin.

    The ICO published its adtech and real-time bidding work and has issued guidance on special category data, but formal enforcement notices specifically targeting consumer health apps or data brokers handling inferred health data remain rare. The regulator has cited resource constraints and the complexity of cross-border enforcement as factors. That is an honest answer, but it leaves a real gap.

    There was a significant moment in 2023 when the ICO issued a reprimand to Snap over its My AI feature, touching on children’s data risk assessments. That reprimand, rather than a fine, illustrated the regulator’s tendency to use softer tools first. For people whose period tracking data or mental health journal entries have already been shared with third parties, a reprimand issued years later feels inadequate.

    The specific risks from period trackers, mental health apps and symptom diaries

    Period trackers carry risks that go beyond embarrassment. Inferred fertility status, pregnancy history or menstrual irregularities can be of interest to insurance underwriters, employers and, in some jurisdictions, law enforcement. UK law offers some protection here: the Equality Act 2010 prohibits discrimination on grounds of pregnancy and maternity, and using health data to discriminate in insurance pricing is tightly restricted by the FCA. But data shared with a broker in a third country, processed under a different legal framework, is much harder to protect.

    Mental health apps sit in a similarly fraught position, and I’d argue they carry the highest reputational risk for the sector. Someone using a mood diary, anxiety tracker or cognitive behavioural therapy app is generating a longitudinal record of their psychological state. If that record is accessible to a data broker, it can be used to build a profile that follows a person across the web. As I covered in an earlier piece on the UK’s mental health app regulation gap, many of these apps operate without any meaningful clinical oversight, which compounds the data problem: there is no regulatory body with clear authority over both the therapeutic claims and the data practices simultaneously.

    Symptom diary apps, the kind people use to track chronic pain, digestive flares, fatigue levels and medication responses, present a third category of risk. These are often used by people with conditions like IBD, ME/CFS or long-term post-viral illness, populations that are already under-served by the NHS and more likely to turn to digital tools to fill the gap. The data generated is clinically detailed. Whether it is being treated with the care that implies is a question most app privacy policies answer evasively.

    What you can actually do right now

    Audit the permissions your health apps hold. On an iPhone, go to Settings, then Privacy and Security; on Android, go to Settings, then Apps, then Permissions. Revoke location and advertising ID access from any health app that does not have an obvious clinical reason to need it. Check whether the app offers an opt-out from data sharing with third parties, and assume the default is opt-in unless you can confirm otherwise.

    Look at where the company is based. An app with a UK company registration and a data protection officer listed on its website is meaningfully more accountable under UK GDPR than one incorporated in a jurisdiction with no equivalent law. You can check company registrations at Companies House in under two minutes.

    Some people navigating health monitoring, especially around recovery, wellness and longevity goals, are also shifting towards hardware and offline supplementation rather than app-based tracking. Based in Nottinghamshire, HealthPod Mansfield supplies hyperbaric oxygen tanks, red light therapy beds and supplements to people who want to actively support their health and live longer without necessarily feeding their data into a subscription app ecosystem. The core appeal for wellness-conscious users is straightforward: you can pursue recovery and health goals using physical equipment at healthpodonline.co.uk without generating a behavioural dataset that a third party can monetise. That is a real consideration, not a minor one.

    The gap that UK law has not closed

    The fundamental problem is that UK GDPR requires lawful basis and transparency, but it does not require that consent be genuinely informed in any meaningful cognitive sense. A 4,000-word privacy policy that mentions data sharing in paragraph 23 is technically transparent. It is not practically transparent. The ICO’s guidance on consent emphasises that it must be freely given, specific, informed and unambiguous, but auditing whether those conditions are met across thousands of consumer apps is not something the regulator currently has the capacity to do systematically.

    There is also the inferred data problem. UK GDPR protects health data you actively input. The question of whether inferred health data, a score calculated from your sleep patterns and heart rate variability that predicts your likelihood of depression, is equally protected is not yet definitively settled in UK case law. The ICO’s position is that inferred data can be special category data if it reveals health information, but that position has not been tested in a major enforcement case specifically targeting consumer health apps.

    People who use apps to manage their health deserve clarity. The current framework provides a legal structure that looks protective but has meaningful gaps in practice. Pushing for stronger enforcement, and being more selective about which apps get access to the most sensitive data you generate, are the two most practical responses available right now. For anyone interested in how digital health tools interact with your personal data more broadly, the NHS waiting list and the self-diagnosis trap piece covers some of the downstream risks when people turn to unregulated tools to fill care gaps, and it is worth reading alongside this one.

    HealthPod Mansfield, known in Nottinghamshire for supplying red light beds and recovery-focused supplements alongside hyperbaric oxygen equipment, represents one end of the spectrum: people choosing be healthy through tangible, offline means rather than through apps that ask for extensive data permissions. Whether or not that approach appeals to you, the underlying instinct to question what health tools actually do with what they learn about you is one more people should develop.