What your smartwatch knows about your health, who can see it, and how to lock it down in three steps

Your smartwatch records heart rate, sleep, blood oxygen, location and in some cases the menstrual cycle. This is what UK GDPR actually covers, what a peer-reviewed 2025 analysis of seventeen manufacturers found about their published data policies, and the three settings that remove most of your exposure in five minutes.
This guide contains affiliate links. As an Amazon Associate, m8d.io earns from qualifying purchases, at no extra cost to you.
Your watch does not count steps. It narrates you: when you sleep, when you are under strain, which streets you run down every morning and, on some of them, when you have your period.
The uncomfortable question of 2026 is not how many calories you burned. It is who else is reading all of that.
The short version: smartwatches record heart rate, sleep, blood oxygen, temperature, location and in some cases the menstrual cycle. Under UK GDPR that is special category data, and processing it is prohibited by default unless a specific condition applies. The gap is not the law: it is that almost every watch syncs it to a manufacturer's cloud, and a 2025 peer-reviewed analysis of 17 manufacturers found the industry's weakest point is telling you what happens to it. Apple states its health data is end-to-end encrypted, Garmin does not make its money from your data, and the cheapest devices almost always send everything off the wrist.
What your wrist actually records
A modern watch does not measure one thing: it builds a portrait of your body around the clock. This is what most of them capture without you thinking about it:
Each one on its own looks harmless. Together, over months, they are a profile worth money to a lot of people who are not you.
In 2018 the public heatmap published by Strava unintentionally revealed the location and the patrol routes of classified military bases. All it took was the running routes of the soldiers wearing their watches. A sports app, a location field and a state secret in the open. Your daily routine says the same kind of thing about you.
Who can see it (and why the law does not protect you the way you think)
Most people assume the data on their watch is as protected as their medical record. In the United Kingdom the legal position is genuinely strong on paper: under Article 9 of the UK GDPR, data concerning health is a special category and its processing is prohibited by default unless one of the listed conditions applies, and the Information Commissioner's Office is the body that enforces it. The condition almost every manufacturer relies on is your explicit consent, which you gave when you accepted forty pages of terms without reading them.
And the same framework catches you the other way round, as the person doing the collecting rather than the person collected. Point a camera at anything beyond your own front door and you become the data controller. That is not a hypothetical for anyone in a flat: it is what happens the moment a WiFi peephole camera can see the communal hallway, and we set out what the published ICO guidance actually requires of you in that guide. The same test applies to every other camera on the house, and we take it apart in full, with the three duties and the buying criterion nobody lists, in our comparison of cameras that record without a subscription.
That is where the protection actually leaks, and it is not a British problem. A 2025 peer-reviewed systematic analysis of the data policies of 17 wearable manufacturers, published in a medical journal and linked in full below, found that the highest-risk area across the whole industry was transparency reporting, rated high risk for 76 per cent of the companies examined, followed by vulnerability disclosure at 65 per cent. In plain terms: the thing these companies are collectively worst at is telling you what happens to your data. The same paper concludes that the existing legal frameworks "were not designed to address the continuous data streams, complex third-party ecosystems, and pervasive data collection intrinsic to wearable technologies".
Where does your data go? Ranked by the 2025 study
Not every watch treats your privacy the same way, and here the honest thing to do is hand you somebody else's numbers rather than our opinion. The systematic analysis cited above scored 17 manufacturers on their published data policies, where a lower score is a lower risk. These are its results for the brands you are most likely to be choosing between:
| Brand | What the 2025 analysis found | Risk rating |
|---|---|---|
| Google and Fitbit | The lowest overall risk score of the 17 examined, at 33 | Low risk |
| Apple | Also rated a low-risk performer, and it states health data synced to its cloud is end-to-end encrypted | Low risk |
| Garmin | Among the 17 reviewed; its business is selling watches rather than advertising | Middle |
| Huawei | Among the highest risk in the study, with 14 high-risk ratings | Higher risk |
| Xiaomi | The highest overall risk score of the 17, at 60 | Highest risk |
Scores from the 2025 systematic analysis of manufacturers' published data policies linked in the sources, consulted on 30 August 2026, where a lower score is a lower risk. It measures what each company publishes about its data practices, not the quality of the watch, and not what actually happens inside the company. We have corrected an earlier version of this table, which placed Fitbit among the most permissive: the study it referred to reports the opposite.
If you are going to buy one, these handle it better
A good watch does not have to watch you back. These four cover the range, from the one that locks your data down hardest to the honest way of shrinking how much there is to lock down at all:




The fourth card is deliberately not the cheapest watch we could find. The cheapest way to reduce your exposure is to buy a device that measures less, and a band with no GPS of its own never builds the map of your week in the first place. That is a privacy argument, not a price one.
How to lock down your watch in 3 steps
You do not have to throw the watch away. These three settings remove most of the exposure in five minutes:
- Revoke what it does not need. In the watch's app, take location off "always" and set it to "while using", then turn off third-party data sharing and advertising personalisation.
- Turn GPS off when you are not training. It is the most delicate field of the lot. If you only switch it on to run, you stop broadcasting the map of your daily life.
- Use your UK GDPR rights. Ask in the app for an export and an erasure of your history. They are obliged to provide both. Do it once a year, and remember that the point of the erasure is not the file you get back, it is what stops being held.
If reading where your metrics end up has you wanting a device that measures less and sends less, a fitness tracker covers steps, sleep and heart rate without the data surface of a full watch.
Best fitness tracker 2026 ›Frequently asked questions
- Privacy in consumer wearable technologies: a living systematic analysis of data policies across leading manufacturers, Doherty, Baldwin, Lambe, Altini and Caulfield, 2025. Seventeen manufacturers scored on their published data policies. Consulted on 30 August 2026: it is the source of the brand table, of the 76 per cent on transparency reporting and of the 65 per cent on vulnerability disclosure.
- UK GDPR, Article 9: processing of special categories of personal data, legislation.gov.uk. The official text: data concerning health is one of the categories whose processing is prohibited by default unless a specific condition applies. Consulted on 30 August 2026.
Comments
Be the firstNo sign-up: just a name. Every comment is reviewed before it is published.
