Civil Law And Wearable Bio-Sensor Data Misuse Litigation In Europe .

Civil Law and Wearable Bio-Sensor Data Misuse Litigation in Europe

1. Introduction

Wearable bio-sensor data misuse litigation concerns disputes arising from the collection, analysis, disclosure, sale, sharing, or other misuse of information generated by wearable devices such as:

smartwatches;

fitness trackers;

continuous glucose monitors;

heart-rate monitors;

sleep trackers;

smart rings;

connected medical devices;

biometric fitness devices;

rehabilitation sensors;

connected sports equipment.

These devices can generate extremely detailed information about a person, including:

heart rate;

heart-rate variability;

blood oxygen levels;

sleep patterns;

body temperature;

glucose levels;

physical activity;

location;

menstrual-cycle information;

stress indicators;

respiratory patterns;

ECG information;

biometric identifiers;

inferred health conditions.

The legal problem is therefore considerably broader than ordinary data theft. A wearable may continuously generate information that, individually or when combined with other information, can reveal a person's physical or mental health status.

Under European law, this can trigger the enhanced protection applicable to special categories of personal data, particularly health data. The CJEU has adopted a broad approach: information can qualify as health data where it is capable of revealing health status through deduction or combination with other information. (EUR-Lex)

Wearable-data litigation consequently sits at the intersection of:

contract law;

tort/delict law;

data-protection law;

consumer protection;

medical-device regulation;

privacy and personality rights;

confidentiality;

cybersecurity;

product liability; and

fundamental rights.

2. What Is Wearable Bio-Sensor Data?

A wearable device may collect two broad categories of information.

A. Directly observed information

Examples include:

pulse rate;

body temperature;

blood oxygen;

glucose level;

movement;

GPS location.

B. Inferred information

Algorithms may use sensor data to infer:

stress;

sleep disorders;

cardiovascular conditions;

pregnancy;

fertility;

physical fitness;

emotional states;

potential disease;

behavioural patterns.

The second category is particularly important.

A company may argue:

"We never collected a diagnosis."

But if its algorithm uses heart-rate, sleep and activity data to infer a person's medical condition, the resulting information can potentially fall within the GDPR's broad concept of health data.

The CJEU has confirmed that information capable of revealing health status through an intellectual operation involving collation or deduction may constitute health data. (EUR-Lex)

3. Why Wearable Data Is Legally Sensitive

Wearables can create a continuous record of a person's life.

For example, a smartwatch might reveal:

02:15 — heart rate increased
02:17 — movement detected
02:30 — sleep interrupted
03:00 — elevated heart rate
06:45 — exercise commenced

Over weeks or months, such information can create a highly detailed behavioural and health profile.

The European Data Protection Board recognises health information as highly sensitive and subject to enhanced protection under the GDPR. (European Data Protection Board)

The legal concern is therefore not merely:

"Who owns the smartwatch?"

but:

Who controls the information generated by the smartwatch, for what purpose, on what legal basis, and with what safeguards?

4. Principal Legal Framework

The central European instrument is the General Data Protection Regulation (GDPR).

Important provisions include:

Article 4

Defines:

personal data;

processing;

controller;

processor;

health data.

Article 5

Establishes principles including:

lawfulness;

fairness;

transparency;

purpose limitation;

data minimisation;

accuracy;

storage limitation;

integrity and confidentiality.

Article 6

Requires a lawful basis for processing personal data.

Article 9

Provides enhanced protection for special categories, including health data.

Articles 12–14

Concern transparency and information.

Articles 15–22

Provide rights including:

access;

rectification;

erasure;

restriction;

portability;

objection;

rights relating to automated decision-making.

Article 25

Requires data protection by design and by default.

Article 32

Requires appropriate security measures.

Article 35

Can require a Data Protection Impact Assessment for high-risk processing.

Article 82

Provides compensation for material and non-material damage resulting from GDPR infringement.

5. Health Data Under Article 9

Article 9 establishes a general prohibition on processing special-category data, subject to specified exceptions.

For wearable companies, potentially relevant exceptions include:

explicit consent;

employment/social-security situations where legally authorised;

vital interests;

healthcare;

public-health purposes;

scientific research under applicable safeguards.

The important point is that ordinary consent to use a wearable does not automatically authorise every possible secondary use of the resulting health data.

A company may therefore face difficulty arguing:

"The customer agreed to the terms and conditions, so we can use all sensor information for advertising."

The lawful basis and the specific purpose of processing must be examined.

6. Case Law 1 — Lindenapotheke, C-21/23

ND v DR (Lindenapotheke), CJEU, Grand Chamber, 4 October 2024

This is one of the most important recent CJEU decisions for wearable-data litigation.

Facts

A German pharmacist sold medicinal products through an online platform.

Customers provided information including:

name;

delivery address;

information about medicines ordered.

A competing pharmacist challenged the processing.

Legal issue

The CJEU considered whether the information could constitute health data under Article 9 GDPR.

Judgment

The Court adopted a broad interpretation of health data.

Information may qualify as health data if it can reveal information concerning an identifiable person's health through deduction or combination.

The Court emphasised that the enhanced protection cannot be avoided simply because the information is not itself a medical diagnosis. (EUR-Lex)

Importance for wearables

This principle is directly relevant to:

heart-rate information;

sleep information;

glucose measurements;

menstrual-cycle data;

exercise patterns;

physiological measurements.

For example:

A wearable company records sleep and heart-rate data. An algorithm concludes that a user may suffer from a particular health condition.

The resulting inference may receive enhanced GDPR protection.

7. Case Law 2 — Vyriausioji tarnybinės etikos komisija, C-184/20

CJEU, 1 August 2022

This case concerned publicly disclosed information that could indirectly reveal sensitive personal information.

Principle

The CJEU interpreted the concept of special-category data broadly and stressed that information indirectly capable of revealing sensitive information can fall within enhanced protection. (curia)

Importance for wearables

Wearable companies frequently argue that certain individual measurements are harmless.

But consider:

resting heart rate;

sleep patterns;

location at a hospital;

exercise frequency;

medication reminders.

Individually, each item may appear innocuous.

Combined together, they can reveal:

"This individual may have a particular health condition."

The CJEU's reasoning therefore strongly supports examining what the data reveal when combined, rather than looking at each sensor measurement in isolation.

8. Case Law 3 — Meta Platforms and Others, C-252/21

CJEU, 4 July 2023

This major case concerned processing of personal data by Meta and the relationship between GDPR requirements, consent and other legal bases.

Importance

The CJEU stressed the strict requirements governing lawful processing and the special protection applicable to sensitive information.

It is particularly relevant to situations where a company attempts to justify extensive data processing through broad contractual terms or advertising arrangements.

Wearable application

Suppose a wearable company states:

"By using this device, you agree that your health, fitness and behavioural information may be used to personalise advertisements."

That does not end the legal analysis.

The company must still establish:

appropriate legal basis;

compliance with Article 9 where applicable;

transparency;

purpose limitation;

necessity;

proportionality.

The CJEU's case law makes clear that processing sensitive data cannot simply be normalised through broad commercial arrangements.

9. Case Law 4 — Österreichische Post, C-300/21

CJEU, 4 May 2023

This case is especially important because it concerns compensation.

Facts

Österreichische Post processed information about individuals and generated political-affinity profiles.

The claimant alleged distress and a feeling of exposure.

Judgment

The CJEU held that:

GDPR infringement alone does not automatically create a right to compensation;

the claimant must establish damage;

there is no requirement that non-material damage reach a particular minimum seriousness threshold. (curia)

Importance for wearables

Imagine a company unlawfully discloses a user's:

heart-rate data;

fertility information;

sleep records;

glucose information.

The user cannot necessarily obtain damages merely by proving:

"The GDPR was breached."

The claimant must establish:

GDPR infringement + damage + causal connection.

But the absence of a minimum seriousness threshold is important.

Potential non-material harm could include:

distress;

anxiety;

loss of control;

exposure;

fear of misuse.

10. Case Law 5 — Natsionalna agentsia za prihodite, C-340/21

CJEU, 14 December 2023

This case arose from a major personal-data security incident.

Principle

The Court addressed the consequences of unlawful disclosure and the concept of non-material damage.

Importantly, the Court recognised that fear of possible misuse of personal data can constitute non-material damage in appropriate circumstances. (Court of Justice of the European Union)

Wearable application

Suppose a wearable company's database is hacked and millions of records are exposed.

The records include:

heart-rate histories;

sleep data;

location;

biometric information.

Even if there is no evidence that a criminal has yet used every individual's data, the affected person may potentially argue that the well-founded fear of misuse constitutes non-material damage.

However, the claimant still has to establish actual damage rather than relying solely on the existence of a GDPR infringement.

11. Case Law 6 — MediaMarktSaturn, C-687/21

CJEU, 25 January 2024

This case further developed Article 82 GDPR jurisprudence.

Principle

The Court reiterated that:

infringement;

damage;

causation

are cumulative requirements.

However, non-material damage does not need to meet an artificial minimum seriousness threshold. (InfoCuria)

Wearable relevance

Suppose an employee's employer improperly accesses wearable information showing:

sleep quality;

stress levels;

heart rate;

physical activity.

The employee may seek compensation where the unlawful processing causes actual non-material damage.

The claim is stronger if the claimant can demonstrate:

anxiety;

humiliation;

fear of workplace discrimination;

loss of control;

exposure of intimate information.

12. Case Law 7 — Krankenversicherung Nordrhein, C-667/21

CJEU, 21 December 2023

This case concerned health-related data and the requirements governing lawful processing.

Importance

The Court emphasised that processing health data must satisfy both:

the requirements of the relevant Article 9 exception; and

the general Article 6 lawfulness requirements.

In other words, an Article 9 justification does not eliminate the need to satisfy Article 6. (EUR-Lex)

Wearable relevance

A wearable health company might say:

"We process the data for health purposes."

That statement alone is insufficient.

The company must still establish the complete legal basis for the processing.

13. Case Law 8 — Österreichische Datenschutzbehörde and Others, C-474/24

AR and Others v Österreichische Datenschutzbehörde and Others, Grand Chamber, 14 July 2026

This is particularly relevant because it is a recent 2026 CJEU judgment.

Issue

The case concerned whether information relating to anti-doping violations constituted health data.

Important principle

The Court explained that health data cover personal data revealing information about past, current or future physical or mental health status.

The Court also reaffirmed the broad interpretive approach to health data, including situations involving information capable of revealing health status through deduction. (EUR-Lex)

Relevance to wearable litigation

Wearable devices are frequently used in:

professional sport;

fitness;

athletic performance;

health monitoring.

The judgment illustrates that courts will need to carefully distinguish between:

ordinary performance information

and

information that reveals or permits inference concerning health.

That distinction can determine whether Article 9's enhanced protections apply.

14. Case Law 9 — Lindqvist, C-101/01

CJEU, 6 November 2003

This is an older but foundational data-protection decision.

Principle

The CJEU addressed the concept of processing personal data and the scope of European data-protection law.

Wearable relevance

Wearable data are not legally transformed into "anonymous information" merely because the data are collected automatically.

Where a person can be identified directly or indirectly, the information can constitute personal data.

The case is therefore useful for understanding the broad conceptual foundation of European data protection.

15. Case Law 10 — Nowak v Data Protection Commissioner, C-434/16

CJEU, 20 December 2017

This is another foundational personal-data case.

Principle

The Court interpreted "personal data" broadly.

Information constitutes personal data where it relates to an identified or identifiable individual and has the required relationship to that person.

Wearable application

A wearable company's records might include:

User ID 84937 — resting heart rate 62 — sleep 7h 21m.

Even without a name in the data field, the information may still be personal data if the individual can be identified through the company's systems.

Thus:

pseudonymisation is not the same as anonymisation.

16. Case Law 11 — Wirtschaftsakademie Schleswig-Holstein, C-210/16

CJEU, 5 June 2018

This case concerned joint responsibility for processing personal data.

Importance

The CJEU adopted a broad concept of joint controllership.

A party can potentially be a joint controller even where it does not itself possess every piece of personal data or perform every processing operation.

Wearable relevance

Consider:

Wearable manufacturer → health-data platform → analytics provider → advertising platform

A company may attempt to say:

"We don't control the data; the analytics provider does."

The legal analysis may be more complicated.

If multiple parties jointly determine the purposes and means of processing, joint-controller questions can arise.

17. Case Law 12 — Google Spain, C-131/12

CJEU, 13 May 2014

Although this case concerned search engines rather than wearable technology, it is highly important for privacy and personal-data remedies.

Principle

The CJEU recognised important rights concerning the processing and dissemination of personal information.

Wearable relevance

Suppose a wearable company publishes:

"Top users with abnormal sleep patterns"

or exposes health-related profiles through a publicly accessible platform.

Google Spain illustrates the importance of examining:

dissemination;

privacy;

proportionality;

rights of the data subject.

18. UK Case Law — Lloyd v Google

Lloyd v Google LLC [2021] UKSC 50

The United Kingdom is no longer an EU Member State, but this case remains relevant to European comparative privacy law.

Facts

The case involved alleged unlawful collection and use of browsing information from millions of iPhone users.

Supreme Court principle

The UK Supreme Court rejected the proposed representative claim because the claimants had not established the required form of damage on the pleaded basis.

Importance

The case illustrates an important civil-law point:

Proof of unlawful data processing and proof of compensable damage are separate questions.

This is particularly relevant to wearable litigation where claimants may attempt mass or representative claims.

19. The Three Elements of an Article 82 Claim

Following the CJEU's Article 82 jurisprudence, a claimant generally needs to establish:

1. GDPR infringement

For example:

unlawful collection;

inadequate consent;

unlawful secondary use;

excessive retention;

inadequate security;

unlawful disclosure.

2. Damage

This can be:

material; or

non-material.

3. Causation

The damage must result from the GDPR infringement.

The CJEU repeatedly treats these as cumulative requirements. (Court of Justice of the European Union)

20. What Constitutes Misuse?

Wearable-data misuse can take many forms.

A. Unauthorised sale

A company sells health data to advertisers.

B. Secondary use

Data collected for fitness tracking are subsequently used for targeted advertising.

C. Unauthorised disclosure

Data are disclosed to:

employers;

insurers;

advertisers;

data brokers;

family members;

social-media companies.

D. Excessive retention

The company retains years of historical sensor data without sufficient justification.

E. Profiling

The company creates health-risk profiles without appropriate legal basis.

F. Automated decision-making

The data are used to determine:

insurance premiums;

employment opportunities;

creditworthiness;

eligibility for services.

21. Wearable Data and Employers

Workplace monitoring creates particularly sensitive disputes.

Imagine an employer provides smartwatches to employees to monitor:

fatigue;

movement;

heart rate;

stress;

sleep.

The employer then uses the information to identify "low productivity" workers.

Potential legal issues include:

employment law;

GDPR;

Article 9;

proportionality;

transparency;

employee consent;

automated decision-making;

discrimination.

The fact that the employee clicked "accept" does not necessarily resolve the problem, particularly where there is a significant imbalance between employer and employee.

22. Wearable Data and Insurance Companies

Insurance creates another major area of potential litigation.

Suppose an insurer offers:

"Lower your premium by sharing continuous smartwatch data."

The insurer may receive:

exercise frequency;

heart rate;

sleep patterns;

location;

physiological indicators.

Potential disputes concern whether the processing is:

voluntary;

transparent;

proportionate;

necessary;

based upon valid consent;

compatible with the original purpose.

The insurer may also face questions concerning automated decision-making.

23. Wearable Data and Advertising

A fitness company might collect:

"10,000 steps/day + elevated heart rate + sleep interruption"

and use the information to infer:

"This person may be stressed."

It could then target advertisements for:

medication;

supplements;

health services;

insurance;

psychological services.

This is legally sensitive because the company may be using apparently ordinary fitness data to generate health-related inferences.

The CJEU's broad approach to health data is therefore particularly important. (EUR-Lex)

24. Wearable Data and Data Brokers

A data broker may obtain wearable information and combine it with:

purchasing data;

location;

social-media information;

browsing history;

demographic information.

The resulting profile could reveal:

health conditions;

lifestyle;

pregnancy;

exercise habits;

emotional states.

This raises questions about:

purpose limitation;

compatibility of further processing;

lawful basis;

Article 9;

transparency;

profiling.

25. Consent

Consent must satisfy the GDPR's requirements.

For sensitive health data, explicit consent is particularly important where consent is the Article 9 exception relied upon.

A problematic consent mechanism might say:

"By using this app you agree to collection, analysis, sharing and commercialisation of all information generated by the device."

A court may examine whether such consent is:

specific;

informed;

freely given;

sufficiently explicit;

genuinely distinguishable between different purposes.

The user should be able to understand what happens to the data.

26. Purpose Limitation

Suppose the original purpose is:

"Monitor heart rate to display fitness information to the user."

The company later decides:

"We will sell heart-rate histories to advertisers."

That is a fundamentally different processing purpose.

The company must assess whether the secondary processing is legally compatible and whether an appropriate lawful basis exists.

Purpose limitation is therefore one of the strongest tools against "function creep."

27. Data Minimisation

A company should not collect unlimited data merely because the technology makes it possible.

For example, if an application needs only:

daily step count,

it may be difficult to justify retaining:

second-by-second location;

continuous heart rate;

sleep information;

body temperature;

unless those additional data are necessary for a legitimate and legally supported purpose.

28. Security Breaches

Wearable companies are attractive targets because their databases may contain:

health information;

location histories;

identity information;

behavioural profiles.

A security incident may lead to:

Article 33 notification;

Article 34 communication to affected persons;

regulatory enforcement;

Article 82 damages claims.

The security standard is risk-based.

A company handling highly sensitive continuous physiological information should implement appropriate technical and organisational measures.

29. Data Breach and Civil Liability

Suppose a hacker obtains:

5 million users' heart-rate and sleep histories.

Possible claims may involve:

inadequate security;

unlawful processing;

breach notification failures;

non-material damage;

fear of misuse;

loss of control.

But not every data breach automatically creates damages.

The claimant still has to establish the Article 82 requirements.

The CJEU has nevertheless recognised that fear of misuse can itself constitute non-material damage where the fear is sufficiently connected to the infringement and circumstances. (Court of Justice of the European Union)

30. Loss of Control Over Data

The concept of loss of control is particularly important in wearable cases.

A person might say:

"I do not know who has my heart-rate history, where it has gone, or how it is being used."

That loss of control may constitute non-material damage where the Article 82 requirements are satisfied.

Recent CJEU jurisprudence has recognised that even a relatively short loss of control can potentially qualify as non-material damage, provided actual damage is established. (Court of Justice of the European Union)

31. Fear of Future Misuse

Suppose the company accidentally exposes a database.

No evidence exists yet that someone has used a particular person's data.

The claimant nevertheless fears:

"Someone could use my health information against me in the future."

CJEU jurisprudence recognises that fear of future misuse can, in appropriate circumstances, amount to non-material damage. But courts must examine whether the fear is well founded in the specific circumstances. (Court of Justice of the European Union)

32. Material Damage

Material losses could include:

financial fraud;

increased insurance costs;

loss of employment opportunity;

costs of security measures;

medical expenses;

financial losses resulting from profiling;

expenses caused by identity fraud.

The claimant must establish a causal relationship between the unlawful processing and the financial damage.

33. Non-Material Damage

Non-material harm may include:

distress;

anxiety;

humiliation;

loss of control;

reputational injury;

fear;

exposure of intimate information.

The CJEU has rejected a requirement that non-material damage must exceed a predetermined seriousness threshold. (curia)

But this does not mean that every technical GDPR violation automatically produces damages.

34. Civil Tort and Privacy Rights

GDPR claims do not necessarily exhaust the claimant's remedies.

National civil law may provide additional causes of action involving:

personality rights;

privacy;

confidentiality;

negligence;

breach of confidence;

unlawful interference;

consumer rights.

The precise availability of these claims differs across European jurisdictions.

Thus a claimant might plead:

GDPR breach + national privacy tort + contractual breach.

35. Contractual Liability

Wearable users normally accept contractual terms.

The contract may contain obligations concerning:

data processing;

privacy;

security;

account management;

deletion;

data portability;

subscription services.

If the company promises:

"Your health information will never be sold to third parties"

and then sells it, the user may have both:

a data-protection argument; and

a contractual argument.

36. Consumer Protection

Consumer law can become important where wearable companies use:

misleading privacy policies;

hidden data-sharing provisions;

unfair contractual terms;

deceptive claims about "privacy";

unclear subscription arrangements.

A contractual term that is technically available somewhere in a lengthy privacy policy may not necessarily satisfy all transparency requirements.

37. Joint Controllers

The wearable ecosystem may involve:

Device manufacturer → app developer → cloud provider → analytics company → advertising partner

Determining who is the:

controller;

joint controller;

processor;

is critical.

The Wirtschaftsakademie jurisprudence demonstrates that controller responsibility can extend beyond the party that physically performs every processing operation.

This prevents companies from simply dividing the technological chain and asserting:

"The other company is responsible."

38. International Transfers

Wearable companies may store information on cloud servers outside the EU/EEA.

Potential issues include:

international transfers;

adequacy decisions;

Standard Contractual Clauses;

supplementary safeguards;

access by foreign authorities.

The Schrems II jurisprudence is particularly relevant to international transfers of personal data.

Where the data are health data, the consequences can be particularly serious.

39. Data Deletion

A user may request deletion of wearable information.

However, deletion rights are not absolute.

There can be exceptions involving:

legal obligations;

public interest;

healthcare;

legal claims;

scientific research;

other GDPR exceptions.

The dispute may therefore become:

"How much historical health information can the company lawfully retain, and for how long?"

40. Automated Profiling

Wearable data can feed AI systems that generate:

health scores;

fitness scores;

stress scores;

insurance risk scores;

employment risk scores.

Where automated decision-making has legal or similarly significant effects, additional GDPR protections may apply.

A claimant may therefore challenge:

the decision;

the underlying profiling;

the information used;

the absence of human intervention;

lack of transparency.

41. Biometric Data

Wearables can also generate biometric information.

A distinction must be made between:

ordinary physiological information

and

biometric data processed for uniquely identifying a person.

Not every heart-rate measurement is necessarily "biometric data" in the strict Article 9 sense.

But if a wearable system processes physiological characteristics to uniquely identify the person, enhanced protections may become relevant.

42. Sports Wearables

Professional athletes present a particularly difficult category.

A club may want to monitor:

heart rate;

recovery;

fatigue;

sleep;

injury risk;

training intensity.

The athlete may argue:

"The club is using health information beyond the purpose for which I agreed to provide it."

Potential legal questions include:

employment law;

collective agreements;

GDPR;

consent;

proportionality;

medical confidentiality;

sports regulation.

The 2026 CJEU anti-doping decision illustrates the continuing importance of determining whether particular information qualifies as health data and whether its publication is justified by a lawful exception. (EUR-Lex)

43. Children and Wearable Devices

Children may use:

fitness trackers;

smartwatches;

location devices;

medical wearables.

This creates additional concerns involving:

parental consent;

children's privacy;

profiling;

advertising;

location tracking.

Because children may be less able to understand the long-term consequences of data collection, the transparency and protection requirements become especially important.

44. Employee Wearables

A workplace may provide wearable devices for:

occupational safety;

productivity monitoring;

fatigue detection.

The employer must carefully distinguish:

legitimate workplace safety monitoring

from

general surveillance of employees' private lives.

Collecting data about an employee's:

sleep at home;

heart rate outside working hours;

exercise;

location;

can create significant proportionality and privacy concerns.

45. Insurance Wearables

Insurance companies may seek continuous behavioural information to calculate premiums.

The civil dispute might arise where:

A customer refuses to provide continuous wearable data and is charged a substantially higher premium.

Possible legal questions include:

Was participation genuinely voluntary?

Was the customer sufficiently informed?

Is the processing proportionate?

Is health data being processed?

Is automated profiling involved?

Was there discrimination?

46. Pharmaceutical and Medical Research

Wearable devices are increasingly used for clinical research.

Researchers may collect:

continuous heart-rate data;

movement;

sleep;

glucose;

neurological measurements.

Research processing can be lawful under specific GDPR provisions, but safeguards are required.

The EDPB notes that health research involving special-category data requires appropriate safeguards. (European Data Protection Board)

A dispute can arise where data originally collected for research are later reused for:

commercial advertising;

insurance;

unrelated research;

product development.

47. Commercial Sale of Health Profiles

A particularly serious scenario is:

Wearable company → data broker → insurance company.

The original user may have believed:

"This device is helping me track fitness."

The commercial ecosystem may instead create:

"A predictive health-risk profile."

The legality of that transformation depends on:

original purpose;

lawful basis;

Article 9;

transparency;

compatibility;

consent;

contractual terms.

48. Evidentiary Issues in Civil Litigation

Wearable data can themselves become evidence.

For example, in a personal-injury lawsuit, one party may seek:

step counts;

heart-rate records;

sleep records;

GPS records.

This creates a conflict between:

relevance to litigation

and

privacy/data protection.

The court may have to determine whether disclosure is:

necessary;

proportionate;

legally authorised.

49. Cross-Border Litigation

Imagine:

German consumer;

French wearable manufacturer;

Irish cloud provider;

US analytics company.

A dispute may involve:

GDPR;

Rome I;

Rome II;

Brussels Ia;

consumer jurisdiction;

international transfers.

The claimant may have to determine:

which court has jurisdiction;

which law governs the contract;

which law governs tort;

where the controller is established;

where the damage occurred.

50. Remedies

Potential remedies include:

A. Compensation

Under Article 82 GDPR.

B. Injunction

To stop unlawful processing.

C. Erasure

Where Article 17 applies.

D. Restriction

Temporary limitation of processing.

E. Rectification

Correction of inaccurate information.

F. Access

Obtaining information about processing.

G. Data portability

Receiving data in an appropriate format.

H. Regulatory enforcement

Complaints to supervisory authorities.

I. Contractual remedies

Where the processing breaches contractual promises.

51. Important Distinction: Regulatory Fine vs Civil Damages

A regulatory authority may impose a fine.

That does not automatically mean:

every affected person receives compensation.

Similarly:

a claimant may obtain civil compensation even though no regulatory fine has been imposed.

The two mechanisms serve different purposes.

52. Practical Hypothetical

Consider this example.

A European company sells a smart ring.

The ring continuously collects:

heart rate;

sleep;

body temperature;

activity;

location.

The company tells consumers:

"We use your information to improve your fitness experience."

Three years later, it begins sharing data with an insurance analytics company.

The analytics company creates:

"Cardiovascular risk scores."

An insurer uses those scores when determining premiums.

The customer discovers the arrangement and brings proceedings.

53. Legal Analysis of the Hypothetical

Issue 1 — Are the data personal data?

Yes, if the individual is identified or identifiable.

Issue 2 — Are they health data?

The answer may be yes where the information reveals health status directly or through deduction.

The CJEU's broad approach in Lindenapotheke is particularly relevant. (EUR-Lex)

Issue 3 — What was the original purpose?

Fitness monitoring.

Issue 4 — What is the new purpose?

Insurance-risk assessment.

The purposes are materially different.

Issue 5 — Is there an Article 6 basis?

The company must establish one.

Issue 6 — Is there an Article 9 exception?

If the information constitutes health data, an additional Article 9 condition is required.

Issue 7 — Was the user adequately informed?

The transparency requirements must be examined.

Issue 8 — Did the user suffer damage?

The claimant may allege:

loss of control;

distress;

increased insurance costs;

privacy invasion.

Issue 9 — Can causation be established?

The claimant must connect the unlawful processing to the particular damage.

Issue 10 — What remedy is available?

Potentially:

compensation;

erasure;

restriction;

injunction;

regulatory action.

54. Case-Law Comparison

CaseCourtPrincipal issueWearable-data relevance
Lindqvist, C-101/01CJEUPersonal-data processingFoundation for data classification
Google Spain, C-131/12CJEUPrivacy and disseminationPublic exposure of sensitive profiles
Wirtschaftsakademie, C-210/16CJEUJoint controllershipDevice/app/cloud ecosystems
Nowak, C-434/16CJEUBroad personal-data conceptSensor records linked to users
Vyriausioji, C-184/20CJEUIndirectly revealing sensitive informationHealth inferences from sensor data
Österreichische Post, C-300/21CJEUCompensation under Article 82Non-material damage
Meta Platforms, C-252/21CJEULawfulness and sensitive dataSecondary commercial use
Natsionalna agentsia za prihodite, C-340/21CJEUData breach and fear of misuseHacked wearable databases
Krankenversicherung Nordrhein, C-667/21CJEUHealth-data processingMedical/health wearable data
MediaMarktSaturn, C-687/21CJEUArticle 82 damageCompensation claims
Lindenapotheke, C-21/23CJEUHealth data and Article 9Health inferences from non-medical data
AR and Others, C-474/24CJEU, 2026Health-data classificationSports/wearable monitoring

55. The Most Important Legal Principles

The case law supports several major principles.

1. Health data receive enhanced protection

Wearable health information can fall within Article 9.

2. Indirect information can be health data

The law is concerned with what information can reveal, not merely what the raw data are called. (EUR-Lex)

3. Pseudonymisation does not necessarily make data anonymous

If the person remains identifiable, GDPR obligations may continue.

4. Consent has limits

A general acceptance of terms does not automatically legitimise every future processing purpose.

5. Secondary use is legally significant

Fitness data used for insurance or advertising may require a separate legal analysis.

6. Compensation requires damage

GDPR infringement alone is insufficient for Article 82 damages. (curia)

7. There is no fixed minimum seriousness threshold for non-material damage

But actual damage must still be demonstrated. (InfoCuria)

8. Fear of misuse may constitute damage

Where sufficiently well founded, fear of misuse can constitute non-material damage. (Court of Justice of the European Union)

9. Multiple companies may share responsibility

The wearable ecosystem can create controller/joint-controller issues.

10. Data protection and civil law overlap

A claimant can potentially combine GDPR remedies with national contractual, tort and personality-right claims.

56. Recommended Litigation Structure

A well-developed wearable-data claim should normally proceed through the following questions:

Step 1 — Identify the data

What exactly did the wearable collect?

Step 2 — Identify the person

Can the data be linked to an identifiable individual?

Step 3 — Determine whether the information is health data

Does it directly or indirectly reveal health status?

Step 4 — Identify the controller

Who determined the purposes and means?

Step 5 — Identify the processing purpose

Why was the data collected?

Step 6 — Examine Article 6

What is the lawful basis?

Step 7 — Examine Article 9

If health data are involved, what additional condition permits processing?

Step 8 — Examine transparency

Was the user properly informed?

Step 9 — Examine security

Were appropriate technical and organisational measures used?

Step 10 — Establish damage

What material or non-material harm occurred?

Step 11 — Establish causation

Did the unlawful processing cause that harm?

Step 12 — Select remedies

Compensation, erasure, restriction, injunction or regulatory complaint.

57. Conclusion

Wearable bio-sensor data misuse litigation is becoming one of the most significant emerging areas of European civil and data-protection law.

The fundamental problem is that wearable devices transform ordinary physical activity into an extensive digital record of a person's body and behaviour. A smartwatch or smart ring may appear to collect simple fitness information, but when the information is combined and analysed it can reveal highly sensitive health characteristics.

The CJEU's jurisprudence is particularly important. Lindenapotheke (C-21/23) confirms the broad approach to health data, including information capable of revealing health status through deduction. Vyriausioji (C-184/20) similarly demonstrates that indirect revelation of sensitive information can trigger enhanced protection. Österreichische Post (C-300/21), Natsionalna agentsia za prihodite (C-340/21) and MediaMarktSaturn (C-687/21) establish the developing principles concerning compensation for non-material harm. The 2026 AR and Others (C-474/24) judgment provides a current illustration of the Court's continuing attention to the boundary between ordinary information and health-related information.

For civil litigation, the most important formula is:

Unlawful processing + actual material or non-material damage + causal connection = potential Article 82 compensation claim.

But wearable-data litigation can go beyond GDPR compensation. Depending on the facts and national law, it may also involve contractual liability, consumer protection, privacy/personality rights, confidentiality, employment law, medical confidentiality, product liability, cybersecurity and injunctions.

The central legal lesson is therefore that the legal value of wearable data lies not merely in the individual sensor reading, but in what that information can reveal about an identifiable person's body, health, behaviour and private life. European courts are increasingly treating those inferential capabilities as crucial when determining the level of legal protection owed to individuals. (European Data Protection Board)

Available next action: Create a downloadable PDF file here in this chat containing the findings and recommendations above

LEAVE A COMMENT