Civil Law And Wearable Medical Device Data Misuse In Europe . ut External Links
Civil Law and Wearable Medical Device Data Misuse in Europe
1. Introduction
Wearable medical and health devices have created a distinctive category of civil and data-protection disputes in Europe. Smartwatches, continuous glucose monitors, ECG patches, fitness trackers, sleep monitors, smart rings, rehabilitation sensors and other connected medical devices can continuously generate information concerning a person's:
heart rate;
ECG patterns;
blood glucose;
blood oxygen;
sleep;
body temperature;
physical activity;
reproductive health;
medication adherence;
neurological activity;
location;
physiological abnormalities; and
inferred medical conditions.
The legal problem becomes particularly serious when manufacturers, healthcare providers, insurers, employers, app developers, cloud providers or advertising platforms use that information for purposes beyond the original medical purpose.
European law does not currently have a single cause of action called "wearable medical-device data misuse." Instead, liability may arise through a combination of:
GDPR;
national civil-law principles;
medical confidentiality;
contractual obligations;
professional negligence;
consumer-protection law;
product-liability law;
privacy and personality rights;
breach of confidence;
unlawful commercial exploitation of personal information; and
Article 8 of the European Convention on Human Rights in cases involving State responsibility.
Health data receive particularly strong protection under European data-protection law. The European human-rights framework likewise treats medical information as highly sensitive. (ECHR)
2. What Is Wearable Medical-Device Data?
Wearable data can be divided into several categories.
A. Direct health data
These are measurements directly concerning the individual's health.
Examples:
blood glucose;
blood pressure;
ECG;
oxygen saturation;
body temperature;
heart rhythm.
These are generally the easiest to classify as "data concerning health".
B. Behavioral health data
Examples include:
sleeping patterns;
exercise levels;
calorie expenditure;
heart-rate variability;
daily movement;
rehabilitation activity.
Individually, some of these measurements might appear innocuous.
However, when combined they may reveal:
depression, pregnancy, cardiovascular disease, sleep disorders, physical disability or other medical conditions.
C. Inferred health information
This is especially important.
A device may not explicitly state:
"The user has cardiac disease."
Instead, an algorithm may infer a medical condition from:
heart-rate patterns;
oxygen levels;
sleep abnormalities;
exercise tolerance.
European data-protection law can protect information capable of revealing health status even where the health condition is inferred rather than expressly stated.
The CJEU has recently emphasized this broad approach to health data. (EUR-Lex)
3. Why Wearable Data Create Special Civil-Law Problems
Wearables create a continuous data stream.
A conventional medical record might contain:
"Patient's blood pressure: 150/95."
A wearable may generate:
millions of individual physiological observations over several months.
This creates several legal questions:
Who controls the data?
Who is the GDPR controller?
Is the device manufacturer a controller or processor?
Can data be reused for advertising?
Can an insurer purchase access?
Can an employer obtain health information?
Can the manufacturer combine wearable information with browsing data?
Can the information be sold to pharmaceutical companies?
Can an artificial-intelligence system infer diseases?
Can the data be retained indefinitely?
Can a patient demand deletion?
What compensation is available for unlawful processing?
4. European Legal Framework
4.1 GDPR
The GDPR is the central legal instrument.
Relevant provisions include:
Article 4(15)
Defines data concerning health.
Article 5
Establishes principles including:
lawfulness;
fairness;
transparency;
purpose limitation;
data minimization;
accuracy;
storage limitation;
integrity and confidentiality.
Article 6
Requires a lawful basis for processing.
Article 9
Provides enhanced protection for special categories of personal data, including health data.
Article 15
Right of access.
Article 16
Right to rectification.
Article 17
Right to erasure, subject to exceptions.
Article 18
Right to restriction of processing.
Article 20
Data portability.
Article 21
Right to object in specified circumstances.
Article 22
Protection against certain solely automated decisions.
Article 25
Data protection by design and by default.
Article 32
Security obligations.
Article 35
Data Protection Impact Assessments.
Article 82
Compensation for material and non-material damage resulting from GDPR infringements.
5. Six Major Types of Wearable Data Misuse
5.1 Unauthorized secondary use
A smartwatch may collect data for:
"monitoring your health."
The company may subsequently use the information for:
advertising;
profiling;
insurance analysis;
marketing;
behavioral prediction.
The question becomes whether this secondary purpose was legally authorized.
5.2 Sale or disclosure to third parties
Potential recipients could include:
insurance companies;
pharmaceutical companies;
employers;
advertising companies;
data brokers;
technology platforms.
Such transfers can create separate liability issues.
5.3 Excessive collection
A company may collect:
precise location;
microphone information;
contacts;
browsing history;
even though these are unnecessary for the medical functionality of the device.
This potentially conflicts with data minimization and purpose limitation.
5.4 Inadequate security
Suppose a wearable platform suffers a cyberattack exposing:
heart-rate histories;
reproductive-health information;
sleep records;
medication information.
The company may face claims concerning:
inadequate security;
GDPR breach;
confidentiality;
negligence;
contractual breach.
5.5 Algorithmic inference
An AI system may analyze wearable information and infer:
"This person is likely to develop cardiovascular disease."
If the inference is used to:
change insurance premiums;
deny employment;
market products;
make healthcare decisions;
additional legal issues arise.
5.6 Retention after withdrawal
A consumer may stop using the device and request deletion.
The company nevertheless retains years of historical health data.
The legality of continued retention depends on:
the original purpose;
applicable legal obligations;
consent;
legitimate legal grounds;
scientific/research exceptions;
public-health exceptions;
storage limitation requirements.
6. Important European Case Laws
Because litigation specifically involving smartwatches and medical wearables remains comparatively limited, European courts have developed the applicable principles through broader health-data, digital-platform and privacy cases.
It is therefore important not to mischaracterize these authorities as all being literal "smartwatch cases."
Case 1 — Österreichische Post AG, C-300/21
Background
The CJEU considered compensation under Article 82 GDPR for unlawful processing of personal data.
Importance
The judgment is particularly important because it concerns the threshold for compensable damage under the GDPR.
The existence of a GDPR infringement and the existence of compensable damage are related but distinct questions.
Wearable relevance
Suppose a wearable manufacturer unlawfully discloses an individual's:
heart-rate information;
fertility information;
sleep information.
The claimant must establish the legally relevant damage for a compensation claim.
Potential harm could include:
financial loss;
privacy intrusion;
distress;
loss of control over sensitive information;
reputational consequences.
The case is therefore important when determining whether unlawful wearable-data processing can generate compensation.
Case 2 — Meta Platforms and Others, C-252/21
This is one of the most important modern CJEU data-processing cases.
Background
The CJEU examined the processing of personal data by a major online platform and the interaction between GDPR requirements, legal bases and extensive data combination.
Principle
The Court stressed the strict nature of the GDPR requirements governing sensitive personal data.
Health-related data receive especially strong protection, and exceptions to the prohibition on processing special categories must be interpreted carefully. (EUR-Lex)
Wearable relevance
Imagine:
Smartwatch health data → wearable app → advertising profile → social-media advertising system.
The mere fact that the user agreed to general platform terms does not necessarily answer whether the processing of sensitive health data is lawful.
The legality of:
combining data;
profiling;
advertising;
targeted marketing;
must be separately examined.
Case 3 — Nowak v Data Protection Commissioner, C-434/16
Background
The CJEU interpreted the meaning of personal data broadly.
The case involved examination scripts and comments associated with an individual's examination performance.
Principle
The Court adopted a broad understanding of personal data, emphasizing information relating to an identifiable individual.
Wearable relevance
Wearable systems create enormous amounts of information that may not resemble conventional medical records.
Examples:
raw heart-rate readings;
movement data;
sleep cycles;
temperature;
timestamps;
device-generated scores.
Even if the company argues that the information is merely "technical data," the information may constitute personal data where it relates to an identifiable person.
Case 4 — Wirtschaftsakademie Schleswig-Holstein, C-210/16
Background
The CJEU examined the concept of joint controllership under the GDPR's predecessor framework.
A company operated a Facebook fan page while Facebook processed information concerning visitors.
Principle
An entity can have responsibility for processing even when it does not itself physically perform all of the data-processing operations.
Wearable relevance
This is extremely important for wearable ecosystems.
Consider:
Patient → wearable → manufacturer → health app → cloud provider → analytics company
Several entities may influence:
why data are collected;
what data are collected;
how they are used;
who receives them.
A manufacturer cannot necessarily escape responsibility simply by arguing:
"The cloud company actually processed the information."
The legal characterization of controllers, joint controllers and processors becomes central.
Case 5 — Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW, C-40/17
Background
The CJEU considered responsibility for processing personal data through an embedded third-party technology.
Principle
An organization may have data-protection responsibilities even where another company performs the actual technical processing.
Wearable relevance
The principle is highly relevant to:
wearable APIs;
embedded analytics;
third-party SDKs;
cloud services;
health-data dashboards.
Suppose a medical-device company incorporates a third-party analytics tool.
The manufacturer cannot necessarily argue:
"The analytics company collected the data, so the manufacturer has no responsibility."
The actual allocation of decision-making power must be examined.
Case 6 — I v Finland, Application No. 20511/03
Background
The applicant was an HIV-positive nurse who received treatment at a hospital where she also worked.
She suspected that colleagues had improperly accessed her medical records.
The European Court of Human Rights examined whether the State had provided adequate safeguards against unauthorized access.
Decision
The Court emphasized that sensitive medical data require strong safeguards against unauthorized access.
The Court found a violation of Article 8 because the national system did not provide adequate protection and traceability for access to the applicant's medical records. (Global Health Rights)
Wearable relevance
This is highly analogous to wearable medical data.
A health-data platform should ideally be able to establish:
who accessed the data;
when they accessed it;
what information they viewed;
whether access was authorized;
whether information was exported.
A system incapable of detecting unauthorized access can itself become part of the legal problem.
Case 7 — Z. v Finland, Application No. 22009/93
Background
The case concerned disclosure of the applicant's HIV status in judicial proceedings.
Principle
The ECtHR emphasized the exceptional sensitivity of medical information and the importance of medical confidentiality.
The Court stressed that confidentiality of health information is a fundamental principle and that disclosure requires particularly strong justification and safeguards. (ECHR)
Wearable relevance
Wearable information can reveal information comparable to traditional medical records.
For example:
continuous glucose monitoring can reveal diabetes;
reproductive-health tracking can reveal pregnancy;
ECG data can reveal cardiovascular conditions.
Unauthorized publication or disclosure of such information can therefore engage serious privacy interests.
Case 8 — S. and Marper v United Kingdom
Background
The applicants challenged indefinite retention of fingerprints, cellular samples and DNA profiles.
Principle
The ECtHR held that retaining sensitive biological information constitutes an interference with private life.
The Court emphasized that cellular samples contain highly sensitive information, including health-related and genetic information. (HUDOC)
Wearable relevance
Although the case concerned forensic biological material rather than wearable devices, it provides an important principle:
Retention itself can constitute a privacy interference.
A wearable company therefore cannot necessarily argue:
"We have not disclosed the health data, so there is no legal problem."
Long-term retention of highly sensitive physiological information may itself raise serious legal questions.
Case 9 — Ryneš v Úřad pro ochranu osobních údajů, C-212/13
Background
The CJEU considered whether video surveillance fell within the so-called household exemption.
Principle
The Court interpreted the personal/household exemption narrowly.
Wearable relevance
This becomes important when a wearable continuously collects:
location;
images;
audio;
environmental information;
information about other people.
A person cannot necessarily treat every wearable-related processing activity as a purely private household activity.
Where processing extends beyond genuinely personal activity, data-protection law may apply.
Case 10 — Breyer v Bundesrepublik Deutschland, C-582/14
Background
The case concerned dynamic IP addresses and whether information could constitute personal data where identification required additional information held by another party.
Principle
The CJEU adopted a functional approach to identifiability.
Wearable relevance
A company may claim that:
"The device ID is pseudonymized."
That does not necessarily mean that the information falls outside personal-data protection.
If the individual can reasonably be identified by combining information held by relevant parties, GDPR obligations may remain applicable.
This is especially important for:
pseudonymized wearable datasets;
device identifiers;
cloud accounts;
research datasets;
health-data analytics.
7. A Particularly Important 2026 Authority
AR and Others v Österreichische Datenschutzbehörde and Others, C-474/24
The CJEU Grand Chamber decided this case on 14 July 2026.
Although it concerns anti-doping information rather than wearable devices, it is highly relevant to the interpretation of health data.
The Court explained that whether information constitutes "data concerning health" depends upon its content and whether it reveals information about the health status of the person concerned. Where information qualifies as health data, Article 9's restrictions apply, subject to its specific exceptions. (EUR-Lex)
Importance for wearable devices
The case reinforces a substance-over-form approach.
A company cannot necessarily avoid Article 9 merely by labeling information:
"fitness data"
rather than:
"medical data."
If the information reveals a person's physical or medical condition, the GDPR's special-category protections may become relevant.
8. The Central Question: Is Wearable Data "Health Data"?
This is often the first legal question.
Consider the following:
| Wearable information | Likely legal significance |
|---|---|
| ECG recording | Clearly health-related |
| Blood glucose | Clearly health-related |
| Blood oxygen | Potentially health-related |
| Heart-rate history | Context-dependent, potentially health-related |
| Sleep patterns | Potentially health-related |
| Step count | May initially appear ordinary |
| GPS location | Personal data; may become health-related depending on context |
| Medication reminders | Strong health implications |
| Fertility tracking | Highly sensitive health information |
| Raw accelerometer data | Context-dependent |
| Algorithmic disease prediction | Potentially highly sensitive |
The critical question is not simply:
"What did the device call the data?"
It is:
What can the data reveal about an identifiable person's health?
9. Consent Problems
Many wearable applications rely heavily on consent.
However, valid consent under GDPR must satisfy legal requirements concerning:
specificity;
informed choice;
freedom;
clarity;
ability to withdraw.
A consent screen saying:
"By continuing, you agree to all data uses"
may be insufficient for every conceivable secondary purpose.
This becomes particularly problematic where a company seeks to combine health data with:
advertising profiles;
social-media activity;
shopping behavior;
location histories.
10. Commercial Exploitation of Wearable Health Data
Imagine a company collects:
heart-rate + sleep + exercise + menstrual-cycle + location data.
It then sells analytical information to advertisers.
Potential legal issues include:
unlawful processing;
incompatible secondary purpose;
inadequate consent;
failure of transparency;
violation of data minimization;
unlawful profiling;
failure to establish an Article 9 condition;
inadequate security;
unlawful international transfer.
11. Employer Misuse
Wearable medical devices can create significant employment-law problems.
Suppose an employer encourages workers to use a health-tracking device.
The employer subsequently discovers:
Employee A has an irregular sleep pattern and high resting heart rate.
The employer uses this information to decide:
promotion;
dismissal;
scheduling;
performance evaluation.
This may create serious concerns under:
GDPR;
employment law;
anti-discrimination principles;
privacy law;
national constitutional law.
The employer-employee relationship also raises questions about whether purported "consent" was genuinely freely given.
12. Insurance Misuse
A particularly sensitive scenario is:
Wearable → health data → insurance company → premium decision.
For example, an insurer might attempt to infer:
probability of cardiac disease;
lifestyle habits;
pregnancy;
sleep disorders;
physical inactivity.
Potential legal issues include:
unlawful processing;
profiling;
discrimination;
transparency;
automated decision-making;
purpose limitation.
The legal analysis becomes particularly complex where the original device was marketed as a medical or wellness product but the data are later used for financial risk assessment.
13. Data Breach Scenario
Suppose a hacker accesses a wearable manufacturer's cloud database containing:
500,000 ECG records;
sleep histories;
blood-glucose readings;
user identities.
Potential legal consequences may include:
Regulatory
Data-protection authority investigation.
Civil
Compensation claims by affected individuals.
Contractual
Claims based on contractual promises of security or confidentiality.
Consumer law
Claims concerning misleading security representations.
Medical confidentiality
Potential additional duties where healthcare professionals are involved.
14. Civil Liability for Inaccurate Data
Wearable devices can also generate incorrect information.
Suppose:
A wearable incorrectly reports repeated arrhythmia events.
The user becomes alarmed and purchases unnecessary medical treatment.
Alternatively:
The device fails to detect a dangerous medical event.
This creates two separate legal questions:
Data-protection liability
Was inaccurate personal data processed?
Product/service liability
Was the device or software defective?
These claims should not be confused.
A defective medical device may potentially generate liability independently of GDPR liability.
15. Product Liability Dimension
Modern wearable medical products can involve:
hardware;
embedded software;
cloud software;
algorithms;
mobile applications;
artificial intelligence.
European product-liability law has been evolving to address digital products and software.
Accordingly, a claimant may potentially pursue parallel theories:
defective device + defective software + unlawful data processing
The fact that a product is technologically sophisticated does not eliminate ordinary civil-law requirements such as:
defect;
damage;
causation.
16. Data Controller and Processor Issues
A wearable ecosystem may involve:
User
↓
Wearable manufacturer
↓
Mobile application
↓
Cloud-hosting provider
↓
Analytics company
↓
Healthcare provider
↓
Advertising/marketing company
The legal question is not merely:
"Who possesses the data?"
It is:
Who determines the purposes and means of processing?
The CJEU's decisions in Wirtschaftsakademie and Fashion ID are particularly important because responsibility may extend beyond the entity physically performing the technical processing.
17. Joint Controllers
Suppose:
Manufacturer determines why health data are collected;
healthcare provider determines medical purposes;
analytics company determines certain analytics purposes.
Depending on the precise arrangement, more than one entity could potentially qualify as a controller or joint controller.
This is important because a company cannot necessarily avoid responsibility by outsourcing processing.
18. Data Minimization
The GDPR requires personal data to be:
adequate, relevant and limited to what is necessary for the relevant purpose.
Suppose a glucose-monitoring device requires:
glucose levels;
timestamps.
But the application additionally collects:
precise GPS;
contact lists;
microphone recordings;
browsing history.
The additional information may require separate justification.
The central question is:
Is each category of information genuinely necessary for the stated purpose?
19. Purpose Limitation
Suppose the original purpose is:
"monitoring cardiovascular health."
The company subsequently uses the same information for:
"targeted advertising."
The legality of that secondary use must be independently assessed.
A broad privacy policy does not automatically make every future use lawful.
20. Data Retention
Wearable companies may retain years of historical data.
But indefinite storage raises questions under:
storage limitation;
necessity;
purpose limitation;
security;
erasure rights.
The reasoning in S. and Marper is particularly useful by analogy because it demonstrates that retaining sensitive personal information can itself constitute a privacy interference. (HUDOC)
21. Remedies Available to Victims
A victim may potentially seek:
1. Access
Obtain a copy of the data being processed.
2. Rectification
Correct inaccurate health information.
3. Erasure
Request deletion where Article 17 applies.
4. Restriction
Limit processing.
5. Objection
Object to certain processing activities.
6. Compensation
Claim compensation for qualifying material or non-material damage under Article 82 GDPR.
7. Injunctions
National civil courts may, depending upon national procedural law, provide injunctive relief.
8. Regulatory complaint
A complaint may be filed with the relevant data-protection supervisory authority.
22. Evidence in Wearable-Data Litigation
Evidence can include:
device logs;
application logs;
privacy policies;
consent screens;
API documentation;
data-processing agreements;
data-access records;
server logs;
cloud-storage records;
data-breach reports;
algorithmic documentation;
expert evidence.
Particularly important evidence
Audit logs.
If the system records:
User A → Employee B → accessed ECG data → 14:32 → downloaded file
the evidence may establish unauthorized access.
If the system does not maintain adequate access records, that itself can become legally significant.
23. Causation in Civil Claims
A claimant must distinguish between:
Unlawful processing
and
Recoverable damage.
For example:
Company unlawfully collected heart-rate data.
That establishes a potential GDPR infringement.
But the claimant may additionally need to demonstrate legally compensable harm for an Article 82 damages claim.
Possible damage may include:
financial loss;
identity-related harm;
serious privacy intrusion;
psychological distress;
reputational damage;
exposure of intimate medical information.
The precise requirements are governed by European and national law.
24. Hypothetical Example
Assume a European company sells a medical smartwatch.
The device collects:
ECG data;
blood oxygen;
sleep patterns;
heart rate;
location.
Its privacy notice says:
"We process data to provide health-monitoring services."
The company subsequently sends individualized health profiles to an advertising company.
The advertising company identifies users likely to suffer from:
insomnia;
cardiovascular conditions;
anxiety.
Potential legal claims
The consumer could potentially argue:
unlawful processing of special-category data;
lack of an appropriate Article 9 condition;
lack of transparency;
violation of purpose limitation;
excessive data sharing;
unlawful profiling;
inadequate security;
compensation under Article 82;
national civil-law privacy claims.
25. Comparison of the Major Authorities
| Case | Main principle | Wearable relevance |
|---|---|---|
| Österreichische Post, C-300/21 | GDPR compensation | Damages for unlawful health-data processing |
| Meta Platforms, C-252/21 | Lawfulness and sensitive data | Combining health data with other datasets |
| Nowak, C-434/16 | Broad personal-data concept | Wearable-generated information |
| Wirtschaftsakademie, C-210/16 | Joint controllership | Manufacturer/app relationships |
| Fashion ID, C-40/17 | Responsibility for embedded processing | APIs and third-party analytics |
| Ryneš, C-212/13 | Household exemption | Wearable surveillance/data collection |
| Breyer, C-582/14 | Identifiability | Pseudonymized wearable datasets |
| I v Finland | Medical-data security | Unauthorized access to health information |
| Z v Finland | Medical confidentiality | Disclosure of wearable health information |
| S. and Marper | Retention of sensitive data | Long-term wearable-data retention |
| AR and Others, C-474/24 | Meaning of health data | Classification of inferred physiological information |
26. Key Legal Principles
The European case law supports several important conclusions.
First
Health information receives enhanced protection.
Medical information is among the most sensitive categories of personal information in European law. (ECHR)
Second
The label used by a technology company is not decisive.
Calling information "fitness data" does not necessarily prevent it from being treated as health data where it reveals health status.
Third
Outsourcing does not automatically eliminate responsibility.
The controller/processor/joint-controller analysis remains critical.
Fourth
Retention itself can be legally significant.
A company cannot necessarily justify indefinite retention simply because information has not yet been publicly disclosed.
Fifth
Medical confidentiality is particularly strong.
The ECtHR has repeatedly emphasized the importance of safeguards against unauthorized disclosure and access to medical information. (ECHR)
Sixth
GDPR and civil law can operate simultaneously.
A claimant may potentially combine:
GDPR claim + contractual claim + negligence claim + confidentiality/privacy claim + product-liability claim.
27. Conclusion
Wearable medical-device data misuse represents an emerging European civil-law problem at the intersection of data protection, privacy, consumer law, medical confidentiality and product liability.
The most important legal issue is that wearable devices can transform ordinary physical activity into an extraordinarily detailed medical profile. A single device can reveal:
cardiovascular condition;
sleep disorders;
reproductive information;
physical disability;
medication effects;
lifestyle patterns;
potentially future health risks.
European law therefore approaches such information with heightened sensitivity.
The most useful authorities include Österreichische Post, Meta Platforms, Nowak, Wirtschaftsakademie, Fashion ID, Ryneš, Breyer, I v Finland, Z v Finland, and S. and Marper, while the 2026 AR and Others judgment in C-474/24 provides an especially current interpretation of the concept of health data. (EUR-Lex)
For a civil claim, the strongest analytical structure is generally:
1. Identify the data → 2. establish whether it is personal/health data → 3. identify the controller → 4. determine the legal basis → 5. examine Article 9 → 6. assess purpose limitation and minimization → 7. examine security/confidentiality → 8. establish breach → 9. establish damage → 10. establish causation → 11. determine the appropriate remedy.
Because reported European litigation specifically involving wearable medical devices is still developing, the established health-data and digital-platform cases are especially important for predicting how courts are likely to approach future smartwatch, smart-ring, glucose-monitor and connected-medical-device disputes.

comments