Civil Law And Wearable Medical Device Data Misuse In Europe . ut External Links

Civil Law and Wearable Medical Device Data Misuse in Europe

1. Introduction

Wearable medical and health devices have created a distinctive category of civil and data-protection disputes in Europe. Smartwatches, continuous glucose monitors, ECG patches, fitness trackers, sleep monitors, smart rings, rehabilitation sensors and other connected medical devices can continuously generate information concerning a person's:

heart rate;

ECG patterns;

blood glucose;

blood oxygen;

sleep;

body temperature;

physical activity;

reproductive health;

medication adherence;

neurological activity;

location;

physiological abnormalities; and

inferred medical conditions.

The legal problem becomes particularly serious when manufacturers, healthcare providers, insurers, employers, app developers, cloud providers or advertising platforms use that information for purposes beyond the original medical purpose.

European law does not currently have a single cause of action called "wearable medical-device data misuse." Instead, liability may arise through a combination of:

GDPR;

national civil-law principles;

medical confidentiality;

contractual obligations;

professional negligence;

consumer-protection law;

product-liability law;

privacy and personality rights;

breach of confidence;

unlawful commercial exploitation of personal information; and

Article 8 of the European Convention on Human Rights in cases involving State responsibility.

Health data receive particularly strong protection under European data-protection law. The European human-rights framework likewise treats medical information as highly sensitive. (ECHR)

2. What Is Wearable Medical-Device Data?

Wearable data can be divided into several categories.

A. Direct health data

These are measurements directly concerning the individual's health.

Examples:

blood glucose;

blood pressure;

ECG;

oxygen saturation;

body temperature;

heart rhythm.

These are generally the easiest to classify as "data concerning health".

B. Behavioral health data

Examples include:

sleeping patterns;

exercise levels;

calorie expenditure;

heart-rate variability;

daily movement;

rehabilitation activity.

Individually, some of these measurements might appear innocuous.

However, when combined they may reveal:

depression, pregnancy, cardiovascular disease, sleep disorders, physical disability or other medical conditions.

C. Inferred health information

This is especially important.

A device may not explicitly state:

"The user has cardiac disease."

Instead, an algorithm may infer a medical condition from:

heart-rate patterns;

oxygen levels;

sleep abnormalities;

exercise tolerance.

European data-protection law can protect information capable of revealing health status even where the health condition is inferred rather than expressly stated.

The CJEU has recently emphasized this broad approach to health data. (EUR-Lex)

3. Why Wearable Data Create Special Civil-Law Problems

Wearables create a continuous data stream.

A conventional medical record might contain:

"Patient's blood pressure: 150/95."

A wearable may generate:

millions of individual physiological observations over several months.

This creates several legal questions:

Who controls the data?

Who is the GDPR controller?

Is the device manufacturer a controller or processor?

Can data be reused for advertising?

Can an insurer purchase access?

Can an employer obtain health information?

Can the manufacturer combine wearable information with browsing data?

Can the information be sold to pharmaceutical companies?

Can an artificial-intelligence system infer diseases?

Can the data be retained indefinitely?

Can a patient demand deletion?

What compensation is available for unlawful processing?

4. European Legal Framework

4.1 GDPR

The GDPR is the central legal instrument.

Relevant provisions include:

Article 4(15)

Defines data concerning health.

Article 5

Establishes principles including:

lawfulness;

fairness;

transparency;

purpose limitation;

data minimization;

accuracy;

storage limitation;

integrity and confidentiality.

Article 6

Requires a lawful basis for processing.

Article 9

Provides enhanced protection for special categories of personal data, including health data.

Article 15

Right of access.

Article 16

Right to rectification.

Article 17

Right to erasure, subject to exceptions.

Article 18

Right to restriction of processing.

Article 20

Data portability.

Article 21

Right to object in specified circumstances.

Article 22

Protection against certain solely automated decisions.

Article 25

Data protection by design and by default.

Article 32

Security obligations.

Article 35

Data Protection Impact Assessments.

Article 82

Compensation for material and non-material damage resulting from GDPR infringements.

5. Six Major Types of Wearable Data Misuse

5.1 Unauthorized secondary use

A smartwatch may collect data for:

"monitoring your health."

The company may subsequently use the information for:

advertising;

profiling;

insurance analysis;

marketing;

behavioral prediction.

The question becomes whether this secondary purpose was legally authorized.

5.2 Sale or disclosure to third parties

Potential recipients could include:

insurance companies;

pharmaceutical companies;

employers;

advertising companies;

data brokers;

technology platforms.

Such transfers can create separate liability issues.

5.3 Excessive collection

A company may collect:

precise location;

microphone information;

contacts;

browsing history;

even though these are unnecessary for the medical functionality of the device.

This potentially conflicts with data minimization and purpose limitation.

5.4 Inadequate security

Suppose a wearable platform suffers a cyberattack exposing:

heart-rate histories;

reproductive-health information;

sleep records;

medication information.

The company may face claims concerning:

inadequate security;

GDPR breach;

confidentiality;

negligence;

contractual breach.

5.5 Algorithmic inference

An AI system may analyze wearable information and infer:

"This person is likely to develop cardiovascular disease."

If the inference is used to:

change insurance premiums;

deny employment;

market products;

make healthcare decisions;

additional legal issues arise.

5.6 Retention after withdrawal

A consumer may stop using the device and request deletion.

The company nevertheless retains years of historical health data.

The legality of continued retention depends on:

the original purpose;

applicable legal obligations;

consent;

legitimate legal grounds;

scientific/research exceptions;

public-health exceptions;

storage limitation requirements.

6. Important European Case Laws

Because litigation specifically involving smartwatches and medical wearables remains comparatively limited, European courts have developed the applicable principles through broader health-data, digital-platform and privacy cases.

It is therefore important not to mischaracterize these authorities as all being literal "smartwatch cases."

Case 1 — Österreichische Post AG, C-300/21

Background

The CJEU considered compensation under Article 82 GDPR for unlawful processing of personal data.

Importance

The judgment is particularly important because it concerns the threshold for compensable damage under the GDPR.

The existence of a GDPR infringement and the existence of compensable damage are related but distinct questions.

Wearable relevance

Suppose a wearable manufacturer unlawfully discloses an individual's:

heart-rate information;

fertility information;

sleep information.

The claimant must establish the legally relevant damage for a compensation claim.

Potential harm could include:

financial loss;

privacy intrusion;

distress;

loss of control over sensitive information;

reputational consequences.

The case is therefore important when determining whether unlawful wearable-data processing can generate compensation.

Case 2 — Meta Platforms and Others, C-252/21

This is one of the most important modern CJEU data-processing cases.

Background

The CJEU examined the processing of personal data by a major online platform and the interaction between GDPR requirements, legal bases and extensive data combination.

Principle

The Court stressed the strict nature of the GDPR requirements governing sensitive personal data.

Health-related data receive especially strong protection, and exceptions to the prohibition on processing special categories must be interpreted carefully. (EUR-Lex)

Wearable relevance

Imagine:

Smartwatch health data → wearable app → advertising profile → social-media advertising system.

The mere fact that the user agreed to general platform terms does not necessarily answer whether the processing of sensitive health data is lawful.

The legality of:

combining data;

profiling;

advertising;

targeted marketing;

must be separately examined.

Case 3 — Nowak v Data Protection Commissioner, C-434/16

Background

The CJEU interpreted the meaning of personal data broadly.

The case involved examination scripts and comments associated with an individual's examination performance.

Principle

The Court adopted a broad understanding of personal data, emphasizing information relating to an identifiable individual.

Wearable relevance

Wearable systems create enormous amounts of information that may not resemble conventional medical records.

Examples:

raw heart-rate readings;

movement data;

sleep cycles;

temperature;

timestamps;

device-generated scores.

Even if the company argues that the information is merely "technical data," the information may constitute personal data where it relates to an identifiable person.

Case 4 — Wirtschaftsakademie Schleswig-Holstein, C-210/16

Background

The CJEU examined the concept of joint controllership under the GDPR's predecessor framework.

A company operated a Facebook fan page while Facebook processed information concerning visitors.

Principle

An entity can have responsibility for processing even when it does not itself physically perform all of the data-processing operations.

Wearable relevance

This is extremely important for wearable ecosystems.

Consider:

Patient → wearable → manufacturer → health app → cloud provider → analytics company

Several entities may influence:

why data are collected;

what data are collected;

how they are used;

who receives them.

A manufacturer cannot necessarily escape responsibility simply by arguing:

"The cloud company actually processed the information."

The legal characterization of controllers, joint controllers and processors becomes central.

Case 5 — Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW, C-40/17

Background

The CJEU considered responsibility for processing personal data through an embedded third-party technology.

Principle

An organization may have data-protection responsibilities even where another company performs the actual technical processing.

Wearable relevance

The principle is highly relevant to:

wearable APIs;

embedded analytics;

third-party SDKs;

cloud services;

health-data dashboards.

Suppose a medical-device company incorporates a third-party analytics tool.

The manufacturer cannot necessarily argue:

"The analytics company collected the data, so the manufacturer has no responsibility."

The actual allocation of decision-making power must be examined.

Case 6 — I v Finland, Application No. 20511/03

Background

The applicant was an HIV-positive nurse who received treatment at a hospital where she also worked.

She suspected that colleagues had improperly accessed her medical records.

The European Court of Human Rights examined whether the State had provided adequate safeguards against unauthorized access.

Decision

The Court emphasized that sensitive medical data require strong safeguards against unauthorized access.

The Court found a violation of Article 8 because the national system did not provide adequate protection and traceability for access to the applicant's medical records. (Global Health Rights)

Wearable relevance

This is highly analogous to wearable medical data.

A health-data platform should ideally be able to establish:

who accessed the data;

when they accessed it;

what information they viewed;

whether access was authorized;

whether information was exported.

A system incapable of detecting unauthorized access can itself become part of the legal problem.

Case 7 — Z. v Finland, Application No. 22009/93

Background

The case concerned disclosure of the applicant's HIV status in judicial proceedings.

Principle

The ECtHR emphasized the exceptional sensitivity of medical information and the importance of medical confidentiality.

The Court stressed that confidentiality of health information is a fundamental principle and that disclosure requires particularly strong justification and safeguards. (ECHR)

Wearable relevance

Wearable information can reveal information comparable to traditional medical records.

For example:

continuous glucose monitoring can reveal diabetes;

reproductive-health tracking can reveal pregnancy;

ECG data can reveal cardiovascular conditions.

Unauthorized publication or disclosure of such information can therefore engage serious privacy interests.

Case 8 — S. and Marper v United Kingdom

Background

The applicants challenged indefinite retention of fingerprints, cellular samples and DNA profiles.

Principle

The ECtHR held that retaining sensitive biological information constitutes an interference with private life.

The Court emphasized that cellular samples contain highly sensitive information, including health-related and genetic information. (HUDOC)

Wearable relevance

Although the case concerned forensic biological material rather than wearable devices, it provides an important principle:

Retention itself can constitute a privacy interference.

A wearable company therefore cannot necessarily argue:

"We have not disclosed the health data, so there is no legal problem."

Long-term retention of highly sensitive physiological information may itself raise serious legal questions.

Case 9 — Ryneš v Úřad pro ochranu osobních údajů, C-212/13

Background

The CJEU considered whether video surveillance fell within the so-called household exemption.

Principle

The Court interpreted the personal/household exemption narrowly.

Wearable relevance

This becomes important when a wearable continuously collects:

location;

images;

audio;

environmental information;

information about other people.

A person cannot necessarily treat every wearable-related processing activity as a purely private household activity.

Where processing extends beyond genuinely personal activity, data-protection law may apply.

Case 10 — Breyer v Bundesrepublik Deutschland, C-582/14

Background

The case concerned dynamic IP addresses and whether information could constitute personal data where identification required additional information held by another party.

Principle

The CJEU adopted a functional approach to identifiability.

Wearable relevance

A company may claim that:

"The device ID is pseudonymized."

That does not necessarily mean that the information falls outside personal-data protection.

If the individual can reasonably be identified by combining information held by relevant parties, GDPR obligations may remain applicable.

This is especially important for:

pseudonymized wearable datasets;

device identifiers;

cloud accounts;

research datasets;

health-data analytics.

7. A Particularly Important 2026 Authority

AR and Others v Österreichische Datenschutzbehörde and Others, C-474/24

The CJEU Grand Chamber decided this case on 14 July 2026.

Although it concerns anti-doping information rather than wearable devices, it is highly relevant to the interpretation of health data.

The Court explained that whether information constitutes "data concerning health" depends upon its content and whether it reveals information about the health status of the person concerned. Where information qualifies as health data, Article 9's restrictions apply, subject to its specific exceptions. (EUR-Lex)

Importance for wearable devices

The case reinforces a substance-over-form approach.

A company cannot necessarily avoid Article 9 merely by labeling information:

"fitness data"

rather than:

"medical data."

If the information reveals a person's physical or medical condition, the GDPR's special-category protections may become relevant.

8. The Central Question: Is Wearable Data "Health Data"?

This is often the first legal question.

Consider the following:

Wearable informationLikely legal significance
ECG recordingClearly health-related
Blood glucoseClearly health-related
Blood oxygenPotentially health-related
Heart-rate historyContext-dependent, potentially health-related
Sleep patternsPotentially health-related
Step countMay initially appear ordinary
GPS locationPersonal data; may become health-related depending on context
Medication remindersStrong health implications
Fertility trackingHighly sensitive health information
Raw accelerometer dataContext-dependent
Algorithmic disease predictionPotentially highly sensitive

The critical question is not simply:

"What did the device call the data?"

It is:

What can the data reveal about an identifiable person's health?

9. Consent Problems

Many wearable applications rely heavily on consent.

However, valid consent under GDPR must satisfy legal requirements concerning:

specificity;

informed choice;

freedom;

clarity;

ability to withdraw.

A consent screen saying:

"By continuing, you agree to all data uses"

may be insufficient for every conceivable secondary purpose.

This becomes particularly problematic where a company seeks to combine health data with:

advertising profiles;

social-media activity;

shopping behavior;

location histories.

10. Commercial Exploitation of Wearable Health Data

Imagine a company collects:

heart-rate + sleep + exercise + menstrual-cycle + location data.

It then sells analytical information to advertisers.

Potential legal issues include:

unlawful processing;

incompatible secondary purpose;

inadequate consent;

failure of transparency;

violation of data minimization;

unlawful profiling;

failure to establish an Article 9 condition;

inadequate security;

unlawful international transfer.

11. Employer Misuse

Wearable medical devices can create significant employment-law problems.

Suppose an employer encourages workers to use a health-tracking device.

The employer subsequently discovers:

Employee A has an irregular sleep pattern and high resting heart rate.

The employer uses this information to decide:

promotion;

dismissal;

scheduling;

performance evaluation.

This may create serious concerns under:

GDPR;

employment law;

anti-discrimination principles;

privacy law;

national constitutional law.

The employer-employee relationship also raises questions about whether purported "consent" was genuinely freely given.

12. Insurance Misuse

A particularly sensitive scenario is:

Wearable → health data → insurance company → premium decision.

For example, an insurer might attempt to infer:

probability of cardiac disease;

lifestyle habits;

pregnancy;

sleep disorders;

physical inactivity.

Potential legal issues include:

unlawful processing;

profiling;

discrimination;

transparency;

automated decision-making;

purpose limitation.

The legal analysis becomes particularly complex where the original device was marketed as a medical or wellness product but the data are later used for financial risk assessment.

13. Data Breach Scenario

Suppose a hacker accesses a wearable manufacturer's cloud database containing:

500,000 ECG records;

sleep histories;

blood-glucose readings;

user identities.

Potential legal consequences may include:

Regulatory

Data-protection authority investigation.

Civil

Compensation claims by affected individuals.

Contractual

Claims based on contractual promises of security or confidentiality.

Consumer law

Claims concerning misleading security representations.

Medical confidentiality

Potential additional duties where healthcare professionals are involved.

14. Civil Liability for Inaccurate Data

Wearable devices can also generate incorrect information.

Suppose:

A wearable incorrectly reports repeated arrhythmia events.

The user becomes alarmed and purchases unnecessary medical treatment.

Alternatively:

The device fails to detect a dangerous medical event.

This creates two separate legal questions:

Data-protection liability

Was inaccurate personal data processed?

Product/service liability

Was the device or software defective?

These claims should not be confused.

A defective medical device may potentially generate liability independently of GDPR liability.

15. Product Liability Dimension

Modern wearable medical products can involve:

hardware;

embedded software;

cloud software;

algorithms;

mobile applications;

artificial intelligence.

European product-liability law has been evolving to address digital products and software.

Accordingly, a claimant may potentially pursue parallel theories:

defective device + defective software + unlawful data processing

The fact that a product is technologically sophisticated does not eliminate ordinary civil-law requirements such as:

defect;

damage;

causation.

16. Data Controller and Processor Issues

A wearable ecosystem may involve:

User

↓

Wearable manufacturer

↓

Mobile application

↓

Cloud-hosting provider

↓

Analytics company

↓

Healthcare provider

↓

Advertising/marketing company

The legal question is not merely:

"Who possesses the data?"

It is:

Who determines the purposes and means of processing?

The CJEU's decisions in Wirtschaftsakademie and Fashion ID are particularly important because responsibility may extend beyond the entity physically performing the technical processing.

17. Joint Controllers

Suppose:

Manufacturer determines why health data are collected;

healthcare provider determines medical purposes;

analytics company determines certain analytics purposes.

Depending on the precise arrangement, more than one entity could potentially qualify as a controller or joint controller.

This is important because a company cannot necessarily avoid responsibility by outsourcing processing.

18. Data Minimization

The GDPR requires personal data to be:

adequate, relevant and limited to what is necessary for the relevant purpose.

Suppose a glucose-monitoring device requires:

glucose levels;

timestamps.

But the application additionally collects:

precise GPS;

contact lists;

microphone recordings;

browsing history.

The additional information may require separate justification.

The central question is:

Is each category of information genuinely necessary for the stated purpose?

19. Purpose Limitation

Suppose the original purpose is:

"monitoring cardiovascular health."

The company subsequently uses the same information for:

"targeted advertising."

The legality of that secondary use must be independently assessed.

A broad privacy policy does not automatically make every future use lawful.

20. Data Retention

Wearable companies may retain years of historical data.

But indefinite storage raises questions under:

storage limitation;

necessity;

purpose limitation;

security;

erasure rights.

The reasoning in S. and Marper is particularly useful by analogy because it demonstrates that retaining sensitive personal information can itself constitute a privacy interference. (HUDOC)

21. Remedies Available to Victims

A victim may potentially seek:

1. Access

Obtain a copy of the data being processed.

2. Rectification

Correct inaccurate health information.

3. Erasure

Request deletion where Article 17 applies.

4. Restriction

Limit processing.

5. Objection

Object to certain processing activities.

6. Compensation

Claim compensation for qualifying material or non-material damage under Article 82 GDPR.

7. Injunctions

National civil courts may, depending upon national procedural law, provide injunctive relief.

8. Regulatory complaint

A complaint may be filed with the relevant data-protection supervisory authority.

22. Evidence in Wearable-Data Litigation

Evidence can include:

device logs;

application logs;

privacy policies;

consent screens;

API documentation;

data-processing agreements;

data-access records;

server logs;

cloud-storage records;

data-breach reports;

algorithmic documentation;

expert evidence.

Particularly important evidence

Audit logs.

If the system records:

User A → Employee B → accessed ECG data → 14:32 → downloaded file

the evidence may establish unauthorized access.

If the system does not maintain adequate access records, that itself can become legally significant.

23. Causation in Civil Claims

A claimant must distinguish between:

Unlawful processing

and

Recoverable damage.

For example:

Company unlawfully collected heart-rate data.

That establishes a potential GDPR infringement.

But the claimant may additionally need to demonstrate legally compensable harm for an Article 82 damages claim.

Possible damage may include:

financial loss;

identity-related harm;

serious privacy intrusion;

psychological distress;

reputational damage;

exposure of intimate medical information.

The precise requirements are governed by European and national law.

24. Hypothetical Example

Assume a European company sells a medical smartwatch.

The device collects:

ECG data;

blood oxygen;

sleep patterns;

heart rate;

location.

Its privacy notice says:

"We process data to provide health-monitoring services."

The company subsequently sends individualized health profiles to an advertising company.

The advertising company identifies users likely to suffer from:

insomnia;

cardiovascular conditions;

anxiety.

Potential legal claims

The consumer could potentially argue:

unlawful processing of special-category data;

lack of an appropriate Article 9 condition;

lack of transparency;

violation of purpose limitation;

excessive data sharing;

unlawful profiling;

inadequate security;

compensation under Article 82;

national civil-law privacy claims.

25. Comparison of the Major Authorities

CaseMain principleWearable relevance
Österreichische Post, C-300/21GDPR compensationDamages for unlawful health-data processing
Meta Platforms, C-252/21Lawfulness and sensitive dataCombining health data with other datasets
Nowak, C-434/16Broad personal-data conceptWearable-generated information
Wirtschaftsakademie, C-210/16Joint controllershipManufacturer/app relationships
Fashion ID, C-40/17Responsibility for embedded processingAPIs and third-party analytics
Ryneš, C-212/13Household exemptionWearable surveillance/data collection
Breyer, C-582/14IdentifiabilityPseudonymized wearable datasets
I v FinlandMedical-data securityUnauthorized access to health information
Z v FinlandMedical confidentialityDisclosure of wearable health information
S. and MarperRetention of sensitive dataLong-term wearable-data retention
AR and Others, C-474/24Meaning of health dataClassification of inferred physiological information

26. Key Legal Principles

The European case law supports several important conclusions.

First

Health information receives enhanced protection.

Medical information is among the most sensitive categories of personal information in European law. (ECHR)

Second

The label used by a technology company is not decisive.

Calling information "fitness data" does not necessarily prevent it from being treated as health data where it reveals health status.

Third

Outsourcing does not automatically eliminate responsibility.

The controller/processor/joint-controller analysis remains critical.

Fourth

Retention itself can be legally significant.

A company cannot necessarily justify indefinite retention simply because information has not yet been publicly disclosed.

Fifth

Medical confidentiality is particularly strong.

The ECtHR has repeatedly emphasized the importance of safeguards against unauthorized disclosure and access to medical information. (ECHR)

Sixth

GDPR and civil law can operate simultaneously.

A claimant may potentially combine:

GDPR claim + contractual claim + negligence claim + confidentiality/privacy claim + product-liability claim.

27. Conclusion

Wearable medical-device data misuse represents an emerging European civil-law problem at the intersection of data protection, privacy, consumer law, medical confidentiality and product liability.

The most important legal issue is that wearable devices can transform ordinary physical activity into an extraordinarily detailed medical profile. A single device can reveal:

cardiovascular condition;

sleep disorders;

reproductive information;

physical disability;

medication effects;

lifestyle patterns;

potentially future health risks.

European law therefore approaches such information with heightened sensitivity.

The most useful authorities include Österreichische Post, Meta Platforms, Nowak, Wirtschaftsakademie, Fashion ID, Ryneš, Breyer, I v Finland, Z v Finland, and S. and Marper, while the 2026 AR and Others judgment in C-474/24 provides an especially current interpretation of the concept of health data. (EUR-Lex)

For a civil claim, the strongest analytical structure is generally:

1. Identify the data → 2. establish whether it is personal/health data → 3. identify the controller → 4. determine the legal basis → 5. examine Article 9 → 6. assess purpose limitation and minimization → 7. examine security/confidentiality → 8. establish breach → 9. establish damage → 10. establish causation → 11. determine the appropriate remedy.

Because reported European litigation specifically involving wearable medical devices is still developing, the established health-data and digital-platform cases are especially important for predicting how courts are likely to approach future smartwatch, smart-ring, glucose-monitor and connected-medical-device disputes.

LEAVE A COMMENT