Health data collection through wearables.

 

Health Data Collection Through Wearables

1. Introduction

Health data collection through wearables refers to the collection, processing, storage, and use of an individual's health and physiological information through devices such as smartwatches, fitness bands, smart rings, glucose monitors, heart-rate monitors, sleep trackers, and other connected devices.

These devices can collect information such as:

  • Heart rate and heart-rate variability
  • Blood oxygen levels
  • Sleep patterns
  • Physical activity and step count
  • Body temperature
  • Blood glucose levels
  • Blood pressure
  • Menstrual and reproductive information
  • Location and movement patterns
  • Exercise and fitness information
  • In some cases, information indicating illness or medical conditions

The legal significance of wearable health data is considerable because such information can reveal highly personal aspects of an individual's physical condition, lifestyle, habits, and sometimes medical status.

2. Why Wearable Health Data Raises Legal Concerns

Wearables continuously or periodically collect information about individuals. Unlike a traditional medical examination, the data may be generated throughout the day and across different environments.

This creates several concerns:

  1. Privacy
  2. Consent
  3. Purpose limitation
  4. Data security
  5. Employee monitoring
  6. Discrimination
  7. Third-party sharing
  8. Profiling
  9. Retention of health information
  10. Cross-border transfer of data

For employers, the issue becomes particularly sensitive when employees are asked or encouraged to use wearable devices for workplace wellness, productivity, insurance, attendance, safety, or performance-monitoring programmes.

3. Wearable Health Data as Personal Information

Health information can be directly or indirectly connected to an identifiable individual.

For example, a smartwatch may generate:

"Heart rate: 112 bpm at 10:35 a.m."

Standing alone, this may appear to be merely physiological information. However, when associated with an employee account, device ID, email address, employee number, or other identifier, it can become personal information relating to that individual.

A collection of data can be even more revealing:

  • Employee identity
  • Heart rate
  • Sleep duration
  • Exercise patterns
  • Location
  • Medication reminders
  • Blood glucose information

Together, these may create a detailed profile of the individual.

4. Indian Constitutional Framework

Right to Privacy

The most important constitutional decision concerning personal data is:

Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1

A nine-judge Bench of the Supreme Court recognised privacy as a fundamental right under Article 21 and the broader guarantees of Part III of the Constitution.

The judgment recognised different dimensions of privacy, including informational privacy.

This is highly relevant to wearable technology because health and physiological information can reveal intimate details about an individual.

Therefore, collection of wearable health information should be examined through principles of:

  • legality
  • legitimate purpose
  • necessity
  • proportionality
  • procedural safeguards

5. Consent for Wearable Health Data

Consent is particularly important where an organisation collects health information through an employee's wearable.

Consent should ordinarily be:

  • informed
  • specific
  • meaningful
  • freely given where consent is the legal basis
  • capable of withdrawal where applicable

Simply stating:

"By participating in the wellness programme, you agree to all data collection"

may not provide adequate transparency if the organisation actually collects heart rate, sleep, location, reproductive information, or other sensitive information.

The individual should know:

  • What information is collected
  • Why it is collected
  • Who receives it
  • How long it will be retained
  • Whether participation is mandatory
  • Whether the information will affect employment decisions
  • Whether information is shared with insurers or other third parties

6. Employment Context

The collection of wearable health data becomes more complicated when an employer is involved.

An employee may technically agree to use a wearable but may feel compelled to participate because of:

  • workplace pressure
  • incentives
  • performance evaluations
  • promotion concerns
  • insurance benefits
  • managerial expectations

Therefore, the voluntariness of consent should be carefully examined.

Employers should avoid using health information to make unjustified decisions concerning:

  • recruitment
  • promotion
  • termination
  • salary
  • performance ratings
  • disciplinary action
  • work allocation

7. Employee Monitoring Through Wearables

An employer could theoretically use wearable information to determine:

  • Whether employees are physically active
  • Whether they are sleeping adequately
  • Whether they have attended a particular location
  • Whether their heart rate changes during work
  • Whether they are taking sufficient breaks
  • Whether they are physically fit

Such extensive monitoring can create serious privacy concerns.

The fact that technology can collect information does not necessarily mean that an employer should collect it.

The principle of proportionality requires the employer to consider whether the same objective can be achieved using less intrusive means.

8. Purpose Limitation

Information collected for one purpose should not automatically be used for another unrelated purpose.

For example:

Original purpose:

Employee voluntarily participates in a fitness programme.

Subsequent use:

Employer uses wearable data to identify employees who may have health problems.

The second use may raise significant legal and ethical concerns.

Similarly, information collected for workplace safety should not automatically become a tool for employee performance surveillance.

9. Data Minimisation

Organisations should collect only the information reasonably necessary for the identified purpose.

For example, if the purpose is simply to count steps during a voluntary wellness programme, collecting:

  • exact GPS location,
  • heart-rate history,
  • sleep patterns,
  • reproductive information,

may be excessive unless there is a specific and lawful reason for doing so.

A privacy-conscious system should ask:

What is the minimum amount of information required to achieve the objective?

10. Security of Wearable Health Data

Wearable information can be transmitted through:

  • Bluetooth
  • smartphones
  • cloud platforms
  • employer systems
  • health applications
  • third-party analytics providers

Security safeguards should therefore address:

  • encryption
  • authentication
  • access controls
  • secure APIs
  • device security
  • breach detection
  • incident response
  • appropriate retention and deletion

A security failure could expose extremely sensitive information.

11. Third-Party Sharing

Wearable manufacturers and applications may use third-party service providers for:

  • cloud storage
  • analytics
  • advertising
  • insurance services
  • healthcare services
  • research

Organisations should clearly identify such disclosures.

An employee should not discover later that information collected for a workplace wellness programme was transferred to another company for an unrelated purpose.

12. Profiling and AI

Wearable data can be combined with artificial intelligence to create predictions or classifications.

For example:

"Employee A has a high probability of stress."

or

"Employee B may have a health-related productivity risk."

Such conclusions may be inaccurate.

A major legal concern arises if an automated prediction affects employment decisions.

Health-related profiling can result in:

  • discrimination
  • stereotyping
  • wrongful denial of opportunities
  • unfair insurance consequences
  • employment disadvantage

Therefore, organisations should not treat algorithmic predictions as automatically accurate or legally sufficient.

13. Data Protection and Indian Law

India's data-protection framework is particularly relevant to wearable health information.

The Digital Personal Data Protection Act, 2023 regulates processing of digital personal data and establishes obligations concerning lawful processing, notice, consent, security safeguards, breach-related obligations and other matters.

Wearable information that is linked or reasonably linkable to an identifiable individual can fall within the broader framework of digital personal data.

Organisations should therefore establish appropriate policies for:

  • collection
  • notice
  • consent where applicable
  • processing
  • security
  • retention
  • deletion
  • grievance handling
  • third-party processing

14. Case Laws

1. Justice K.S. Puttaswamy (Retd.) v. Union of India, (2017) 10 SCC 1

This is the leading Indian privacy decision.

The Supreme Court recognised privacy as a fundamental right and specifically discussed informational privacy.

Relevance

Health information generated by wearables can reveal highly intimate information. Its collection and processing must therefore respect constitutional privacy principles, particularly where the State or State-linked institutions are involved.

2. K.S. Puttaswamy (Retd.) v. Union of India, (2019) 1 SCC 1

The Supreme Court subsequently examined the Aadhaar framework and the relationship between privacy and data collection.

The Court emphasised concerns relating to the collection and use of personal information and the need for safeguards.

Relevance

The case illustrates that large-scale collection of personal information must be accompanied by appropriate legal safeguards and cannot be justified merely because technology makes collection possible.

3. People's Union for Civil Liberties (PUCL) v. Union of India, (1997) 1 SCC 301

The Supreme Court considered telephone interception and recognised the serious privacy implications of surveillance.

The Court required procedural safeguards for interception.

Relevance

Although the case did not concern wearables, its principles are relevant to technologically enabled monitoring. Continuous collection of employee physiological information can resemble a form of surveillance and therefore requires appropriate safeguards.

4. Mr. X v. Hospital Z, (1998) 8 SCC 296

The Supreme Court examined confidentiality concerning medical information.

The case recognised the importance of maintaining confidentiality of medical information, while also considering circumstances in which disclosure may be justified.

Relevance

Health information obtained through a wearable should not automatically become freely available to managers, co-workers, insurers, or other third parties.

5. Suchita Srivastava v. Chandigarh Administration, (2009) 9 SCC 1

The Supreme Court strongly recognised personal autonomy in matters involving reproductive choices.

Relevance

Wearables can potentially collect information concerning reproductive cycles and related physiological characteristics. The principle of personal autonomy reinforces the need to respect an individual's control over deeply personal information.

6. Selvi v. State of Karnataka, (2010) 7 SCC 263

The Supreme Court considered involuntary techniques involving the extraction of personal information from individuals, including narco-analysis and related techniques.

The Court emphasised personal liberty, mental privacy and protection against compelled extraction of personal information.

Relevance

While wearable technology is fundamentally different, the case provides an important conceptual principle: highly personal information should not be obtained or used through coercive methods without adequate legal justification.

7. District Registrar and Collector, Hyderabad v. Canara Bank, (2005) 1 SCC 496

The Supreme Court examined privacy interests in documents and personal information.

Relevance

The decision supports the broader principle that access to personal information by authorities must have a legitimate legal basis and cannot be treated as unlimited merely because information is capable of being accessed.

8. R. Rajagopal v. State of Tamil Nadu, (1994) 6 SCC 632

The Supreme Court recognised the right to privacy and protection against unwarranted publication of private matters.

Relevance

Information obtained from a wearable may concern an individual's private life. Organisations should therefore avoid unnecessary publication or disclosure of such information.

15. Employer Best Practices

Employers using wearable technology should:

  1. Prepare a clear wearable-data policy.
  2. Identify the exact data collected.
  3. Explain the purpose of collection.
  4. Avoid unnecessary data collection.
  5. Separate wellness data from performance-management systems.
  6. Restrict managerial access.
  7. Use anonymised or aggregated data wherever possible.
  8. Establish appropriate retention periods.
  9. Secure data through technical and organisational safeguards.
  10. Clearly identify third-party processors.
  11. Provide a mechanism for employees to raise concerns.
  12. Avoid discriminatory use of health information.
  13. Conduct privacy and proportionality assessments before introducing continuous monitoring.
  14. Establish procedures for responding to data breaches.
  15. Review whether participation is genuinely voluntary.

16. Important Distinction: Wellness vs Surveillance

A voluntary wellness programme may be legitimate where the employer collects limited information to provide general health benefits.

However, the same technology can become problematic if the employer begins monitoring employees continuously.

For example:

Lower-risk approach:

Employees voluntarily participate and the employer receives only aggregated step-count statistics.

Higher-risk approach:

The employer receives individual employees' heart rate, sleep, GPS and health information and uses it to evaluate employee performance.

The second arrangement raises substantially greater privacy, proportionality and discrimination concerns.

17. Conclusion

Health data collected through wearables is increasingly important in employment and data-protection law. Such devices can provide useful information for healthcare, safety and voluntary wellness programmes, but they can also facilitate continuous and highly intrusive monitoring.

The central legal principles are privacy, informed choice, purpose limitation, data minimisation, security, confidentiality, proportionality and accountability.

The decision in Justice K.S. Puttaswamy v. Union of India is particularly significant because informational privacy forms part of the constitutional right to privacy. Other decisions concerning medical confidentiality, surveillance, autonomy and personal information—including Mr. X v. Hospital Z, PUCL v. Union of India, Selvi v. State of Karnataka and R. Rajagopal v. State of Tamil Nadu—provide useful principles for assessing wearable-health-data practices.

Accordingly, employers and organisations should ensure that wearable health data is collected only for a legitimate and clearly communicated purpose, limited to what is necessary, adequately protected, and never converted into unjustified employee surveillance or discriminatory decision-making.

LEAVE A COMMENT