Who knew you were pregnant before you did?
There’s a story doing the rounds this week about a woman whose fitness tracker flagged her pregnancy weeks before a test did. Elevated resting heart rate, a shift in temperature, the usual pattern. It’s a nice human interest story, and it’s also, if you sit with it for a minute, a fairly uncomfortable one.
Most people don’t tell their employer they’re pregnant until well past the first scan. Plenty don’t tell their own parents. It’s one of the last pieces of genuinely private news most of us get to control the timing of. And yet a growing number of devices sitting on people’s wrists already know, often before the person wearing them has worked it out themselves.
The interesting question isn’t whether a tracker can spot the physiological signs. It can, and that’s well documented. The interesting question is who else has access to that inference once it exists, and what they’re allowed to do with it.
The gap most people assume isn't there
There’s a common assumption that health data is automatically protected in a way ordinary data isn’t. In the US that assumption is largely wrong. HIPAA only applies to hospitals, insurers, and their direct business associates. A consumer wearable company selling you a wristband is none of those things, so the strict health privacy rules people expect simply don’t apply.
UK and EU users are in a better position on paper. Under UK GDPR, health data is a special category, which means it needs a specific lawful basis and, usually, explicit consent before it can be processed. The trouble is that consent gets given once, in a wall of small print during setup, and it rarely limits what happens three steps down the chain once that data has been shared with a partner, an analytics provider, or an advertising network.
A Duke University study found that 79% of popular health and fitness apps share user data with third parties. Only 28% of the people using those apps were aware of it. Separate research from Mozilla put third-party sharing even higher, and found some fitness apps passing data to Meta and Google even when the user had set their account to private. That’s the mechanism behind the running shoe adverts that turn up the day after a jog you never posted about.
The cheaper the device, the murkier the chain
The big brands at least publish a privacy policy and have a reputation to protect, however loosely they interpret it. The budget end of the market, the unbranded trackers that turn up as Amazon’s Choice for under twenty pounds, is a different picture entirely.
Research from Princeton looked specifically at that segment and found the majority run on a small handful of generic companion apps built by tiny teams, with little or no meaningful explanation of how data is used or where it goes. One of the most common, used across several popular budget brands, routes data through data centres overseas. There’s no clear accountable controller to send a subject access request to, and often no realistic route to find out what’s actually being collected, let alone stop it.
If a twenty pound gadget from a marketplace listing can infer a pregnancy, it can just as easily infer a fertility struggle, a mental health pattern from disrupted sleep, or heavy drinking from resting heart rate variability. None of that requires the device to be sophisticated. It just requires the data to sit somewhere for long enough, and a change in ownership, a partnership, or a breach to bring it into contact with someone who has a reason to use it.
Where this becomes an organisational problem
This stops being a consumer curiosity the moment an organisation gets involved, and a lot of organisations already are. Wellness schemes that hand out or subsidise fitness trackers as a staff benefit are common, and well intentioned. Few of them have been through a proper assessment of what they’ve actually taken on.
If an employer provides the device, part-funds it, or runs a linked challenge or leaderboard through the app, there’s a reasonable argument that the organisation has stepped into a data controller or joint controller role for special category data. That brings obligations most wellness initiatives were never built around: a proper lawful basis, freely given consent that staff can withdraw without penalty, and in most cases a Data Protection Impact Assessment before rollout rather than after someone asks an awkward question.
Insurers and occupational health providers are moving into this space too, using wearable data to inform premiums or return-to-work decisions. That’s a legitimate use in principle, but it needs a contract that says explicitly what’s collected, who processes it, where it’s stored, and how long it’s kept, not a vague assumption that the tracker vendor has it covered.
The practical advice for anyone procuring or approving a wellness scheme is the same advice that applies to any new data source: find out who the controller is before you find out how many staff have signed up. Ask the vendor directly where the data goes after it leaves their app, get it in writing, and treat a wearable programme as a data processing decision rather than a wellbeing perk that happens to involve data.
Worth Remembering
Pregnancy makes a good headline because everyone understands instantly why the timing matters. But the same inference chain works quietly for a lot of things people would rather keep to themselves, and most of us have no real visibility into how far our own data has already travelled. The device on your wrist isn’t the risk. The list of everyone it’s quietly been introduced to is.



