Civil Law And Wearable Bio-Sensor Data Misuse Litigation In Europe .
Civil Law and Wearable Bio-Sensor Data Misuse Litigation in Europe
1. Introduction
Wearable bio-sensor data misuse litigation concerns disputes arising from the collection, analysis, disclosure, sale, sharing, or other misuse of information generated by wearable devices such as:
smartwatches;
fitness trackers;
continuous glucose monitors;
heart-rate monitors;
sleep trackers;
smart rings;
connected medical devices;
biometric fitness devices;
rehabilitation sensors;
connected sports equipment.
These devices can generate extremely detailed information about a person, including:
heart rate;
heart-rate variability;
blood oxygen levels;
sleep patterns;
body temperature;
glucose levels;
physical activity;
location;
menstrual-cycle information;
stress indicators;
respiratory patterns;
ECG information;
biometric identifiers;
inferred health conditions.
The legal problem is therefore considerably broader than ordinary data theft. A wearable may continuously generate information that, individually or when combined with other information, can reveal a person's physical or mental health status.
Under European law, this can trigger the enhanced protection applicable to special categories of personal data, particularly health data. The CJEU has adopted a broad approach: information can qualify as health data where it is capable of revealing health status through deduction or combination with other information. (EUR-Lex)
Wearable-data litigation consequently sits at the intersection of:
contract law;
tort/delict law;
data-protection law;
consumer protection;
medical-device regulation;
privacy and personality rights;
confidentiality;
cybersecurity;
product liability; and
fundamental rights.
2. What Is Wearable Bio-Sensor Data?
A wearable device may collect two broad categories of information.
A. Directly observed information
Examples include:
pulse rate;
body temperature;
blood oxygen;
glucose level;
movement;
GPS location.
B. Inferred information
Algorithms may use sensor data to infer:
stress;
sleep disorders;
cardiovascular conditions;
pregnancy;
fertility;
physical fitness;
emotional states;
potential disease;
behavioural patterns.
The second category is particularly important.
A company may argue:
"We never collected a diagnosis."
But if its algorithm uses heart-rate, sleep and activity data to infer a person's medical condition, the resulting information can potentially fall within the GDPR's broad concept of health data.
The CJEU has confirmed that information capable of revealing health status through an intellectual operation involving collation or deduction may constitute health data. (EUR-Lex)
3. Why Wearable Data Is Legally Sensitive
Wearables can create a continuous record of a person's life.
For example, a smartwatch might reveal:
02:15 — heart rate increased
02:17 — movement detected
02:30 — sleep interrupted
03:00 — elevated heart rate
06:45 — exercise commenced
Over weeks or months, such information can create a highly detailed behavioural and health profile.
The European Data Protection Board recognises health information as highly sensitive and subject to enhanced protection under the GDPR. (European Data Protection Board)
The legal concern is therefore not merely:
"Who owns the smartwatch?"
but:
Who controls the information generated by the smartwatch, for what purpose, on what legal basis, and with what safeguards?
4. Principal Legal Framework
The central European instrument is the General Data Protection Regulation (GDPR).
Important provisions include:
Article 4
Defines:
personal data;
processing;
controller;
processor;
health data.
Article 5
Establishes principles including:
lawfulness;
fairness;
transparency;
purpose limitation;
data minimisation;
accuracy;
storage limitation;
integrity and confidentiality.
Article 6
Requires a lawful basis for processing personal data.
Article 9
Provides enhanced protection for special categories, including health data.
Articles 12–14
Concern transparency and information.
Articles 15–22
Provide rights including:
access;
rectification;
erasure;
restriction;
portability;
objection;
rights relating to automated decision-making.
Article 25
Requires data protection by design and by default.
Article 32
Requires appropriate security measures.
Article 35
Can require a Data Protection Impact Assessment for high-risk processing.
Article 82
Provides compensation for material and non-material damage resulting from GDPR infringement.
5. Health Data Under Article 9
Article 9 establishes a general prohibition on processing special-category data, subject to specified exceptions.
For wearable companies, potentially relevant exceptions include:
explicit consent;
employment/social-security situations where legally authorised;
vital interests;
healthcare;
public-health purposes;
scientific research under applicable safeguards.
The important point is that ordinary consent to use a wearable does not automatically authorise every possible secondary use of the resulting health data.
A company may therefore face difficulty arguing:
"The customer agreed to the terms and conditions, so we can use all sensor information for advertising."
The lawful basis and the specific purpose of processing must be examined.
6. Case Law 1 — Lindenapotheke, C-21/23
ND v DR (Lindenapotheke), CJEU, Grand Chamber, 4 October 2024
This is one of the most important recent CJEU decisions for wearable-data litigation.
Facts
A German pharmacist sold medicinal products through an online platform.
Customers provided information including:
name;
delivery address;
information about medicines ordered.
A competing pharmacist challenged the processing.
Legal issue
The CJEU considered whether the information could constitute health data under Article 9 GDPR.
Judgment
The Court adopted a broad interpretation of health data.
Information may qualify as health data if it can reveal information concerning an identifiable person's health through deduction or combination.
The Court emphasised that the enhanced protection cannot be avoided simply because the information is not itself a medical diagnosis. (EUR-Lex)
Importance for wearables
This principle is directly relevant to:
heart-rate information;
sleep information;
glucose measurements;
menstrual-cycle data;
exercise patterns;
physiological measurements.
For example:
A wearable company records sleep and heart-rate data. An algorithm concludes that a user may suffer from a particular health condition.
The resulting inference may receive enhanced GDPR protection.
7. Case Law 2 — Vyriausioji tarnybinės etikos komisija, C-184/20
CJEU, 1 August 2022
This case concerned publicly disclosed information that could indirectly reveal sensitive personal information.
Principle
The CJEU interpreted the concept of special-category data broadly and stressed that information indirectly capable of revealing sensitive information can fall within enhanced protection. (curia)
Importance for wearables
Wearable companies frequently argue that certain individual measurements are harmless.
But consider:
resting heart rate;
sleep patterns;
location at a hospital;
exercise frequency;
medication reminders.
Individually, each item may appear innocuous.
Combined together, they can reveal:
"This individual may have a particular health condition."
The CJEU's reasoning therefore strongly supports examining what the data reveal when combined, rather than looking at each sensor measurement in isolation.
8. Case Law 3 — Meta Platforms and Others, C-252/21
CJEU, 4 July 2023
This major case concerned processing of personal data by Meta and the relationship between GDPR requirements, consent and other legal bases.
Importance
The CJEU stressed the strict requirements governing lawful processing and the special protection applicable to sensitive information.
It is particularly relevant to situations where a company attempts to justify extensive data processing through broad contractual terms or advertising arrangements.
Wearable application
Suppose a wearable company states:
"By using this device, you agree that your health, fitness and behavioural information may be used to personalise advertisements."
That does not end the legal analysis.
The company must still establish:
appropriate legal basis;
compliance with Article 9 where applicable;
transparency;
purpose limitation;
necessity;
proportionality.
The CJEU's case law makes clear that processing sensitive data cannot simply be normalised through broad commercial arrangements.
9. Case Law 4 — Österreichische Post, C-300/21
CJEU, 4 May 2023
This case is especially important because it concerns compensation.
Facts
Österreichische Post processed information about individuals and generated political-affinity profiles.
The claimant alleged distress and a feeling of exposure.
Judgment
The CJEU held that:
GDPR infringement alone does not automatically create a right to compensation;
the claimant must establish damage;
there is no requirement that non-material damage reach a particular minimum seriousness threshold. (curia)
Importance for wearables
Imagine a company unlawfully discloses a user's:
heart-rate data;
fertility information;
sleep records;
glucose information.
The user cannot necessarily obtain damages merely by proving:
"The GDPR was breached."
The claimant must establish:
GDPR infringement + damage + causal connection.
But the absence of a minimum seriousness threshold is important.
Potential non-material harm could include:
distress;
anxiety;
loss of control;
exposure;
fear of misuse.
10. Case Law 5 — Natsionalna agentsia za prihodite, C-340/21
CJEU, 14 December 2023
This case arose from a major personal-data security incident.
Principle
The Court addressed the consequences of unlawful disclosure and the concept of non-material damage.
Importantly, the Court recognised that fear of possible misuse of personal data can constitute non-material damage in appropriate circumstances. (Court of Justice of the European Union)
Wearable application
Suppose a wearable company's database is hacked and millions of records are exposed.
The records include:
heart-rate histories;
sleep data;
location;
biometric information.
Even if there is no evidence that a criminal has yet used every individual's data, the affected person may potentially argue that the well-founded fear of misuse constitutes non-material damage.
However, the claimant still has to establish actual damage rather than relying solely on the existence of a GDPR infringement.
11. Case Law 6 — MediaMarktSaturn, C-687/21
CJEU, 25 January 2024
This case further developed Article 82 GDPR jurisprudence.
Principle
The Court reiterated that:
infringement;
damage;
causation
are cumulative requirements.
However, non-material damage does not need to meet an artificial minimum seriousness threshold. (InfoCuria)
Wearable relevance
Suppose an employee's employer improperly accesses wearable information showing:
sleep quality;
stress levels;
heart rate;
physical activity.
The employee may seek compensation where the unlawful processing causes actual non-material damage.
The claim is stronger if the claimant can demonstrate:
anxiety;
humiliation;
fear of workplace discrimination;
loss of control;
exposure of intimate information.
12. Case Law 7 — Krankenversicherung Nordrhein, C-667/21
CJEU, 21 December 2023
This case concerned health-related data and the requirements governing lawful processing.
Importance
The Court emphasised that processing health data must satisfy both:
the requirements of the relevant Article 9 exception; and
the general Article 6 lawfulness requirements.
In other words, an Article 9 justification does not eliminate the need to satisfy Article 6. (EUR-Lex)
Wearable relevance
A wearable health company might say:
"We process the data for health purposes."
That statement alone is insufficient.
The company must still establish the complete legal basis for the processing.
13. Case Law 8 — Österreichische Datenschutzbehörde and Others, C-474/24
AR and Others v Österreichische Datenschutzbehörde and Others, Grand Chamber, 14 July 2026
This is particularly relevant because it is a recent 2026 CJEU judgment.
Issue
The case concerned whether information relating to anti-doping violations constituted health data.
Important principle
The Court explained that health data cover personal data revealing information about past, current or future physical or mental health status.
The Court also reaffirmed the broad interpretive approach to health data, including situations involving information capable of revealing health status through deduction. (EUR-Lex)
Relevance to wearable litigation
Wearable devices are frequently used in:
professional sport;
fitness;
athletic performance;
health monitoring.
The judgment illustrates that courts will need to carefully distinguish between:
ordinary performance information
and
information that reveals or permits inference concerning health.
That distinction can determine whether Article 9's enhanced protections apply.
14. Case Law 9 — Lindqvist, C-101/01
CJEU, 6 November 2003
This is an older but foundational data-protection decision.
Principle
The CJEU addressed the concept of processing personal data and the scope of European data-protection law.
Wearable relevance
Wearable data are not legally transformed into "anonymous information" merely because the data are collected automatically.
Where a person can be identified directly or indirectly, the information can constitute personal data.
The case is therefore useful for understanding the broad conceptual foundation of European data protection.
15. Case Law 10 — Nowak v Data Protection Commissioner, C-434/16
CJEU, 20 December 2017
This is another foundational personal-data case.
Principle
The Court interpreted "personal data" broadly.
Information constitutes personal data where it relates to an identified or identifiable individual and has the required relationship to that person.
Wearable application
A wearable company's records might include:
User ID 84937 — resting heart rate 62 — sleep 7h 21m.
Even without a name in the data field, the information may still be personal data if the individual can be identified through the company's systems.
Thus:
pseudonymisation is not the same as anonymisation.
16. Case Law 11 — Wirtschaftsakademie Schleswig-Holstein, C-210/16
CJEU, 5 June 2018
This case concerned joint responsibility for processing personal data.
Importance
The CJEU adopted a broad concept of joint controllership.
A party can potentially be a joint controller even where it does not itself possess every piece of personal data or perform every processing operation.
Wearable relevance
Consider:
Wearable manufacturer → health-data platform → analytics provider → advertising platform
A company may attempt to say:
"We don't control the data; the analytics provider does."
The legal analysis may be more complicated.
If multiple parties jointly determine the purposes and means of processing, joint-controller questions can arise.
17. Case Law 12 — Google Spain, C-131/12
CJEU, 13 May 2014
Although this case concerned search engines rather than wearable technology, it is highly important for privacy and personal-data remedies.
Principle
The CJEU recognised important rights concerning the processing and dissemination of personal information.
Wearable relevance
Suppose a wearable company publishes:
"Top users with abnormal sleep patterns"
or exposes health-related profiles through a publicly accessible platform.
Google Spain illustrates the importance of examining:
dissemination;
privacy;
proportionality;
rights of the data subject.
18. UK Case Law — Lloyd v Google
Lloyd v Google LLC [2021] UKSC 50
The United Kingdom is no longer an EU Member State, but this case remains relevant to European comparative privacy law.
Facts
The case involved alleged unlawful collection and use of browsing information from millions of iPhone users.
Supreme Court principle
The UK Supreme Court rejected the proposed representative claim because the claimants had not established the required form of damage on the pleaded basis.
Importance
The case illustrates an important civil-law point:
Proof of unlawful data processing and proof of compensable damage are separate questions.
This is particularly relevant to wearable litigation where claimants may attempt mass or representative claims.
19. The Three Elements of an Article 82 Claim
Following the CJEU's Article 82 jurisprudence, a claimant generally needs to establish:
1. GDPR infringement
For example:
unlawful collection;
inadequate consent;
unlawful secondary use;
excessive retention;
inadequate security;
unlawful disclosure.
2. Damage
This can be:
material; or
non-material.
3. Causation
The damage must result from the GDPR infringement.
The CJEU repeatedly treats these as cumulative requirements. (Court of Justice of the European Union)
20. What Constitutes Misuse?
Wearable-data misuse can take many forms.
A. Unauthorised sale
A company sells health data to advertisers.
B. Secondary use
Data collected for fitness tracking are subsequently used for targeted advertising.
C. Unauthorised disclosure
Data are disclosed to:
employers;
insurers;
advertisers;
data brokers;
family members;
social-media companies.
D. Excessive retention
The company retains years of historical sensor data without sufficient justification.
E. Profiling
The company creates health-risk profiles without appropriate legal basis.
F. Automated decision-making
The data are used to determine:
insurance premiums;
employment opportunities;
creditworthiness;
eligibility for services.
21. Wearable Data and Employers
Workplace monitoring creates particularly sensitive disputes.
Imagine an employer provides smartwatches to employees to monitor:
fatigue;
movement;
heart rate;
stress;
sleep.
The employer then uses the information to identify "low productivity" workers.
Potential legal issues include:
employment law;
GDPR;
Article 9;
proportionality;
transparency;
employee consent;
automated decision-making;
discrimination.
The fact that the employee clicked "accept" does not necessarily resolve the problem, particularly where there is a significant imbalance between employer and employee.
22. Wearable Data and Insurance Companies
Insurance creates another major area of potential litigation.
Suppose an insurer offers:
"Lower your premium by sharing continuous smartwatch data."
The insurer may receive:
exercise frequency;
heart rate;
sleep patterns;
location;
physiological indicators.
Potential disputes concern whether the processing is:
voluntary;
transparent;
proportionate;
necessary;
based upon valid consent;
compatible with the original purpose.
The insurer may also face questions concerning automated decision-making.
23. Wearable Data and Advertising
A fitness company might collect:
"10,000 steps/day + elevated heart rate + sleep interruption"
and use the information to infer:
"This person may be stressed."
It could then target advertisements for:
medication;
supplements;
health services;
insurance;
psychological services.
This is legally sensitive because the company may be using apparently ordinary fitness data to generate health-related inferences.
The CJEU's broad approach to health data is therefore particularly important. (EUR-Lex)
24. Wearable Data and Data Brokers
A data broker may obtain wearable information and combine it with:
purchasing data;
location;
social-media information;
browsing history;
demographic information.
The resulting profile could reveal:
health conditions;
lifestyle;
pregnancy;
exercise habits;
emotional states.
This raises questions about:
purpose limitation;
compatibility of further processing;
lawful basis;
Article 9;
transparency;
profiling.
25. Consent
Consent must satisfy the GDPR's requirements.
For sensitive health data, explicit consent is particularly important where consent is the Article 9 exception relied upon.
A problematic consent mechanism might say:
"By using this app you agree to collection, analysis, sharing and commercialisation of all information generated by the device."
A court may examine whether such consent is:
specific;
informed;
freely given;
sufficiently explicit;
genuinely distinguishable between different purposes.
The user should be able to understand what happens to the data.
26. Purpose Limitation
Suppose the original purpose is:
"Monitor heart rate to display fitness information to the user."
The company later decides:
"We will sell heart-rate histories to advertisers."
That is a fundamentally different processing purpose.
The company must assess whether the secondary processing is legally compatible and whether an appropriate lawful basis exists.
Purpose limitation is therefore one of the strongest tools against "function creep."
27. Data Minimisation
A company should not collect unlimited data merely because the technology makes it possible.
For example, if an application needs only:
daily step count,
it may be difficult to justify retaining:
second-by-second location;
continuous heart rate;
sleep information;
body temperature;
unless those additional data are necessary for a legitimate and legally supported purpose.
28. Security Breaches
Wearable companies are attractive targets because their databases may contain:
health information;
location histories;
identity information;
behavioural profiles.
A security incident may lead to:
Article 33 notification;
Article 34 communication to affected persons;
regulatory enforcement;
Article 82 damages claims.
The security standard is risk-based.
A company handling highly sensitive continuous physiological information should implement appropriate technical and organisational measures.
29. Data Breach and Civil Liability
Suppose a hacker obtains:
5 million users' heart-rate and sleep histories.
Possible claims may involve:
inadequate security;
unlawful processing;
breach notification failures;
non-material damage;
fear of misuse;
loss of control.
But not every data breach automatically creates damages.
The claimant still has to establish the Article 82 requirements.
The CJEU has nevertheless recognised that fear of misuse can itself constitute non-material damage where the fear is sufficiently connected to the infringement and circumstances. (Court of Justice of the European Union)
30. Loss of Control Over Data
The concept of loss of control is particularly important in wearable cases.
A person might say:
"I do not know who has my heart-rate history, where it has gone, or how it is being used."
That loss of control may constitute non-material damage where the Article 82 requirements are satisfied.
Recent CJEU jurisprudence has recognised that even a relatively short loss of control can potentially qualify as non-material damage, provided actual damage is established. (Court of Justice of the European Union)
31. Fear of Future Misuse
Suppose the company accidentally exposes a database.
No evidence exists yet that someone has used a particular person's data.
The claimant nevertheless fears:
"Someone could use my health information against me in the future."
CJEU jurisprudence recognises that fear of future misuse can, in appropriate circumstances, amount to non-material damage. But courts must examine whether the fear is well founded in the specific circumstances. (Court of Justice of the European Union)
32. Material Damage
Material losses could include:
financial fraud;
increased insurance costs;
loss of employment opportunity;
costs of security measures;
medical expenses;
financial losses resulting from profiling;
expenses caused by identity fraud.
The claimant must establish a causal relationship between the unlawful processing and the financial damage.
33. Non-Material Damage
Non-material harm may include:
distress;
anxiety;
humiliation;
loss of control;
reputational injury;
fear;
exposure of intimate information.
The CJEU has rejected a requirement that non-material damage must exceed a predetermined seriousness threshold. (curia)
But this does not mean that every technical GDPR violation automatically produces damages.
34. Civil Tort and Privacy Rights
GDPR claims do not necessarily exhaust the claimant's remedies.
National civil law may provide additional causes of action involving:
personality rights;
privacy;
confidentiality;
negligence;
breach of confidence;
unlawful interference;
consumer rights.
The precise availability of these claims differs across European jurisdictions.
Thus a claimant might plead:
GDPR breach + national privacy tort + contractual breach.
35. Contractual Liability
Wearable users normally accept contractual terms.
The contract may contain obligations concerning:
data processing;
privacy;
security;
account management;
deletion;
data portability;
subscription services.
If the company promises:
"Your health information will never be sold to third parties"
and then sells it, the user may have both:
a data-protection argument; and
a contractual argument.
36. Consumer Protection
Consumer law can become important where wearable companies use:
misleading privacy policies;
hidden data-sharing provisions;
unfair contractual terms;
deceptive claims about "privacy";
unclear subscription arrangements.
A contractual term that is technically available somewhere in a lengthy privacy policy may not necessarily satisfy all transparency requirements.
37. Joint Controllers
The wearable ecosystem may involve:
Device manufacturer → app developer → cloud provider → analytics company → advertising partner
Determining who is the:
controller;
joint controller;
processor;
is critical.
The Wirtschaftsakademie jurisprudence demonstrates that controller responsibility can extend beyond the party that physically performs every processing operation.
This prevents companies from simply dividing the technological chain and asserting:
"The other company is responsible."
38. International Transfers
Wearable companies may store information on cloud servers outside the EU/EEA.
Potential issues include:
international transfers;
adequacy decisions;
Standard Contractual Clauses;
supplementary safeguards;
access by foreign authorities.
The Schrems II jurisprudence is particularly relevant to international transfers of personal data.
Where the data are health data, the consequences can be particularly serious.
39. Data Deletion
A user may request deletion of wearable information.
However, deletion rights are not absolute.
There can be exceptions involving:
legal obligations;
public interest;
healthcare;
legal claims;
scientific research;
other GDPR exceptions.
The dispute may therefore become:
"How much historical health information can the company lawfully retain, and for how long?"
40. Automated Profiling
Wearable data can feed AI systems that generate:
health scores;
fitness scores;
stress scores;
insurance risk scores;
employment risk scores.
Where automated decision-making has legal or similarly significant effects, additional GDPR protections may apply.
A claimant may therefore challenge:
the decision;
the underlying profiling;
the information used;
the absence of human intervention;
lack of transparency.
41. Biometric Data
Wearables can also generate biometric information.
A distinction must be made between:
ordinary physiological information
and
biometric data processed for uniquely identifying a person.
Not every heart-rate measurement is necessarily "biometric data" in the strict Article 9 sense.
But if a wearable system processes physiological characteristics to uniquely identify the person, enhanced protections may become relevant.
42. Sports Wearables
Professional athletes present a particularly difficult category.
A club may want to monitor:
heart rate;
recovery;
fatigue;
sleep;
injury risk;
training intensity.
The athlete may argue:
"The club is using health information beyond the purpose for which I agreed to provide it."
Potential legal questions include:
employment law;
collective agreements;
GDPR;
consent;
proportionality;
medical confidentiality;
sports regulation.
The 2026 CJEU anti-doping decision illustrates the continuing importance of determining whether particular information qualifies as health data and whether its publication is justified by a lawful exception. (EUR-Lex)
43. Children and Wearable Devices
Children may use:
fitness trackers;
smartwatches;
location devices;
medical wearables.
This creates additional concerns involving:
parental consent;
children's privacy;
profiling;
advertising;
location tracking.
Because children may be less able to understand the long-term consequences of data collection, the transparency and protection requirements become especially important.
44. Employee Wearables
A workplace may provide wearable devices for:
occupational safety;
productivity monitoring;
fatigue detection.
The employer must carefully distinguish:
legitimate workplace safety monitoring
from
general surveillance of employees' private lives.
Collecting data about an employee's:
sleep at home;
heart rate outside working hours;
exercise;
location;
can create significant proportionality and privacy concerns.
45. Insurance Wearables
Insurance companies may seek continuous behavioural information to calculate premiums.
The civil dispute might arise where:
A customer refuses to provide continuous wearable data and is charged a substantially higher premium.
Possible legal questions include:
Was participation genuinely voluntary?
Was the customer sufficiently informed?
Is the processing proportionate?
Is health data being processed?
Is automated profiling involved?
Was there discrimination?
46. Pharmaceutical and Medical Research
Wearable devices are increasingly used for clinical research.
Researchers may collect:
continuous heart-rate data;
movement;
sleep;
glucose;
neurological measurements.
Research processing can be lawful under specific GDPR provisions, but safeguards are required.
The EDPB notes that health research involving special-category data requires appropriate safeguards. (European Data Protection Board)
A dispute can arise where data originally collected for research are later reused for:
commercial advertising;
insurance;
unrelated research;
product development.
47. Commercial Sale of Health Profiles
A particularly serious scenario is:
Wearable company → data broker → insurance company.
The original user may have believed:
"This device is helping me track fitness."
The commercial ecosystem may instead create:
"A predictive health-risk profile."
The legality of that transformation depends on:
original purpose;
lawful basis;
Article 9;
transparency;
compatibility;
consent;
contractual terms.
48. Evidentiary Issues in Civil Litigation
Wearable data can themselves become evidence.
For example, in a personal-injury lawsuit, one party may seek:
step counts;
heart-rate records;
sleep records;
GPS records.
This creates a conflict between:
relevance to litigation
and
privacy/data protection.
The court may have to determine whether disclosure is:
necessary;
proportionate;
legally authorised.
49. Cross-Border Litigation
Imagine:
German consumer;
French wearable manufacturer;
Irish cloud provider;
US analytics company.
A dispute may involve:
GDPR;
Rome I;
Rome II;
Brussels Ia;
consumer jurisdiction;
international transfers.
The claimant may have to determine:
which court has jurisdiction;
which law governs the contract;
which law governs tort;
where the controller is established;
where the damage occurred.
50. Remedies
Potential remedies include:
A. Compensation
Under Article 82 GDPR.
B. Injunction
To stop unlawful processing.
C. Erasure
Where Article 17 applies.
D. Restriction
Temporary limitation of processing.
E. Rectification
Correction of inaccurate information.
F. Access
Obtaining information about processing.
G. Data portability
Receiving data in an appropriate format.
H. Regulatory enforcement
Complaints to supervisory authorities.
I. Contractual remedies
Where the processing breaches contractual promises.
51. Important Distinction: Regulatory Fine vs Civil Damages
A regulatory authority may impose a fine.
That does not automatically mean:
every affected person receives compensation.
Similarly:
a claimant may obtain civil compensation even though no regulatory fine has been imposed.
The two mechanisms serve different purposes.
52. Practical Hypothetical
Consider this example.
A European company sells a smart ring.
The ring continuously collects:
heart rate;
sleep;
body temperature;
activity;
location.
The company tells consumers:
"We use your information to improve your fitness experience."
Three years later, it begins sharing data with an insurance analytics company.
The analytics company creates:
"Cardiovascular risk scores."
An insurer uses those scores when determining premiums.
The customer discovers the arrangement and brings proceedings.
53. Legal Analysis of the Hypothetical
Issue 1 — Are the data personal data?
Yes, if the individual is identified or identifiable.
Issue 2 — Are they health data?
The answer may be yes where the information reveals health status directly or through deduction.
The CJEU's broad approach in Lindenapotheke is particularly relevant. (EUR-Lex)
Issue 3 — What was the original purpose?
Fitness monitoring.
Issue 4 — What is the new purpose?
Insurance-risk assessment.
The purposes are materially different.
Issue 5 — Is there an Article 6 basis?
The company must establish one.
Issue 6 — Is there an Article 9 exception?
If the information constitutes health data, an additional Article 9 condition is required.
Issue 7 — Was the user adequately informed?
The transparency requirements must be examined.
Issue 8 — Did the user suffer damage?
The claimant may allege:
loss of control;
distress;
increased insurance costs;
privacy invasion.
Issue 9 — Can causation be established?
The claimant must connect the unlawful processing to the particular damage.
Issue 10 — What remedy is available?
Potentially:
compensation;
erasure;
restriction;
injunction;
regulatory action.
54. Case-Law Comparison
| Case | Court | Principal issue | Wearable-data relevance |
|---|---|---|---|
| Lindqvist, C-101/01 | CJEU | Personal-data processing | Foundation for data classification |
| Google Spain, C-131/12 | CJEU | Privacy and dissemination | Public exposure of sensitive profiles |
| Wirtschaftsakademie, C-210/16 | CJEU | Joint controllership | Device/app/cloud ecosystems |
| Nowak, C-434/16 | CJEU | Broad personal-data concept | Sensor records linked to users |
| Vyriausioji, C-184/20 | CJEU | Indirectly revealing sensitive information | Health inferences from sensor data |
| Österreichische Post, C-300/21 | CJEU | Compensation under Article 82 | Non-material damage |
| Meta Platforms, C-252/21 | CJEU | Lawfulness and sensitive data | Secondary commercial use |
| Natsionalna agentsia za prihodite, C-340/21 | CJEU | Data breach and fear of misuse | Hacked wearable databases |
| Krankenversicherung Nordrhein, C-667/21 | CJEU | Health-data processing | Medical/health wearable data |
| MediaMarktSaturn, C-687/21 | CJEU | Article 82 damage | Compensation claims |
| Lindenapotheke, C-21/23 | CJEU | Health data and Article 9 | Health inferences from non-medical data |
| AR and Others, C-474/24 | CJEU, 2026 | Health-data classification | Sports/wearable monitoring |
55. The Most Important Legal Principles
The case law supports several major principles.
1. Health data receive enhanced protection
Wearable health information can fall within Article 9.
2. Indirect information can be health data
The law is concerned with what information can reveal, not merely what the raw data are called. (EUR-Lex)
3. Pseudonymisation does not necessarily make data anonymous
If the person remains identifiable, GDPR obligations may continue.
4. Consent has limits
A general acceptance of terms does not automatically legitimise every future processing purpose.
5. Secondary use is legally significant
Fitness data used for insurance or advertising may require a separate legal analysis.
6. Compensation requires damage
GDPR infringement alone is insufficient for Article 82 damages. (curia)
7. There is no fixed minimum seriousness threshold for non-material damage
But actual damage must still be demonstrated. (InfoCuria)
8. Fear of misuse may constitute damage
Where sufficiently well founded, fear of misuse can constitute non-material damage. (Court of Justice of the European Union)
9. Multiple companies may share responsibility
The wearable ecosystem can create controller/joint-controller issues.
10. Data protection and civil law overlap
A claimant can potentially combine GDPR remedies with national contractual, tort and personality-right claims.
56. Recommended Litigation Structure
A well-developed wearable-data claim should normally proceed through the following questions:
Step 1 — Identify the data
What exactly did the wearable collect?
Step 2 — Identify the person
Can the data be linked to an identifiable individual?
Step 3 — Determine whether the information is health data
Does it directly or indirectly reveal health status?
Step 4 — Identify the controller
Who determined the purposes and means?
Step 5 — Identify the processing purpose
Why was the data collected?
Step 6 — Examine Article 6
What is the lawful basis?
Step 7 — Examine Article 9
If health data are involved, what additional condition permits processing?
Step 8 — Examine transparency
Was the user properly informed?
Step 9 — Examine security
Were appropriate technical and organisational measures used?
Step 10 — Establish damage
What material or non-material harm occurred?
Step 11 — Establish causation
Did the unlawful processing cause that harm?
Step 12 — Select remedies
Compensation, erasure, restriction, injunction or regulatory complaint.
57. Conclusion
Wearable bio-sensor data misuse litigation is becoming one of the most significant emerging areas of European civil and data-protection law.
The fundamental problem is that wearable devices transform ordinary physical activity into an extensive digital record of a person's body and behaviour. A smartwatch or smart ring may appear to collect simple fitness information, but when the information is combined and analysed it can reveal highly sensitive health characteristics.
The CJEU's jurisprudence is particularly important. Lindenapotheke (C-21/23) confirms the broad approach to health data, including information capable of revealing health status through deduction. Vyriausioji (C-184/20) similarly demonstrates that indirect revelation of sensitive information can trigger enhanced protection. Österreichische Post (C-300/21), Natsionalna agentsia za prihodite (C-340/21) and MediaMarktSaturn (C-687/21) establish the developing principles concerning compensation for non-material harm. The 2026 AR and Others (C-474/24) judgment provides a current illustration of the Court's continuing attention to the boundary between ordinary information and health-related information.
For civil litigation, the most important formula is:
Unlawful processing + actual material or non-material damage + causal connection = potential Article 82 compensation claim.
But wearable-data litigation can go beyond GDPR compensation. Depending on the facts and national law, it may also involve contractual liability, consumer protection, privacy/personality rights, confidentiality, employment law, medical confidentiality, product liability, cybersecurity and injunctions.
The central legal lesson is therefore that the legal value of wearable data lies not merely in the individual sensor reading, but in what that information can reveal about an identifiable person's body, health, behaviour and private life. European courts are increasingly treating those inferential capabilities as crucial when determining the level of legal protection owed to individuals. (European Data Protection Board)
Available next action: Create a downloadable PDF file here in this chat containing the findings and recommendations above

comments