DataAct Ready

EU Data Act guides ·

Does the EU Data Act Apply to Wearables and Fitness Trackers?

What the EU Data Act means for smartwatches, fitness bands and other wearables, which data users can request, and how the rules interact with the GDPR.

A smartwatch counts your steps, tracks your heart rate, maps your morning run and logs your sleep. Until recently, how much of that data you could actually retrieve depended almost entirely on what the manufacturer's app happened to offer. The EU Data Act changes the baseline. It has been applicable since 12 September 2025, and wearables such as smartwatches, fitness bands, smart rings and connected headphones fall squarely within its definition of a connected product.

Why wearables are covered

The Data Act applies to connected products, meaning items that obtain, generate or collect data about their use or environment and can communicate that data. A fitness tracker that records steps and heart rate, a smart ring that measures sleep stages, a cycling computer that logs routes: all of these fit. The companion app and the manufacturer's cloud platform will usually count as a related service, which brings the data they process within scope too.

This is a different question from whether a device is a medical device. Most consumer wearables are wellness products, not regulated medical devices, and they do not need to be medical to be covered. The Data Act attaches to connectivity and data generation, not to a health claim.

What users can request

Since September 2025, the user of a wearable, normally the person who bought it, can ask the data holder for the readily available data the device and its related services generate, together with the metadata needed to interpret it. The data should be provided without undue delay, free of charge, and in a structured, commonly used and machine-readable format where applicable. That reaches beyond the polished summaries in the app and is expected to include the underlying usage data the manufacturer actually holds.

Users can also ask for the data to be shared with a third party of their choice, such as a coaching platform, an independent analytics tool or a rival ecosystem they are moving to. The manufacturer may seek reasonable compensation from that third party, and it can require confidentiality safeguards where trade secrets are involved, but a flat refusal is expected to be hard to justify in most consumer scenarios.

Where the GDPR fits in

Almost everything a wearable records about its wearer is personal data, and much of it, such as heart rate and sleep patterns, is health-related. The Data Act does not weaken the GDPR. Where personal data is involved, both regimes apply at the same time, so a manufacturer answering a Data Act request must still have a lawful basis under the GDPR and must still honour data subject rights such as access and portability. In practice the Data Act often gives users a broader and faster route to raw device data, while the GDPR continues to govern how that data is protected along the way.

Enforcement reflects this dual structure. In Germany, the Data Act implementation law known as the DADG has been in force since 30 May 2026, with the Bundesnetzagentur enforcing the Act through tiered fines of up to EUR 500,000. Where personal data is involved, GDPR-level fines of up to 4 percent of global annual turnover can apply under Article 40(4). For wearables, where nearly all data is personal, that higher ceiling is the one manufacturers should keep in mind.

Deadlines that matter now

For wearables placed on the EU market from 12 September 2026, the access-by-design obligation applies: devices and their related services must be built so users can access their data directly, easily and securely, where relevant and technically feasible. That rule has been in force since 12 September 2026, so current product generations are expected to meet it, not future ones. From 12 January 2027, charges for switching between data processing services are expected to be withdrawn, which touches the cloud platforms behind most wearable ecosystems. And from 12 September 2027, certain legacy contracts concluded before the Act applied will come within the data access rules.

Manufacturers watching Brussels should note that the Digital Omnibus proposals would soften parts of the Data Act, including possible legacy contract exemptions and relief for smaller companies. These are proposals, not law, and product plans built on the assumption that they will pass are taking a real risk.

Where to start

If you build or sell wearables for the EU market, three questions are worth answering now. Can a user actually export the underlying data your device collects, and how long would a request take you to fulfil? Do devices shipped since September 2026 offer direct access by design? And do your privacy notice and terms explain Data Act rights alongside GDPR rights in plain language?

If you are not sure where your product stands, our free Data Act readiness assessment walks you through the key obligations step by step and shows you where the gaps are likely to be. It takes a few minutes and gives you a concrete starting point for compliance.

Where does your product stand on the Data Act?

Free 3-minute readiness assessment, scoped to your product, with a scored gap report. No signup required to see your score.

Start free assessment

This article is general information about EU Regulation 2023/2854, not legal advice. Consult qualified counsel for your specific situation.