Smartwatch Privacy in the UK: What Your Wearable Knows About You and How to Stay Safe in 2026
Smartwatches and fitness trackers have become a fixture on British wrists. From the Apple Watch Series 10 to the Samsung Galaxy Watch 7, the Garmin Forerunner 965, and the Fitbit Charge 6, millions of UK consumers now wear devices that continuously collect intimate data about their bodies, movements, and daily routines. But how much do these devices actually know about you — and where does that data go?
This guide, compiled from thorough research of manufacturer privacy policies, UK data protection guidance from the Information Commissioner's Office (ICO), and authoritative technology publications, examines the privacy implications of popular smartwatches and fitness trackers available in the UK in 2026. It also provides practical steps to protect your personal data without giving up the benefits these devices offer.
What Data Does Your Smartwatch Actually Collect?
Modern smartwatches are sophisticated health and lifestyle monitoring platforms. The data they collect falls into several categories:
Health and Biometric Data
- Heart rate: Continuous optical heart rate monitoring, typically using photoplethysmography (PPG) sensors
- Blood oxygen saturation (SpO2): Available on Apple Watch Series 6 and later, Samsung Galaxy Watch 4 and later, Garmin Forerunner 965, and Fitbit Charge 6
- ECG (electrocardiogram): Available on Apple Watch Series 4 and later (UK-approved), Samsung Galaxy Watch 4 and later (UK-approved), and select Withings devices
- Skin temperature: Apple Watch Series 8 and later, Samsung Galaxy Watch 5 and later, Fitbit Sense 2
- Sleep tracking: Sleep stages (light, deep, REM), sleep duration, and sleep quality scores
- Menstrual cycle tracking: Available on Apple Watch (Cycle Tracking), Samsung Galaxy Watch, and Fitbit devices
- Stress levels: Derived from heart rate variability (HRV) measurements
- Blood glucose monitoring: Samsung Galaxy Watch 7 includes a non-invasive blood glucose monitoring feature (regulatory status varies)
Activity and Location Data
- GPS location: Built-in GPS on Apple Watch Ultra 2, Apple Watch Series 9 and later, Samsung Galaxy Watch 7, Garmin Forerunner 965, and many others
- Step count and distance: Continuous accelerometer-based tracking
- Exercise and workout data: Type of activity, duration, intensity, calories burned
- Route mapping: GPS-enabled devices record your exact routes during outdoor activities
Behavioural and Device Data
- Notification content: Many smartwatches display message previews, email snippets, and app notifications
- App usage patterns: Which apps you use and when
- Payment data: Apple Pay, Google Pay, and Samsung Pay transactions via NFC
- Voice data: Siri, Google Assistant, and Bixby interactions
Where Does Your Smartwatch Data Go?
Understanding where your data is stored and processed is essential for making informed privacy decisions.
Apple Watch and Apple Health
Apple stores health data in its Health app, which is encrypted on-device using your iPhone's passcode. Health data synced to iCloud is encrypted end-to-end, meaning Apple cannot access it. However, if you share data with third-party apps through HealthKit, those apps are governed by their own privacy policies, which may be less stringent.
Apple's privacy policy states that health data is not used for advertising purposes. The company is headquartered in the United States, and data transfers to the US are governed by the UK-US data bridge arrangement (successor to Privacy Shield), which came into effect in October 2023.
Samsung Galaxy Watch and Samsung Health
Samsung Health stores data on Samsung's servers, with servers located in the US, EU, and other regions. Samsung's privacy policy states that health data is not sold to third parties, but it may be shared with Samsung affiliates and service providers. Samsung Health data can be shared with third-party apps, each with their own privacy policies.
Samsung is a South Korean company. Data transfers from the UK to South Korea are covered by the UK's adequacy decision for South Korea, which was adopted in 2021.
Garmin Connect
Garmin stores activity and health data on its Connect platform, with servers in the US and EU. Garmin's privacy policy states that it does not sell personal data to third parties. In 2020, Garmin suffered a significant ransomware attack that disrupted its services for several days — a reminder that even reputable companies can be vulnerable to data breaches.
Garmin is a US company. Data transfers are covered by the UK-US data bridge arrangement.
Fitbit and Google
Fitbit was acquired by Google in 2021, and Fitbit data is now processed under Google's privacy framework. Google has committed that Fitbit health and wellness data will not be used for Google advertising. However, Google's broader data practices and the integration of Fitbit data into Google's ecosystem raise legitimate privacy questions for users who are concerned about data aggregation.
Google is a US company. Data transfers are covered by the UK-US data bridge arrangement.
UK Data Protection Law and Your Smartwatch
In the UK, the processing of health data is governed by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Health data is classified as "special category data" under UK GDPR, which means it receives enhanced protection and can only be processed under specific legal bases.
Key rights you have under UK GDPR regarding your smartwatch data:
- Right of access: You can request a copy of all personal data held about you by the manufacturer
- Right to erasure: You can request deletion of your data (the "right to be forgotten")
- Right to data portability: You can request your data in a machine-readable format
- Right to object: You can object to certain types of processing
- Right to restrict processing: You can request that processing be limited in certain circumstances
The Information Commissioner's Office (ICO) is the UK's independent data protection regulator. If you believe a company has mishandled your data, you can report it to the ICO at ico.org.uk. The ICO has the power to issue fines of up to £17.5 million or 4% of global annual turnover (whichever is higher) for serious breaches of UK GDPR.
The Most Privacy-Conscious Smartwatches Available in the UK
Apple Watch Series 10
Apple has consistently positioned itself as a privacy-first technology company, and the Apple Watch Series 10 reflects this. End-to-end encryption of health data in iCloud, on-device processing for many health features, and a clear commitment not to use health data for advertising make Apple Watch the strongest choice for privacy-conscious users.
UK pricing (as of September 2026, subject to change): From approximately £399 (41mm, GPS); available at Apple UK, Currys, John Lewis, and Amazon UK.
Garmin Forerunner 965
Garmin's approach to privacy is relatively straightforward: it collects activity and health data to power its Connect platform but does not sell data to third parties. For users who are concerned about data being used for advertising, Garmin's independence from the major advertising platforms (Google, Meta) is a meaningful advantage.
UK pricing (as of September 2026, subject to change): Approximately £599; available at Currys, John Lewis, Amazon UK, and specialist sports retailers including Wiggle and Sigma Sports.
Withings ScanWatch 2
Withings is a French health technology company, meaning its data processing is subject to EU GDPR (which the UK has recognised as providing adequate protection). The ScanWatch 2 offers ECG, SpO2, and sleep tracking in a traditional watch design. Withings' privacy policy is notably transparent, and the company does not use health data for advertising.
UK pricing (as of September 2026, subject to change): Approximately £299; available at John Lewis, Amazon UK, and Withings' own UK website.
Privacy Risks to Be Aware Of
Third-Party App Data Sharing
One of the most significant privacy risks with smartwatches is not the device manufacturer itself, but the third-party apps you connect to your health data. When you grant a fitness app, nutrition tracker, or meditation app access to your Apple Health or Samsung Health data, that app's privacy policy governs how your data is used — and many third-party apps have far less stringent privacy practices than the major manufacturers.
Recommendation: Regularly review which apps have access to your health data. On iPhone, go to Settings → Privacy & Security → Health to see and revoke app permissions. On Android, check Samsung Health or Google Fit permissions in Settings → Apps.
Location Data and Route Tracking
GPS-enabled smartwatches record your exact routes during outdoor activities. This data can reveal where you live, work, and spend your time. If your fitness app account is breached, or if you share activities publicly on platforms like Strava, this location data could be exposed.
In 2018, the fitness tracking app Strava published a global heatmap that inadvertently revealed the locations of secret military bases by showing the exercise routes of soldiers. While this was an extreme case, it illustrates the sensitivity of location data generated by wearables.
Recommendation: Review your privacy settings on any fitness platform where you share activities. Consider using privacy zones (available on Garmin Connect and Strava) to hide the start and end points of your routes near your home.
Menstrual and Reproductive Health Data
Cycle tracking features on Apple Watch, Samsung Galaxy Watch, and Fitbit collect particularly sensitive data. In the context of ongoing debates about reproductive rights in various jurisdictions, some users have expressed concern about how this data could be used or subpoenaed.
Apple has stated that cycle tracking data stored in iCloud is end-to-end encrypted and cannot be accessed by Apple. For maximum privacy, Apple recommends keeping cycle tracking data on-device only (not syncing to iCloud).
Recommendation: If you use cycle tracking features and are concerned about data privacy, review the specific privacy settings for this feature in your device's health app and consider whether cloud sync is necessary.
Data Breaches
No company is immune to data breaches. Garmin's 2020 ransomware attack, which disrupted services for several days, is a reminder that even security-conscious companies can be targeted. While health data was not reported to have been exfiltrated in that incident, it highlights the importance of using strong, unique passwords for your health platform accounts and enabling two-factor authentication (2FA) wherever available.
Practical Steps to Protect Your Smartwatch Privacy
1. Review App Permissions Regularly
At least every three months, review which apps have access to your health data and revoke permissions for any apps you no longer use or trust. This applies to both your smartphone's health platform (Apple Health, Samsung Health, Google Fit) and any third-party fitness apps.
2. Enable Two-Factor Authentication
Enable 2FA on your Apple ID, Samsung account, Google account, Garmin Connect account, and any other platform where your health data is stored. This significantly reduces the risk of unauthorised access even if your password is compromised.
3. Use a Strong, Unique Password
Use a password manager (such as 1Password, Bitwarden, or Apple's built-in Keychain) to generate and store strong, unique passwords for each health platform account. Never reuse passwords across services.
4. Review Your Privacy Settings
Take time to explore the privacy settings within your smartwatch's companion app. Many platforms offer granular controls over what data is collected, how long it is retained, and whether it is shared with third parties. Key settings to check include:
- Data sharing with third-party apps
- Research and product improvement data sharing (often opt-in or opt-out)
- Location data retention settings
- Activity sharing settings on social fitness platforms
5. Exercise Your UK GDPR Rights
You have the right to request a copy of all data held about you by your smartwatch manufacturer, and the right to request deletion of that data. Most major manufacturers provide self-service tools for data export and deletion within their apps or websites. If you cannot find these tools, contact the manufacturer's data protection officer (DPO) directly — they are required to respond within one month under UK GDPR.
6. Be Cautious with Public Activity Sharing
If you use a social fitness platform like Strava, Garmin Connect's social features, or Apple Fitness+, review your privacy settings carefully. Consider making your activities private by default and only sharing with trusted connections.
7. Consider On-Device Processing
Apple Watch processes many health features on-device, meaning the raw data never leaves your watch or iPhone. Where manufacturers offer on-device processing options, these are generally preferable from a privacy perspective.
Smartwatch Privacy Comparison
| Device | Manufacturer | Data Location | End-to-End Encryption | Used for Advertising | UK Price (approx., Sep 2026) |
|---|---|---|---|---|---|
| Apple Watch Series 10 | Apple (US) | On-device + iCloud (E2E) | Yes (iCloud health data) | No | From £399 |
| Samsung Galaxy Watch 7 | Samsung (South Korea) | Samsung servers (US/EU) | Partial | No (health data) | From £289 |
| Garmin Forerunner 965 | Garmin (US) | Garmin Connect servers | No | No | £599 |
| Fitbit Charge 6 | Google (US) | Google servers | No | No (health data) | From £139 |
| Withings ScanWatch 2 | Withings (France/EU) | Withings servers (EU) | No | No | £299 |
All prices are approximate as of September 2026 and are subject to change. Privacy policies and data practices may change — always review the current privacy policy before purchasing.
The Bottom Line: Should You Be Worried?
Smartwatches collect genuinely sensitive data about your health, location, and daily life. For most UK users, the privacy risks are manageable with sensible precautions — strong passwords, 2FA, regular permission reviews, and careful use of social sharing features. The major manufacturers (Apple, Samsung, Garmin, Fitbit/Google, Withings) all have privacy policies that prohibit selling health data to third parties, and all are subject to UK GDPR enforcement by the ICO.
The greatest risks come not from the manufacturers themselves, but from third-party apps with access to your health data, weak account security, and oversharing on social fitness platforms. Address these risks first.
If you are particularly privacy-conscious, the Apple Watch Series 10 offers the strongest privacy protections of any mainstream smartwatch available in the UK, thanks to end-to-end encryption of health data in iCloud and on-device processing of many health features. The Withings ScanWatch 2 is a strong alternative for those who prefer a European data processor and a more traditional watch aesthetic.
Whatever device you choose, take the time to understand what data it collects, where that data goes, and what controls you have over it. Your health data is among the most personal information you generate — it deserves the same careful attention you would give to your financial or legal records.
All prices quoted are approximate as of September 2026 and are subject to change. Privacy policies and data practices may be updated by manufacturers — always review the current privacy policy on the manufacturer's UK website before making a purchase decision. For data protection concerns, contact the Information Commissioner's Office (ICO) at ico.org.uk.