How Do Health App Privacy Laws Differ From Country to Country?

You track your period, your mood, your symptoms, maybe your fertility window or your medication doses. That's some of the most personal information about you, and it's sitting inside an app made by a company you've probably never met.

So how do you actually know if it's safe? Here's a simple, no-jargon guide to checking for yourself, wherever in the world you happen to live.

First, a myth to clear up: your local health law probably doesn't cover your app

Most people assume "health data" automatically comes with special legal protection, the same kind that covers your doctor's office or hospital. It doesn't work that way almost anywhere.

Laws like HIPAA in the US, or hospital-focused rules elsewhere, generally only apply to healthcare providers, insurers, and their direct vendors. A period tracker, a mental health journal, or a fitness app you downloaded yourself is almost never one of those. That gap between "medical record" and "app on your phone" exists in nearly every country, which is exactly why it's worth checking the details yourself rather than assuming a law has your back.

What the law actually does (and doesn't) protect, by region

The good news is that most countries do have general privacy laws that apply to health apps, even when dedicated medical-record laws don't. Here's the short version for where SheRanked's readers are.

United States There's no single federal law covering most health apps. HIPAA doesn't apply to a period tracker you downloaded yourself. Instead, two things fill the gap: the FTC's Health Breach Notification Rule, updated in 2024 to explicitly cover health apps, which requires companies to notify you and the FTC if your data is shared or exposed without consent, and a growing list of state laws. Washington's My Health My Data Act, in force since 2024, is the strictest so far. It requires clear consent before your health data is collected or shared, bans selling that data without your written authorization, and lets you request full deletion, and it applies to any company that serves Washington residents, not just companies based there. Other states, including Nevada and Connecticut, have passed similar laws.

United Kingdom The UK GDPR and the Data Protection Act 2018 apply, and they classify health data as "special category data," meaning it needs a stronger legal basis and clearer consent than ordinary personal data. The Information Commissioner's Office (ICO) enforces this and expects apps to justify why they need each piece of data they collect, not just bury it in a long policy. You also have a legal right to ask what data a company holds on you and to request its deletion.

European Union The GDPR treats health data the same way across all member states: as a special category requiring explicit consent, a clear legal basis, and strong security. You have enforceable rights to access, correct, and delete your data, and to data portability if you want to move to a different app. Regulators across the EU have taken action against femtech and wellness apps specifically for sharing health-related data with advertisers without proper consent, so this is an actively enforced area, not just a theoretical protection.

Canada Federally, PIPEDA sets baseline rules for how private companies collect, use, and disclose personal information, including health data, and requires meaningful consent. On top of that, several provinces have their own, often stricter, health-specific laws: Ontario's PHIPA, Alberta's Health Information Act, and Quebec's private-sector privacy law, among others. Which one applies can depend on where the company operates and where you live, so a Canadian-made app may be answering to more than one regulator at once.

Australia The Privacy Act 1988 and the Australian Privacy Principles apply, and health information is treated as "sensitive information" requiring extra protection and, generally, your explicit consent to collect or share. Importantly, the usual small-business exemption (which lets small companies skip some obligations) does not apply to organizations that handle health information, so even a small app developer is covered. Reforms passed in December 2024 are strengthening enforcement further, including new penalties and expanded rights to have data corrected or deleted.

New Zealand The Privacy Act 2020 sets the general rules for any organization handling your personal information, including apps. Health information gets extra protection under the Health Information Privacy Code, which sets specific rules for storage security, access, and disclosure for agencies operating in the health space. As in other countries, whether a wellness or period-tracking app counts as a "health agency" under the Code, or simply falls under the general Privacy Act, can vary, so it's worth checking a company's privacy policy for which framework it says it follows.

The pattern across all six Wherever you are, health data is treated as more sensitive than your average personal information, and you generally have some right to know what's collected, some right to say no, and some right to have it deleted. But enforcement varies a lot, and no law stops a company from writing very permissive terms into its privacy policy in the first place, as long as it's upfront about them. That's why the real safety check happens before you ever hit "accept," not after.

The checklist: what to actually look at

You don't need a law degree to vet an app. You need about ten minutes and these questions.

1. Who else gets your data? Search the privacy policy for words like "third parties," "partners," "advertisers," or "affiliates." Look specifically for whether data is shared for advertising or marketing purposes, since that's the biggest way period, fertility, and mental health data ends up somewhere you never agreed to.

2. Is your data "anonymized," and do you believe it? Companies often say data is anonymized or aggregated before sharing. This sounds reassuring, but health data (especially combined with location, age, or device ID) can sometimes be re-identified. Treat "anonymized" as a soft claim, not a guarantee.

3. What happens to your data if the company is sold or shuts down? Look for a clause about mergers, acquisitions, or bankruptcy. Many privacy policies state that your data is simply considered a transferable "asset" in that event, meaning a new owner, with new rules, could inherit your entire health history.

4. Can you actually delete your data, all of it? A trustworthy app makes deletion simple and complete, including backups. A vague policy that only lets you "deactivate" your account is a warning sign. If you're in the UK, EU, Australia, or a Canadian province with health-specific rules, this is also a legal right, not just a courtesy, so the option should be easy to find.

5. What permissions is it asking for on your phone? Check your phone's settings, not just the app's pitch. Does a period tracker really need your precise location, contacts, or microphone? If a permission doesn't obviously relate to the app's core function, it's worth questioning why it's requested.

6. Is your data encrypted in storage, not just in transit? Encryption "in transit" (while data travels from your phone to their server) is standard and not very impressive on its own. Look for whether they also encrypt data "at rest" (while stored on their servers), which protects you if their database is ever breached.

7. Has the company had a breach or regulatory action before? A quick search of the company name plus "data breach," "FTC," "ICO," or your local regulator's name takes thirty seconds and can tell you a lot about how they've handled mistakes in the past.

8. Where is your data actually stored, and does it cross borders? If you're in the EU, UK, Australia, or New Zealand, check whether the company transfers your data to a country with weaker protections, like the US. Reputable apps disclose this and explain what safeguards apply. If a privacy policy is silent on international transfers, that's worth a second look.

Red flags vs. green flags

Red flags:

  • A privacy policy that's vague, extremely long, or hard to find at all

  • Sharing data with "marketing partners" as a default, opt-out (not opt-in) setting

  • No clear answer on how to fully delete your data

  • Location tracking that isn't explained or justified

  • No mention of encryption at all

  • No mention of which country's privacy law the company follows or where your data is stored

Green flags:

  • Data collection is opt-in, and it's clear what's optional vs. required

  • A plain-language summary of the privacy policy, not just legal text

  • A visible option to export or permanently delete your data

  • Clear statements about what happens to your data in a sale or shutdown

  • Independent security or privacy audits mentioned by name

  • Clear information about which regulator or law the company complies with, and where your data is hosted

The honest truth

No app can promise perfect safety. Breaches happen even to careful companies, and the exact legal protections you get still depend heavily on where you live. What you're really checking for is intent: does this company treat your data as something to protect, or something to monetize? The clues are almost always sitting in plain sight in the privacy policy and the permissions screen. You just have to know where to look, and now you do.

If you'd rather skip the detective work, that's exactly why we built SheRanked. Our team reviews femtech and health apps for exactly these things, so you don't have to read a 40-page privacy policy before your next cycle.

Previous
Previous

Which Health Apps Prioritise User Data Privacy and Security?

Next
Next

Are There Doctor-Approved Fitness Apps for Women? What You Need to Know