A wellbeing app can look like an easy employee benefit. A step-count challenge, a fatigue-alert wearable or an AI tool that identifies possible stress patterns may promise healthier teams, fewer incidents and better support. For a small business, the technology can also seem far more accessible than an in-house occupational-health programme.
But these tools can turn ordinary employment data into highly sensitive workplace monitoring. Step counts may reveal routines and locations. Sleep, heart-rate variability, temperature, injury reports and fatigue scores can reveal or infer information about physical or mental health. Once an employer receives a dashboard, score or alert, the programme is no longer simply a private consumer app benefit: it is a workplace data-protection project.
Before launch, UK small business owners need to be able to explain, in writing, why the data is needed, why a less intrusive option will not work, what legal grounds apply, who can see the information and what will never be done with it. The Information Commissioner’s Office (ICO) says employers considering health monitoring must first consider their aim and whether a less privacy-intrusive approach is available; it also says a data protection impact assessment should be carried out before processing begins. Read the ICO’s health-monitoring guidance.
Start with the real purpose, not the product demo
The first question is not “Does the app have good features?” It is: what specific workplace problem are we trying to solve? A defensible purpose might be reducing fatigue risks for lone workers driving long shifts, helping a worker request adjustments, or offering a genuinely voluntary wellbeing resource. “Improving productivity”, “seeing who is committed” or “finding people at risk of absence” are much harder to justify, particularly where health inferences may affect people’s livelihoods.
Write the purpose in one sentence, then test every proposed data field against it. If the business wants to address sedentary work in an office, it may only need anonymised, organisation-level engagement information or no employer-facing data at all. It is unlikely to need named daily step totals, GPS trails, sleep records or leaderboard rankings.
Be equally precise about the decision the data will support. Is the tool intended to offer the individual a private prompt? Is it intended to trigger a conversation with a trained manager? Or could it lead to changed shifts, sickness action, performance management, access restrictions or insurance consequences? A system sold as “wellbeing” can become monitoring if managers use its outputs to make employment decisions.
Ask the necessity and proportionality questions
Necessity means more than convenience. The business should be able to show the processing is a targeted way of achieving a legitimate objective, not merely a useful extra. Proportionality asks whether the likely benefit outweighs the privacy intrusion and whether safeguards can reduce the impact.
- What concrete health, safety or wellbeing outcome are we trying to achieve?
- What evidence shows that data collection is needed for that outcome?
- Could training, workload redesign, rota changes, a self-referral route, anonymous surveys or occupational-health advice achieve it with less individual monitoring?
- Do we need identifiable information, continuous collection, precise location data or access to raw readings?
- Can the employer receive only an aggregate report, a binary fit-for-duty result, or a worker-initiated request for help instead?
- What harm could follow if a score is wrong, incomplete, biased or viewed out of context?
This exercise often changes the design. For example, a logistics company concerned about long shifts may be able to improve rota controls and offer a confidential fatigue self-reporting channel. If a wearable is still necessary for a narrowly defined safety risk, the company should collect the smallest amount of data for the shortest period, rather than retain a permanent behavioural record.
Recognise when wellbeing data becomes special-category health data
Health information is special-category personal data under UK GDPR. The category is not limited to a formal diagnosis or GP record. Data that reveals information about a person’s physical or mental health can qualify, and an employer should also treat outputs that credibly infer health status with great care. A fatigue score, a stress-risk prediction or a recurring abnormal-reading alert may therefore create a special-category data issue even where the device records seemingly neutral signals.
That matters because one legal justification is not enough. The employer must identify both an Article 6 lawful basis for the personal-data processing and a separate Article 9 condition for the special-category element. The ICO explains this two-stage requirement in its guidance on special-category data.
The appropriate combination depends on the facts. Where an employer is meeting a genuine legal duty connected to employment, health and safety, or equality duties, a lawful basis such as legal obligation may be relevant, together with the employment, social-security and social-protection condition where its requirements are met. That condition requires a clear legal foundation and, in applicable cases, an appropriate policy document under the Data Protection Act 2018. Do not select a condition simply because it sounds helpful: document the exact duty or right and why this processing is necessary to meet it.
For a non-essential wellbeing perk, the stronger answer may be to keep the employer out of the health data entirely. The provider might offer the app directly to the worker, with only truly anonymous, aggregated information supplied to the business. However, check the actual data flow: pseudonymised records that can be linked back to staff are still personal data.
Why workplace consent is often the wrong answer
It is tempting to put a consent tick box in the onboarding form and assume the issue is resolved. It is not. Consent must be freely given, specific, informed, unambiguous and withdrawable. For special-category data, the relevant condition is generally explicit consent, confirmed by a clear statement. The central difficulty at work is the power imbalance: staff may reasonably worry that saying no will make them seem uncooperative or affect opportunities.
The ICO says consent is rarely appropriate in employment because of that imbalance. It may be considered for a wellness programme only where workers have a real choice, can leave at any point and face no adverse consequences for declining or withdrawing. The ICO’s example of voluntary health monitoring is a useful benchmark.
“Optional” is not genuine if non-participants lose a benefit, cannot access the workplace, receive less attractive shifts, are excluded from a team challenge, must repeatedly explain their decision, or are visibly identified as opting out. It is also weak where the business has already decided that everyone must use the tool to perform the role. In that situation, explore another lawful route only if the monitoring is genuinely necessary and legally supported; do not relabel a compulsory scheme as consent.
Build a real alternative
Where explicit consent is the intended basis, create an equally practical non-data alternative. A worker who does not want a biometric or wearable method should not face extra delay, stigma or inferior treatment. For a voluntary wellbeing scheme, that could mean access to the same coaching, information or reward without sharing personal activity data with the employer. Record consent separately from the employment contract, make withdrawal straightforward and ensure withdrawal stops future employer access. Explain what happens to existing data, subject to any lawful retention requirement.
Complete a DPIA before buying or switching on the system
A data protection impact assessment (DPIA) is not a form to complete after procurement. It is the structured process that tests whether the proposal should proceed, what safeguards it needs and whether a less intrusive design is better. The ICO requires a DPIA before processing likely to result in high risk. Its examples include innovative technology used with other high-risk features, certain biometric processing, large-scale sensitive-data processing and automated decisions about access to opportunities or benefits. See the ICO’s DPIA threshold guidance.
Employee health apps and AI wearables commonly raise several warning signs at once: workers are in a dependent relationship with the employer; the technology may systematically observe behaviour; health data or inferences are involved; and the output may influence work allocation or management action. Even a small employer should treat a DPIA as the sensible default for this type of rollout. The ICO specifically advises a DPIA before health-monitoring processing starts.
A useful DPIA should describe the data journey from device to dashboard, not just repeat the supplier’s marketing claims. Include the people affected, data categories, collection frequency, device permissions, locations of processing, recipients, retention periods, proposed lawful bases and special-category condition. Assess risks such as embarrassment, discrimination, inaccurate flags, manager overreach, unauthorised access, loss of trust and pressure to disclose a condition.
Then identify controls: reduce fields, disable location tracking, prevent raw-data access, use aggregation, limit alerts, introduce role-based permissions, set short deletion periods, train managers and prohibit use in disciplinary or performance processes. Consult affected workers or their representatives as part of the assessment where appropriate. If high risk remains after planned mitigations and cannot be reduced, the business must consult the ICO before going ahead. The ICO’s DPIA guidance explains this prior-consultation point.
Put boundaries around AI, scores and automated decisions
AI does not make a weak data case stronger. An AI-enabled wearable may estimate fatigue from movement, sleep or physiological patterns, but its score is still an output that can be inaccurate, unequally reliable across groups or misleading without context. A worker caring for a baby, managing a disability, taking medication or recovering from illness may have data patterns that tell a poor story about their ability to work safely or effectively.
Decide in advance what a score can and cannot do. A sensible starting position is that it may prompt a supportive, confidential conversation or encourage the worker to seek advice; it must not by itself trigger discipline, performance action, pay consequences, selection decisions or exclusion from work. Give people a clear way to challenge an alert, provide context and obtain a meaningful human review.
UK GDPR has specific safeguards for solely automated decisions with legal or similarly significant effects. The ICO defines automated decision-making as a decision made without meaningful human involvement, and explains the protections around such significant decisions. Read the ICO’s guidance on workers’ health data and automated decisions. A manager rubber-stamping an AI recommendation is not meaningful human involvement. Build a review process in which a trained person can genuinely depart from the score after considering reliable, relevant information.
Control the vendor: procurement is a GDPR control, not an IT formality
Most small businesses will use an external platform, device maker, app store or analytics provider. First establish each party’s role. If the supplier processes staff data only on your documented instructions, it is likely to be a processor. If it decides its own purposes, for example using identifiable workforce data for product development, advertising or independent analytics, it may be a separate or joint controller. The label in the contract is less important than the reality of who decides the purposes and means.
Where the supplier is your processor, the UK GDPR requires a written contract with specific Article 28 terms. These include processing only on documented instructions, confidentiality, appropriate security, controls on sub-processors, help with individual rights and incidents, deletion or return at the end of the service, and audit or information rights. Use the ICO’s processor-contract checklist rather than relying on a standard click-through agreement.
Questions to ask every wellbeing-tech supplier
- Exactly which raw data, derived data, scores and device identifiers are collected?
- Can the employer configure the system so it receives only anonymised or aggregated results?
- Will data be used for model training, product improvement, advertising, research or any purpose beyond our instructions?
- Who are the sub-processors, where do they process data and how will we be told about changes?
- What technical and organisational security measures protect data in transit and at rest?
- How quickly will the provider notify us of a personal-data breach and assist with access, deletion and correction requests?
- Can we export and securely delete all data at contract end, including backups subject to defined limits?
- Does any processing involve a restricted international transfer, and what transfer mechanism and assessment support it?
Do not assume a UK-facing app keeps data in the UK. Map cloud hosting, support access, analytics and sub-processors. International transfers require their own UK GDPR analysis. The ICO’s restricted-transfer guidance is a practical starting point.
Make transparency, access and retention work in day-to-day practice
Before enrolment, give workers a plain-English privacy notice specific to the scheme. It should explain the purpose, lawful basis, special-category condition, data types, source, recipients, vendor role, retention, international transfers, rights, complaint route and whether any automated decision-making or profiling is involved. The ICO stresses that employers should be clear, open and honest about health-data use, including who will access it and why; covert collection is very unlikely to be justifiable. See the ICO’s worker-health transparency guidance.
Privacy notices alone do not prevent misuse. Restrict access to a named, small group with a genuine need to know. In most cases, a line manager does not need raw health information or a continuous activity feed. Keep occupational-health information, HR case data and wellness-platform data separated. Train managers not to request screenshots, interrogate staff about scores or use a health alert as a shortcut around proper absence, capability or reasonable-adjustment procedures.
Set a retention schedule before launch. A weekly activity record should not sit indefinitely in an HR file because it might be useful later. Retain identifiable information only for the period justified by the stated purpose, then delete or irreversibly anonymise it. Review the scheme at defined intervals and stop it if the original need disappears or promised benefits do not materialise.
A practical pre-launch checklist for small employers
- Define: write the narrow workplace purpose and prohibited uses.
- Minimise: remove data fields, tracking and manager dashboards that are not essential.
- Justify: document the Article 6 lawful basis and Article 9 special-category condition.
- Assess: complete and approve a DPIA before deployment; involve workers early.
- Choose carefully: if relying on consent, provide a genuine no-detriment alternative and an easy withdrawal route.
- Contract: verify controller/processor roles, Article 28 terms, sub-processors, security, deletion and transfers.
- Protect: limit access, prohibit inappropriate HR uses and set meaningful human review for AI outputs.
- Explain and review: issue a clear privacy notice, train managers, test rights-request processes and review the system regularly.
Launch trust, not surveillance
Employee wellbeing technology can be helpful when it gives workers control, solves a real problem and keeps sensitive information out of unnecessary management processes. It becomes risky when a business collects intimate data because it is available, treats participation as compulsory or lets automated scores influence employment decisions without robust safeguards.
For UK small business owners, the most valuable pre-launch question is simple: would we still choose this design if every worker fully understood what it records, who sees it and how it might affect them? If the answer is uncertain, redesign before rollout. Complete the DPIA, tighten the supplier terms and seek specialist data-protection and employment-law advice where health monitoring, biometrics, safety-critical roles or AI-driven decisions are involved. A privacy-respecting programme is not only easier to defend under UK GDPR; it is far more likely to earn the trust that a wellbeing initiative needs to succeed.





















