To Track or not to Track? Employees’ Privacy in the Age of Corporate Wellness, Mobile Health, and GDPR
Bibliographic record
Abstract
The latest digital health developments have allowed for a better tracking of individuals’ health through wearable devices and health apps, also known as ‘mobile health’ (mHealth). mHealth companies do not only target individual consumers, but also businesses, as they see a market in corporate health and wellness programs. As such, some employers now offer employees to use fitness wristbands or smartwatches so that employees can monitor their health at work and beyond. These devices and apps enable users to track their exercise, number of steps, sleep patterns, eating habits and a myriad of other health-related activities, which are often non work-related. Employers present mHealth devices and apps as company ‘perks’ for employees. However, mHealth may come at a price for employees, who may unwillingly share their most personal information (health information) with their employer and third parties, such as mHealth developers, and/or insurance companies. Therefore, this article investigates the lawfulness of the use of mHealth devices and apps in the context of corporate wellness programs, in particular in light of employees’ rights to privacy, data protection, and non-discrimination under European Union (EU) law and under the European Convention on Human Rights (ECHR) and related case law. First, the article analyzes the conditions for a valid consent given by an employee to the processing of her health data, as set under the EU General Data Protection Regulation (GDPR), and related interpretative guidelines and opinions. The current regime seems very protective of employees’ privacy: in an advisory opinion on data processing at work issued in 2017, the European Data Protection Working Party stated that employees’ free consent to the processing of mHealth data is highly unlikely because of the sensitive nature of health data and the unequal relationship between employers and employees. The article argues that this highly protective regime is not only a way to protect employees’ right to privacy, but also to protect them against any potential discrimination on prohibited grounds, such as pregnancy, disability or health status, as such discrimination in the workplace is often indirect and difficult to prove. Therefore, measures which are less intrusive of employees’ privacy, namely, which do not track employees’ health information, may be deemed more proportionate under EU law and under the ECHR. Secondly, in the event where an employee’s consent to use mHealth technology were found valid in the employer-employee relationship, the article analyzes how third parties developing mHealth apps and devices also need to respect employees’ privacy. This question is answered in light of the recent Draft Code of Conduct on privacy for mobile health applications, as well as EU and ECHR law. The article concludes that although the European privacy regime may seem overly protective of employees’ privacy and data, this may benefit mHealth developers in the long-run by fostering a culture of trust by users of these technologies, who will know that their data cannot be used against them.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.005 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.002 |
| Science and technology studies | 0.001 | 0.001 |
| Scholarly communication | 0.000 | 0.001 |
| Open science | 0.003 | 0.001 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.038 | 0.007 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; both teacher heads agree on what is shown here.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".