The Dutch Data Protection Authority (AP) is examining how period-tracking applications handle sensitive personal information, warning that millions of users may be sharing intimate health data without fully understanding how it is collected, processed or potentially shared with third parties. The regulator has indicated that a formal investigation into these apps remains a possibility.
Period-tracking applications are widely used to monitor menstrual cycles, fertility and pregnancy. Many allow users to record information such as the start and end of menstrual periods, ovulation estimates, hormonal symptoms, sexual activity and other health-related details. Because these records can reveal highly personal information about an individual’s health and reproductive life, they are subject to enhanced legal protections under European data protection law.
Under the General Data Protection Regulation (GDPR), health data is classified as a special category of personal information. Organisations may process such information only under specific legal conditions, including obtaining explicit consent from the individual where required.
The Dutch regulator says it remains unclear whether some period-tracking apps disclose users’ health information to advertising networks, analytics providers or other external partners, and whether users receive sufficiently clear explanations about those practices before agreeing to them.
Monique Verdier, Vice Chair of the Dutch Data Protection Authority, warned that the information collected by these applications could create significant privacy risks if it is used beyond the purposes expected by users. She noted that menstrual cycle, fertility and sexual health information is among the most sensitive categories of personal data and should not be shared without informed consent.
The regulator also cautioned that health records can become valuable targets for cybercriminals. Unlike financial information, which can often be replaced after a breach, intimate medical and reproductive data cannot be changed once exposed, making it potentially useful for identity fraud, extortion or other forms of abuse.
Although the AP has not announced a formal enforcement action, it is encouraging users to review privacy notices carefully before entering sensitive information into health applications. The authority recommends checking whether an app clearly explains how personal data will be used, whether information is shared with third parties and whether users have meaningful options to refuse non-essential data processing.
Concerns surrounding menstrual health applications are not new. Researchers from the University of Cambridge’s Minderoo Centre for Technology and Democracy previously described period-tracking apps as a valuable source of behavioural and consumer profiling data, arguing that detailed reproductive information could be analysed for purposes extending well beyond healthcare.
The discussion has also been shaped by legal action involving one of the sector’s largest applications. In September 2025, Google and the fertility-tracking app Flo agreed to settle a class-action lawsuit for $56 million. The plaintiffs alleged that personal information collected through the app was transmitted using Google’s software development kit and subsequently used to support personalised advertising and related services. The settlement resolved the claims without establishing liability.
As digital health applications continue to gain popularity, privacy regulators across Europe are paying closer attention to how developers collect, store and share sensitive health information. The Dutch authority’s review signals that the handling of reproductive health data may face increased regulatory scrutiny in the future.