Fitbit Public Preview Review: Intuitive Health Tracking Tool

Fitbit is a capable consumer health tracker, but from a data privacy and enterprise security perspective, it is one of the riskiest wearable platforms available in 2026. Following Google's full acquisition and mandatory account migration, users of Fitbit now have their biometric health data governed by Google's broader privacy policy — a significant concern for IT security teams and compliance officers. For individuals seeking a fitness tracker reviewed from a cybersecurity lens, read our wearable device security guide on NetworkUstad.com before committing to this platform.
Fitbit and Google: The Acquisition That Changed Everything
Google acquired Fitbit in January 2021 for $2.1 billion, and since then the platform has undergone a complete architectural shift. What was once an independent fitness tracking ecosystem has been absorbed into Google’s broader services infrastructure. By May 19, 2026, all remaining Fitbit accounts were required to migrate to Google Accounts — making it impossible to use Fitbit without handing your health data to one of the world’s largest data brokers. Users who had not migrated by May 19, 2026 lost access to their Fitbit accounts. Google has scheduled data deletion to begin on July 15, 2026 — users can still download their data before that date. The forced migration met significant user resistance, with Google extending its original 2025 deadline multiple times before enforcing the final cutoff. For enterprise IT teams, this consolidation is a critical governance event: health data that was once siloed in a niche fitness app now sits inside Google’s unified data environment.
Health Data Privacy: What Google Actually Collects
Once a user migrates to a Google Account, all Fitbit health metrics — heart rate, sleep patterns, blood oxygen, skin temperature, menstrual cycle data, EDA stress scores, GPS location during workouts, weight logs, and daily activity histories — are governed by the Google Privacy Policy. Google has formally pledged that Fitbit health and wellness data will not be used for ad targeting, and this commitment was contractually enforced by the European Union as a condition of its merger clearance through at least 2024. However, the long-term trajectory is less reassuring. A 2025 systematic analysis published in the Journal of Medical Internet Research identified Google/Fitbit as having among the most permissive data-sharing terms of all major wearable manufacturers. The policy’s language permitting data use to “improve services” is broad and difficult to audit, meaning third-party developers and researchers may gain access to aggregated or anonymised health data pools derived from Fitbit users.
GDPR Compliance: The European Regulatory Lens
For users in the European Economic Area, United Kingdom, or Switzerland, Fitbit International Unlimited (an Irish entity) serves as the designated data controller under the GDPR. Fitbit requests explicit consent before processing any health data — categorised as a “special category” under Article 9 of the GDPR — when pairing a device, enabling exercise data import, or activating features such as female health tracking. Consent can be withdrawn at any time through account settings. Following the migration to Google Accounts, Fitbit and Google entered a joint processing arrangement for limited profile information including user names, photos, and friends lists. This joint controllership arrangement is a nuanced compliance area that data protection officers (DPOs) at European enterprises should examine carefully before deploying Fitbit in workplace wellness programs. The Irish Data Protection Commission oversees Fitbit’s GDPR obligations, and any cross-border data transfers must comply with Standard Contractual Clauses (SCCs) or equivalent adequacy mechanisms.
HIPAA and the Enterprise Wellness Risk
This is where Fitbit’s risks become most acute for US-based corporate environments. HIPAA — the Health Insurance Portability and Accountability Act — only applies to covered entities: healthcare providers, insurers, and their business associates. Consumer wearable companies, including Fitbit, Google, Apple, and Garmin, are not covered entities by default. However, there is an important nuance: Fitbit can operate within a HIPAA-compliant framework when deployed via a Business Associate Agreement (BAA) with a covered entity, or when integrated into an employer’s group health plan that itself qualifies as a covered entity. In those specific enterprise contexts, HIPAA obligations can flow down. Outside of such formal arrangements — which is the case for the vast majority of consumer and corporate wellness deployments — employee biometric data collected through Fitbit has no federal HIPAA protection. The data collected by wearables — heart rate, sleep cycles, SpO2, skin temperature — qualifies as biometric information under several state laws. Illinois in particular has the Biometric Information Privacy Act (BIPA), which imposes strict requirements including written consent, retention policies, and prohibition on selling biometric data. Employers using Fitbit in wellness incentive programs without a properly drafted consent framework and data processing agreement face real legal exposure under BIPA and equivalent state laws in Texas, Washington, and California. Legal analysis from Akerman LLP published in June 2025 confirmed that the biometric data collected by wearables in corporate programs could trigger disability discrimination claims if used in employment decisions — even indirectly.
Corporate Wearable Policies and IT Security Considerations
Enterprise security teams evaluating Fitbit for employee wellness programs should approach the device through the same BYOD framework applied to smartphones and tablets. The Fitbit Charge 6 and Sense 2 communicate via Bluetooth LE — a protocol that, while low energy, still exposes health data in transit to any device within range if Bluetooth security hygiene is not enforced. The devices sync via the Google Health app on employees’ smartphones, meaning corporate health data passes through personal mobile devices, personal Google accounts, and Google’s cloud servers — all outside the corporate perimeter. This data pathway sits entirely outside the reach of corporate DLP (Data Loss Prevention) systems and MDM (Mobile Device Management) solutions. Security-conscious enterprises should require a separate Google Account dedicated to corporate wellness participation, publish a clear wearable device policy governing acceptable use, and work with legal counsel to draft participant consent forms that address state biometric privacy laws. HR and IT teams should also be aware that Fitbit data — even aggregate step counts and activity trends — may contain enough information for insurers or third parties to make inferences about employee health status, creating potential ADA (Americans with Disabilities Act) liability if that data influences employment decisions.
Verdict
Fitbit remains a technically impressive consumer health platform with a mature sensor suite, seamless Google ecosystem integration, and broad fitness tracking capabilities. But viewed through a data privacy and enterprise security lens, it is a high-risk deployment. The mandatory consolidation into Google Accounts, the absence of HIPAA coverage, permissive data-sharing language in Google’s privacy policy, and significant state-level biometric law exposure make Fitbit a liability-heavy choice for corporate wellness programs without rigorous legal and technical controls in place. Individual users who are comfortable within Google’s ecosystem and not in regulated industries will find Fitbit a capable and well-priced wearable. Enterprise and healthcare-adjacent environments should conduct a formal privacy impact assessment before deployment.
Rating: 3.2 / 5 — Capable wearable hardware undermined by serious health data privacy risks in the post-acquisition Google ecosystem.
Reviewed based on Fitbit/Google Privacy Policy, Google Health FAQ, Akerman LLP BIPA Analysis — June 2025, Vora Wearable Privacy Report — March 2026, 9to5Google Fitbit Migration Coverage — July 2026.
Frequently Asked Questions
Is Fitbit HIPAA compliant?
Does Google use Fitbit health data for advertising?
What happened to Fitbit accounts in 2026?
Is Fitbit GDPR compliant for European employees?
Can employers legally require employees to use Fitbit in wellness programs?
What data does Fitbit Charge 6 collect and store locally?
How does Fitbit compare to Apple Watch for privacy?
What should an enterprise do before deploying Fitbit in a wellness program?
+Pros
- Rich biometric sensor suite — ECG, EDA, SpO2, skin temperature all in one device
- Google's infrastructure provides strong encryption and two-factor authentication
- Explicit GDPR consent mechanism for health data collection in EEA/UK/Switzerland
- Broad enterprise wellness program support with historical deployments across Fortune 500 firms
- Google's commitment (contractually enforced by EU) to not use Fitbit health data for ad targeting
−Cons
- Google Account is now mandatory — health data is fully consolidated into Google's data ecosystem
- HIPAA does not apply to Fitbit as a consumer wearable — corporate health data has no federal protection
- Post-acquisition Google Privacy Policy permits use of data to "improve services" — a broad and legally ambiguous clause
- Users who had not migrated by May 19, 2026 lost access to their Fitbit accounts; Google will begin deleting account data on July 15, 2026
- State-level biometric laws (e.g. Illinois BIPA) create serious legal exposure for employers using Fitbit in wellness programs