Authors: Shohrah Kadwani, Swati Dahiya, Shivangi Bhupendra, Krishnapriya KS, Archit Bhattacharya, and Ayeni Sarah Biola
Abstract
The rapid expansion of digital health technologies through wearable devices, health applications, and AI-driven technologies has created a shift in how traditional patient health data is being handled. As health data increasingly shifts from traditional healthcare institutions to consumer-facing digital platforms, it creates regulatory challenges that existing legal frameworks were not designed to address. This paper examines how effectively the United Kingdom and European Union protect digital health data privacy in this evolving environment. This paper uses a qualitative and comparative approach to analyse the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018, the Data (Use and Access) Act 2025, the European Union’s General Data Protection Regulation (GDPR), and the European Health Data Space (EHDS). Research was conducted into legislation, academic literature and case studies, and the paper is divided into three interconnected themes: wearable technologies, public trust and consent. The findings draw on the concept of regulatory lag, and suggest that despite comprehensive legal frameworks, both jurisdictions face a common structural problem: technological innovation seems to be advancing faster than policy can respond. Wearable technologies blur the distinction between lifestyle and health data to exploit the gaps in existing regulatory frameworks, and current consent mechanisms often fail to provide meaningful user control over data. This paper argues that both the UK and EU have largely adopted a reactive, rather than a proactive approach to digital health governance and emphasises a need to incorporate stronger consent mechanisms, oversight of wearable technologies and clearer accountability structures to adapt to an increasingly digital healthcare environment.