The Dutch data protection authority today warned that menstruation apps hold some of the most intimate information people record anywhere, and said it does not rule out opening an investigation. A redacted internal report from the UK regulator, which ran that same enquiry and closed it without enforcement, shows what such a review actually produces.
The Autoriteit Persoonsgegevens (AP) published its statement on 04 August 2026, calling for restraint in what people share with cycle and fertility trackers. Nearly a quarter of Dutch women use such an app, according to research cited by the regulator. The apps record when a period started, which hormonal symptoms were experienced and when the user had sex, and return predictions about cycle length and ovulation.
That is the material at issue. According to the AP, these apps gather a large volume of highly personal data that qualifies as special category data under the General Data Protection Regulation, which in principle may not be collected at all unless a specific exemption applies, such as explicit consent from the individual.
What happens to it afterwards is the part the regulator says remains opaque. According to the AP, it is not clear in practice whether the apps share this information with advertising partners, or whether users have been properly informed that they do.
The regulator's language is unusually direct
Monique Verdier, vice-chair of the AP, framed the exposure in commercial terms. "Girls and women record a lot of intimate information in these apps. That makes them vulnerable. For example, when this sensitive information ends up with advertisers unintentionally. Because with free apps you often 'pay' with your data. In this case with information about when you have sex or when your period is late," she said, in remarks published in Dutch.
Verdier also raised a second route out of the app. "Your data can also fall into the hands of hackers. These criminals target the most sensitive personal data precisely because it allows them to blackmail people," she said.
The AP set out three requirements for providers of these apps under the GDPR: demonstrate why collecting and possibly sharing special category data is exempt from the regulation's processing prohibition; state plainly what they do with personal data and inform users in advance; and put appropriate technical and organisational measures in place, including protection against data breaches.
Then came the line that separates this statement from routine guidance. "We are concerned about how these apps work and about their security. Precisely because of the sensitivity of the information. The AP has these apps in its sights and does not rule out starting an investigation," Verdier said.
The enquiry another regulator already ran
There is a documented answer to the question of what a national regulator finds when it opens the hood on this category. The UK Information Commissioner's Office ran the exercise between 2023 and early 2024, and an internal report on the work, disclosed with substantial sections blacked out, records the method and the result in detail.
The project was designated a PACE project in May 2023, testing a single problem statement: that fertility and period tracking apps are misusing the data of their users in a way which causes harm. Its lineage runs back further. Concerns first reached the ICO in 2019 following a Privacy International investigation into menstruation app data sharing, with further findings published by the same campaign in December 2020. In November 2020 the regulator received a complaint from an individual whose data appeared to vanish on upgrading to a new handset despite a premium subscription. A December 2022 strategic assessment named online tracking as a regulatory priority and singled out fertility and menstruation apps; the ICO's first Tech Horizons report, published the same month, listed consumer healthtech and named fertility tracking apps within it.
The scoping numbers give a sense of the market. A November 2022 internal briefing identified 28 fertility apps, 49 menstrual apps and 30 combined trackers, with overlap between the lists. Eight period tracking apps on the UK Google Play Store carried download figures between 10 million and 100 million. In total, 37 apps were reviewed, alongside 11 media articles and 14 academic papers. One structural finding shaped everything after it: only 10 percent of the FemTech market is UK-based, which the report describes as a considerable risk that entities outside the UK are processing UK citizen data.
Eleven app providers were contacted with a 16-part enquiry. It asked which data fields were mandatory and why, which lawful basis applied, which Article 9 condition covered special category data, the identity of every third party receiving data, whether each was a controller or a processor, copies of data sharing agreements, screenshots of the consent and withdrawal journeys, whether any anonymised data was shared and which privacy enhancing technologies achieved the anonymisation, whether profiling occurred within the meaning of Article 4(4), where data was stored, retention periods, and the mechanics of access, rectification and erasure requests.
Ten of the eleven responded without the ICO needing to serve Information Notices. The identities of the apps sit in an appendix that is entirely redacted, as is the compliance table summarising performance across the ten respondents and two full workstreams of the project.
Where the advertising data actually went
The technical finding at the centre of the report is narrower than the headlines around this category usually suggest, and more useful because of it.
According to the report, data relating to menstruation, period tracking and health is shared only for purposes tied to storage, security, cycle prediction functionality and customer support. In those cases the apps identify explicit consent as the Article 9 condition. The assessment states there is no evidence that the apps are sharing sensitive data for advertising purposes.
Other categories move differently. IP address, device data, usage data and advertising ID are shared by some apps for advertising and marketing. In most cases the recipients are processors acting on the app developer's instructions. Two responses confirmed that some third parties are controllers in their own right, and every third-party controller in those cases was engaged for advertising. None of the data reaching those parties, according to the report, consists of personal information typed in by users.
That distinction is precisely the one Mozilla drew in hands-on testing published on 16 July 2026, which scored six period tracking apps and placed Stardust at 2 out of 10. Period Calendar, the only ad-supported app in that set, sent device model, screen dimensions and timezone to Google advertising systems from the moment its home screen loaded, with each request naming the originating app. No symptom log left for advertisers. The app name attached to a persistent identifier was sufficient on its own to file a device under a reproductive health signal.
Set against the UK enquiry, the two records describe the same architecture from opposite ends. The ICO asked what apps say they share and received answers that keep special category data out of the ad stack. Network testing shows what an ad system can infer without ever receiving a symptom.
Despite the reassurance on sensitive data, the internal report is blunt about the compliance picture. Detailed review of the responses pointed to excessive data collection, inappropriate lawful bases, failure to obtain valid consent, a general lack of transparency, inadequate security measures and an overall lack of accountability. Concerns were sorted into nine areas: data minimisation, lawful basis, valid consent, transparency, security, retention, individual rights, data sharing and accountability. The report identifies systemic issues regarding the lawful bases relied upon and a failure to obtain valid consent, coupled with a general lack of transparency about the processing at hand, including sharing with third parties.
What 1,152 women told the regulator
The ICO commissioned Savanta to poll 1,152 UK women aged 18 and over between 1 and 3 September 2023, weighted by age, gender, region and social grade. A third had used an app to track periods or fertility.
Ranking what mattered when choosing an app, respondents put transparency over how data is used at 59 percent and security of that data at 57 percent, both above cost and ease of use at 55 percent each. The volume of adverts inside the app came last at 21 percent.
The advertising finding is the one that travelled. Among people who had used such an app, 54 percent believed they had noticed an increase in baby or fertility-related adverts since signing up. Of those, 17 percent described receiving them as distressing and 18 percent described them as positive.
A call for evidence followed, open from 7 September to 5 October 2023, drawing 187 responses from individuals aged 17 to 52. The report treats it as qualitative rather than representative. Some 64.5 percent considered their experience positive, 43.5 percent said it did not change their usage and 26.6 percent used the app more afterwards.
More than 30 responses raised targeted advertising. One respondent reported receiving conception and baby product advertisements while having no interest in children. Another wrote that "all I have gotten from it are constant fertility adverts which has definitely affected me negatively" after logging a pregnancy that subsequently miscarried. A third described an access request revealing data shared with entities they had not specifically consented to.
Ten in-depth interviews and two focus groups run by IFF Research Limited produced the finding that explains the rest. There were no unprompted mentions of data security or privacy. None of the lapsed users had stopped over data concerns. Participants assumed apps are validated as safe by virtue of appearing in an app store. During app walkthroughs, nobody clicked the privacy policy unprompted. The report concludes that a lack of user engagement with privacy notices allows app providers to perpetuate poor privacy practices under the radar.
Closure letters, not enforcement
Two options were put forward. The first was bespoke advice and guidance to each provider based on the specific concerns raised in its response. The second was formal investigations into each app, which the report describes as time consuming, resource intensive and without guarantee of successful outcomes given cross-border enforcement difficulties.
Option one was recommended. Closure letters went to the apps engaged with, carrying tailored advice. The compliance concerns were characterised as limited to consent and transparency, addressable through guidance, and not unique to this sector, making it disproportionate to single it out. The report adds a caveat with a long tail: if a future breach, complaint or allegation arises around these compliance issues, the ICO would be in an informed position when opening an investigation. Findings were fed into the regulator's wider adtech strategy work.
The public output landed on 8 February 2024, when the ICO reminded all app developers to prioritise privacy. Emily Keaney, Deputy Commissioner Regulatory Policy, said: "Signing up to an app often involves handing over large amounts of personal information, especially with apps that support our health and wellbeing. Users deserve peace of mind that their data is secure, and they are only expected to share information that is necessary." The statement set out four reminders covering transparency, valid consent without pre-ticked boxes, correct lawful basis selection without a one-size-fits-all approach, and accountability as data controller.
Why this lands on media buyers
The gap between the two records is the practical point. The UK regulator found no evidence of sensitive data flowing into advertising, and still found bundled consent declarations, insufficient information on processing and users inadvertently losing control over granular choices. The AP is now looking at the same question in a market where the apps are, in the main, based elsewhere.
The Dutch authority has a demonstrated range of outcomes. It closed a cookie banner investigation into five website operators with final letters rather than penalties after corrective measures were implemented. It also fined the operator of drugstore chain Kruidvat 600,000 euros over tracking cookies set without valid consent, and imposed a 100 million euro penalty on the Netherlands parent of ride-hailing app Yango over transfers to Russia. Which end of that range applies here depends on what an investigation, if opened, finds in the traffic rather than in the privacy policy.
For buyers, the exposure sits in the inference layer rather than in the payload. Google tightened how Demand Gen and Discovery campaigns serve against sensitive interest categories in June 2026, restricting advertiser-curated audiences that might carry embedded health signals. California fined a data broker 45,000 dollars for reselling consumer lists organised by health condition in January 2026. A federal jury in San Francisco found that Meta violated the California Invasion of Privacy Act by collecting reproductive health data through Flo in August 2025.
The UK regulatory direction has meanwhile moved the other way on low-risk cases. The ICO advised government in May 2026 to relax PECR regulation 6 consent requirements for contextual targeting, frequency capping and measurement, while keeping behavioural advertising firmly inside the consent perimeter. Reproductive health inference is not a low-risk case under anybody's definition, and the ICO's own file shows the sector's compliance weaknesses sitting exactly where consent and transparency are assessed.
Timeline
- 2019: Privacy International publishes research into menstruation app data sharing; the ICO begins considering the sector
- November 2020: The ICO receives a complaint about a period app account and access to a subscriber's data
- December 2020: Privacy International publishes further findings from the same campaign
- November 2022: An internal ICO briefing identifies 28 fertility apps, 49 menstrual apps and 30 combined trackers, with eight UK titles between 10 million and 100 million downloads
- December 2022: The ICO strategic assessment names online tracking a regulatory priority; the first Tech Horizons report lists fertility tracking apps
- March 2023: Scoping work begins on fertility and menstrual apps
- April 2023: An internal problem profile on FemTech and women's health apps is produced
- May 2023: The workstream is designated a PACE project
- June 2023: External stakeholder analysis begins
- 1 to 3 September 2023: Savanta polls 1,152 UK women for the ICO
- 7 September to 5 October 2023: The ICO call for evidence collects 187 responses
- 8 February 2024: The ICO publishes its four reminders to app developers following the review
- July 2024: The Dutch regulator fines Kruidvat operator AS Watson 600,000 euros over tracking cookies
- July 2025: The Dutch regulator publishes the letters closing its cookie banner investigations into five operators
- 4 August 2025: A federal jury finds Meta violated the California Invasion of Privacy Act through data collected in Flo
- January 2026: California fines a data broker 45,000 dollars for selling health condition lists
- 1 April 2026: The Dutch regulator fines Yango parent MLU B.V. 100 million euros over transfers to Russia
- May 2026: The ICO advises the UK government to cut consent requirements for low-risk advertising
- 3 June 2026: Google clarifies sensitive category serving for Demand Gen and Discovery campaigns
- 16 July 2026: Mozilla publishes privacy testing of six period tracking apps, scoring Stardust 2 out of 10
- 04 August 2026: The Autoriteit Persoonsgegevens warns about menstruation apps and says it does not rule out an investigation
Related PPC Land coverage
- Mozilla rates Stardust 2 of 10 over symptom data sent to third parties documents network testing of six trackers, including device identifiers reaching Google ad systems from an ad-supported cycle app.
- Jury finds Meta violated privacy law collecting health data reports the August 2025 verdict over menstrual and reproductive data gathered through a period app integration.
- Dutch regulator releases final letters on cookie banner probe shows how the AP has previously closed consent investigations with corrective letters rather than fines.
- Dutch privacy watchdog fines Kruidvat 600,000 euros for illegal tracking cookies covers the penalty imposed for setting tracking cookies without valid consent.
- Yango's 100 million euro GDPR fine: Dutch watchdog cracks down on data flows to Russia illustrates the upper end of the AP's enforcement range.
- UK's ICO tells government to cut consent rules for low-risk ads sets out the regulator's advice on PECR regulation 6 and where behavioural targeting still requires consent.
- UK regulator investigates RTB in compliance with GDPR covers the ICO finding that bid requests carry special category data including physical and mental health signals.
- Google tightens Demand Gen and Discovery ad serving for sensitive categories explains the restrictions on advertiser-curated audiences that may contain health signals.
- California data broker fined 45,000 dollars for selling health condition lists describes enforcement against resale of consumer records organised by medical condition.
- UK Court of Appeal rewrites consent rules for gambling marketing sets the objective standard controllers must apply when assessing whether consent was validly given.
Summary
Who: The Autoriteit Persoonsgegevens, the Dutch data protection authority, with vice-chair Monique Verdier as its named spokesperson. The comparison material comes from the UK Information Commissioner's Office, its polling partner Savanta, its research contractor IFF Research Limited, and the eleven unnamed app providers contacted during the UK enquiry.
What: A public warning about privacy risks in menstruation and fertility tracking apps, stating that the regulator does not rule out opening an investigation, alongside three GDPR obligations for providers covering the exemption relied on for special category data, prior information to users, and technical and organisational security. The UK internal report set against it records a 16-part enquiry to eleven providers, ten responses without Information Notices, nine categories of potential compliance concern, and closure letters instead of formal investigation.
When: The Dutch statement was published on 04 August 2026. The UK project ran from its May 2023 designation through polling on 1 to 3 September 2023, a call for evidence from 7 September to 5 October 2023, and a public statement on 8 February 2024.
Where: The Netherlands for the current warning and the United Kingdom for the completed review, with both regulators noting that most providers in this category operate from outside their jurisdiction.
Why: Cycle apps collect data that qualifies as special category under the GDPR, and the unresolved question in both records is not whether symptom logs reach ad platforms, but whether ordinary telemetry such as advertising identifiers and app names supports the same inference without any health field changing hands.
Discussion