guides
Published by Floriva · Updated 2026-05-01 · How Floriva checks its guides
EU vs US: How Period Tracker Privacy Laws Compare
GDPR gives EU users enforceable rights over period tracker data. US users face a patchwork of state laws and no federal equivalent. Here is how the two systems compare for reproductive health privacy.
The EU's GDPR classifies reproductive health data as a special category requiring explicit consent and provides enforceable rights to access, deletion, and data portability. The US has no federal equivalent. American users rely on a patchwork of state laws, FTC enforcement actions, and app developers' voluntary privacy policies.
Two Fundamentally Different Approaches
The EU and the US took opposite approaches to data protection, and the gap is nowhere more consequential than in reproductive health.
The EU built a comprehensive framework, GDPR, that treats health data as a special category deserving heightened protection. It applies to every organization that processes personal data of EU residents, regardless of industry, size, or business model.
The US built nothing equivalent at the federal level. Health data protection exists only through HIPAA, which covers healthcare providers and insurers but not consumer apps. What fills the gap is a patchwork: state consumer privacy laws (where they exist), FTC enforcement authority (reactive, not proactive), and whatever companies voluntarily promise in their privacy policies.
For period tracker users, this difference is not abstract. It determines whether you have enforceable rights over your most intimate health data or whether you are relying on a company's good faith.
GDPR: What EU Users Get
GDPR provides EU residents with specific, enforceable rights over their period tracker data:
Explicit consent requirement (Article 9): Health data, including menstrual cycle data, fertility information, and sexual health data, is classified as "special category" data. Processing requires the user's explicit consent, which must be freely given, specific, informed, and unambiguous. Pre-checked boxes and buried consent clauses do not qualify.
Right of access (Article 15): You can request a complete copy of every piece of personal data a company holds about you. The company must respond within one month, free of charge.
Right to erasure (Article 17): You can demand deletion of your data. The company must comply unless it has a legal obligation to retain it (such as tax records). "We need it for analytics" is not a valid retention reason.
Right to data portability (Article 20): You can receive your data in a structured, machine-readable format and transfer it to another service. This prevents lock-in.
Right to withdraw consent (Article 7): You can revoke your consent to data processing at any time. The company must stop processing and cannot penalize you for withdrawing.
Enforcement with teeth: Data Protection Authorities can fine companies up to 4% of annual global revenue or EUR 20 million, whichever is higher. This gives GDPR enforcement real deterrent power.
How US Law Works
Federal level: No federal consumer health data protection law exists. HIPAA does not apply to consumer apps. The FTC can act against deceptive practices, as it did against Flo and Premom, but only after a violation occurs and only when the FTC has the resources to investigate.
State level: A handful of states have enacted relevant laws:
Washington: The My Health My Data Act (2023) explicitly covers consumer health data including reproductive health information. It requires consent for collection and sharing, provides a private right of action (users can sue directly), and applies to any entity collecting health data from Washington residents.
California: CCPA/CPRA provides rights to know, delete, and opt out of the sale of personal data, including health data. Enforced by the California Privacy Protection Agency.
Connecticut, Colorado, Virginia: Consumer privacy laws with varying health data provisions. Generally weaker enforcement mechanisms than Washington or California.
Most other states: No consumer health data law.
The result: An American user's rights over their period data depend primarily on which state they live in. A user in Washington has strong, enforceable rights. A user in Alabama has effectively none specific to consumer health apps.
Clue vs. Flo: A Jurisdictional Case Study
Clue and Flo illustrate how jurisdiction shapes privacy outcomes.
Clue is based in Berlin and directly regulated by Germany's Federal Commissioner for Data Protection (BfDI), one of the stricter DPAs in the EU. Clue must comply with GDPR's special category data requirements for every EU user. It publishes transparency reports and has positioned GDPR compliance as a competitive differentiator.
Flo is headquartered in London (post-Brexit, under the UK GDPR, which mirrors EU GDPR). However, its primary enforcement history is with the US FTC. The FTC's 2021 consent order against Flo required changes to its data sharing practices, but the FTC cannot mandate the structural reforms that a GDPR enforcement action could, such as requiring a Data Protection Impact Assessment or appointing a Data Protection Officer with real authority.
This does not mean Clue is inherently safe and Flo is inherently unsafe. Both store data on servers. Both are subject to the legal risks that come with centralized data storage. The difference is the regulatory floor: GDPR provides a higher baseline of enforceable user rights than any US framework currently offers.
What Both Systems Miss
Neither GDPR nor the US patchwork fully addresses the core problem: data that exists on a company's server is data that can be accessed.
GDPR can mandate consent, access, and deletion. But it cannot prevent a government from issuing a lawful data request to a German company, and GDPR explicitly allows processing when required by law. If a legal framework changes, data that was collected lawfully can become evidence.
US state laws can provide deletion rights, but they cannot retroactively protect data that was shared before the law took effect. They also cannot reach companies outside their jurisdiction.
Both approaches regulate data after it has been collected. Neither addresses the question of whether the data should be collected in the first place.
The Architecture Answer
The strongest protection against both regulatory gaps and jurisdictional uncertainty is data that never reaches a server. On-device-only architecture means:
No server to receive a government data request
No cross-border data transfer to manage
No consent framework to trust or audit
No breach to disclose because there is nothing centralized to breach
This does not make GDPR or state privacy laws irrelevant. Legal protections matter, and stronger laws should be supported. But law follows technology, often by years. If your data never leaves your device, you are not waiting for the law to catch up. This is not legal advice, consult a qualified attorney for guidance on your specific situation and jurisdiction.
Definitions
- GDPR (General Data Protection Regulation)
- The EU's comprehensive data protection law, effective since 2018. It applies to any organization processing personal data of EU residents, regardless of where the organization is based. Health data, including reproductive and sexual health information, is a special category requiring explicit consent.
- Special category data
- Under GDPR Article 9, certain types of personal data including health, biometric, genetic, racial, and sexual orientation data that receive heightened protection. Processing requires explicit consent or another specific legal basis. Period and fertility data qualifies as special category data.
- Data Protection Authority (DPA)
- An independent public body in each EU member state responsible for enforcing GDPR. DPAs can investigate complaints, order organizations to stop processing data, and impose fines of up to 4% of annual global revenue.
Quick answers to the obvious questions.
How do period tracker privacy laws compare between Europe and the US?
GDPR gives EU users explicit rights over their period data: the right to access it, delete it, port it to another service, and withdraw consent at any time. These rights apply to all organizations processing EU residents' data, including app companies. The US has no federal equivalent. Some states like California and Washington have enacted consumer privacy laws, but most Americans have no specific legal right to control their period tracker data.
Is Clue safer than Flo because of GDPR?
Clue, based in Berlin, is directly subject to GDPR and German data protection enforcement. Flo, headquartered in the UK (post-Brexit, under the UK GDPR), has faced FTC enforcement in the US. GDPR compliance provides a meaningful regulatory floor, but it does not guarantee safety, it guarantees that violations have consequences.
Questions people ask before they switch.
Does GDPR apply to American users of EU-based apps?
GDPR applies based on the data subject's location, not citizenship. If you are physically in the EU, GDPR protects your data regardless of your nationality. If you are in the US using a Berlin-based app like Clue, GDPR does not apply to your data, the app's US-facing privacy policy governs instead.
Can EU users request all their period data from any app?
Yes. GDPR Article 15 gives EU residents the right to a copy of all personal data an organization holds about them, provided free of charge within one month. This includes cycle dates, symptoms, notes, and any derived analytics. Companies that refuse or delay face potential DPA enforcement.
Which US states have the strongest period data protections?
Washington's My Health My Data Act is the strongest, explicitly covering reproductive health data with a private right of action. California's CCPA/CPRA provides broad consumer data rights including health data. Connecticut and a handful of other states have enacted consumer privacy laws with health data provisions. Most states have no specific consumer health data law.