Why personal wellbeing tools at work should stay private

An employer can pay for access to a wellbeing tool without needing access to the personal reflections inside it. Privacy matters not only because some information may be legally sensitive, but because trust, power and confidentiality can affect what people are willing to share in the first place.

Published 3 September 2026 · Evidence/legal review date: 3 September 2026 · OASYS Editorial

An organisation provides access to CalmStack, while a separate learner privacy boundary contains private Check-ins, notes and My Pattern. No individual reflections flow back to the organisation.

Your employer pays for a wellbeing tool.

You use it after a difficult meeting.

You record how you are feeling.

Perhaps you write a short note about what happened.

Now ask a simple question.

Should your manager be able to see that?

For us, the answer starts with an important distinction.

The organisation paying for access and the organisation having access to your personal reflections are not the same thing.

A workplace can provide something without needing to observe how every individual uses it.

That distinction matters for privacy.

It also matters for whether the tool is useful at all.

What changes when you think somebody might be watching?

Imagine two versions of the same Check in.

In the first, you believe what you record is for you.

In the second, you think your manager, HR team or employer may eventually see it.

Would you write exactly the same thing?

Maybe.

Maybe not.

Research on disclosure at work suggests that decisions about sharing sensitive personal information are affected by context.

Trust matters.

Power relationships matter.

Who will receive the information matters.

What might happen afterwards matters.

A 2025 review of 71 studies examining disclosure of mental health conditions at work found both possible benefits and possible negative consequences.

Disclosure might help somebody access support or adjustments.

It might also expose them to stigma, changed relationships or other unwanted consequences depending on the workplace and circumstances.

The sensible conclusion is not that people should always disclose.

It is not that people should always keep things private either.

It is that disclosure is a choice whose consequences depend partly on the environment in which the choice is made.

A personal wellbeing tool should not quietly make that choice on somebody's behalf.

Monitoring changes the relationship

There is a wider body of research on workplace monitoring too.

This research is not the same thing as research on wellbeing apps, so we should not pretend that every workplace wellbeing tool automatically counts as employee monitoring.

But it becomes relevant if information from a tool is used to observe workers, infer things about them, evaluate them or feed information back into employment decisions.

A major meta analysis by Daniel Ravid and colleagues brought together 94 independent samples involving 23,461 workers.

They found no overall evidence that electronic performance monitoring improved worker performance.

Monitoring was associated with greater worker stress.

More transparent and less invasive monitoring was also associated with more favourable attitudes among workers.

The point is not:

monitoring is always bad.

Organisations have legitimate reasons to process information about workers in many circumstances.

The point is that collecting information changes the relationship between the person being observed and the organisation doing the observing.

That deserves thought.

Especially when the information is personal.

What does UK data protection law actually say?

This is where precision matters.

UK data protection law does not contain a simple rule saying:

"Employers must never see wellbeing data."

Nor does it say:

"If the company paid for the software, the company can see whatever is inside it."

Neither statement is a useful description of the law.

Employers process personal information for many legitimate reasons.

The legal question depends on what information is being collected, why it is being collected, what is done with it and what safeguards apply.

Current Information Commissioner's Office guidance says employers must have a clear purpose for processing workers' information and must use personal information lawfully, fairly and transparently.

Where monitoring is involved, employers are expected to consider whether it is necessary and whether a less intrusive way could achieve the same purpose.

Simply having access to a technology does not make every possible use of it proportionate.

That is a very useful principle for workplace wellbeing technology.

Is wellbeing information automatically health data?

No.

This distinction is important.

Under the UK GDPR, data concerning health means personal data relating to somebody's physical or mental health that reveals information about their health status.

Health information receives additional protection as special category data.

But the word "wellbeing" on an app screen does not automatically turn every piece of information inside the app into health data.

Context and content matter.

An entry such as:

"Annoyed after the team meeting"

is not automatically legally identical to information revealing a diagnosed health condition or other information about somebody's health status.

Equally, a wellbeing system could collect or infer information that does reveal physical or mental health information.

When that happens, the additional rules for special category data become relevant.

So the accurate position is:

some information collected through a wellbeing tool may constitute health data, depending on what the information reveals.

That is more precise than saying all wellbeing data is legally the same.

Health information comes with extra requirements

Where an employer processes workers' health information, the legal requirements are stricter.

The organisation still needs an appropriate lawful basis under Article 6 of the UK GDPR.

It also needs a valid condition for processing special category data under Article 9.

Depending on the condition used, additional requirements under the Data Protection Act 2018 may also apply.

The ICO also stresses necessity and data minimisation.

An organisation should not collect more health information than it genuinely needs for the purpose it has identified.

That leads to an obvious design question.

If an employer can provide somebody with access to a personal reflection tool without seeing their individual reflections, why should collecting those reflections be necessary?

Sometimes there may be a legitimate reason for an employer to process health information.

Occupational health is an obvious example.

Managing sickness absence or reasonable adjustments may be another.

But those are specific purposes.

They do not create a general entitlement to somebody's personal emotional record.

What about consent?

This is another area where simple answers are misleading.

You sometimes hear:

"It's fine because employees consented."

You also hear:

"Consent can never work between an employer and employee."

Neither is quite right.

The ICO warns that consent is not usually appropriate in employment where the imbalance of power means a worker may feel they do not genuinely have a choice.

That matters.

If saying no could affect your job, opportunities or how you are perceived, ticking a consent box does not automatically make the underlying choice freely given.

But consent is not legally impossible in every employment setting.

The ICO gives examples where genuinely voluntary participation may be possible if workers have a real choice and experience no detriment for refusing or withdrawing.

So the stronger question is not:

"Did they click consent?"

It is:

"Did they genuinely have a choice?"

That is particularly important for workplace wellbeing programmes.

Something described as voluntary should actually be voluntary.

Third party software does not remove the responsibility

There is another tempting assumption.

A company buys a platform from a specialist provider.

The provider handles the technology.

Problem solved.

Data protection does not work like that.

The ICO specifically tells employers to think about data protection responsibilities when using third party applications for worker monitoring.

Exactly who is legally responsible for particular processing depends on the relationship between the organisations and what each party decides and does with the data.

The presence of a software supplier does not remove the need to answer basic questions.

What information is collected?

For what purpose?

Who can access it?

How long is it kept?

Is all of it necessary?

Can it be used for another purpose later?

Those questions should be answerable before a worker is asked to put anything personal into the system.

Privacy and secrecy are not the same thing

There is another distinction worth making.

Protecting someone's personal reflection does not mean encouraging secrecy around mental health at work.

People may sometimes benefit from telling a manager, colleague, occupational health professional or HR team what is happening.

Disclosure can make support and reasonable adjustments possible.

Recent reviews show that workplace disclosure can have both positive and negative consequences.

The useful principle is choice.

A worker choosing to share something with a manager is different from a software system sharing it by default.

Those are not equivalent forms of disclosure.

One is a decision by the individual.

The other is a property of the system.

That difference matters.

What this means for CalmStack

CalmStack starts from a simple design principle:

An organisation providing access does not automatically earn access to the individual's emotional life.

For workplace use, that means keeping different purposes separate.

The organisation can provide access to CalmStack.

The individual can use their Check ins, notes and My Pattern for their own reflection.

Those personal reflections should not quietly become a manager dashboard.

If CalmStack provides organisational information, that needs to be designed as a separate function with a clear purpose and a clear explanation of what is and is not being shared.

No hidden secondary use.

No surprise manager access.

No pretending that a private reflection tool is private while quietly turning it into employee monitoring.

This is partly about data protection.

It is also a product decision.

We think a tool designed to encourage honest reflection should give people confidence about who can see what they put into it.

Paid for by work does not mean visible to work

That is the click.

An organisation can fund a wellbeing resource without needing to inspect each person's private use of it.

Those are separate decisions.

The organisation might reasonably want to know whether a service is being used in broad terms, whether it provides value or whether a contract should continue.

That does not automatically require access to an individual's emotional notes or personal Check ins.

Sometimes the best data boundary is not finding a cleverer way to analyse personal information.

It is deciding that the organisation does not need that information in the first place.

One small thing to check

Before using any wellbeing tool provided through work, ask:

"Who can actually see what I put into this?"

If the answer is not obvious, look for it.

Can your manager see individual entries?

Can HR?

Can the software provider?

What, if anything, is reported back to the organisation?

What happens to your information if you stop using the service or leave the organisation?

You should not need a law degree to understand the basic answer.

A wellbeing tool should make its data boundaries clear before you are asked to trust it with something personal.

---

References

  1. Information Commissioner's Office. Data protection and monitoring workers. Current ICO employment guidance. Evidence review checked 3 September 2026.
  2. Information Commissioner's Office. Data protection and workers' health information. Current ICO employment guidance. Evidence review checked 3 September 2026.
  3. Information Commissioner's Office. Special category data. UK GDPR guidance and resources.
  4. Department for Science, Innovation and Technology. (2025 to 2026). Data (Use and Access) Act 2025: plans for commencement. GOV.UK.
  5. Ravid, D. M., White, J. C., Tomczak, D. L., Miles, A. F., & Behrend, T. S. (2023). A meta analysis of the effects of electronic performance monitoring on work outcomes. Personnel Psychology, 76, 5 to 40. DOI: 10.1111/peps.12514.
  6. Richard, C., Corbière, M., Fiset-Renaud, H., Caiada, M., Lamontagne, J., Diotte, F., Merlo, R., & Lecomte, T. (2026). Disclosure impact of mental health conditions in the workplace: A scoping review and a thematic analysis. Journal of Occupational Rehabilitation, 36(1), 131 to 166. DOI: 10.1007/s10926-025-10288-1.
  7. Strudwick, J., Gayed, A., Deady, M., Haffar, S., Mobbs, S., Malik, A., Akhtar, A., Braund, T., Bryant, R. A., & Harvey, S. B. (2023). Workplace mental health screening: A systematic review and meta analysis. Occupational and Environmental Medicine, 80(8), 469 to 484. DOI: 10.1136/oemed-2022-108608.

Emotional regulation Everyday moments At work CalmStack