Headspace · Headspace Privacy Policy · View original document ↗

User Privacy Rights and Data Subject Requests

Medium severity High confidence Explicitdocumentlanguage Unique · 0 of 325 platforms
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Headspace recorded 2 documented changes in the last 30 days.
Start monitoring updates
Monitor governance changes for Headspace Create a free account to receive the weekly governance digest and monitor one platform for governance changes.
Create free account No credit card required.
Document Record

What it is

Depending on where you live, you may have rights to access, correct, delete, or export your personal data, and you can exercise those rights by submitting a request through Headspace's online form or by emailing their support address.

This analysis describes what Headspace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

These rights are particularly meaningful on a mental health platform because they allow users to review what sensitive data Headspace holds about them, request corrections to health information, or ask for complete deletion of their mental health records from the platform.

Consumer impact (what this means for users)

Users in the EU, UK, California, and certain other jurisdictions have enforceable rights to access, correct, delete, or port their personal data including mental health information, and can exercise these rights through Headspace's online privacy request form or by emailing help@headspace.com; the availability and scope of these rights depends on your jurisdiction.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Email help@headspace.com with your deletion or data access request, specifying the categories of personal data you want deleted or accessed; alternatively, use the privacy rights request form linked in the Headspace privacy policy.
  • Export Your Data
    Use the privacy rights request form linked in the Headspace privacy policy to submit a data portability request and receive a copy of your personal information.

How other platforms handle this

Runway Medium

In addition to the above rights, your local laws (including those in the EU, UK, Japan, California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Virginia, or Utah) may afford you f...

ADP Medium

If you are a California resident, you may have certain rights under the California Consumer Privacy Act (CCPA). These rights may include: the right to know about personal information collected, disclosed, or sold; the right to delete personal information collected from you; the right to opt-out of t...

TransUnion Medium

Depending on where you live, you may have certain rights with respect to your personal information. These rights may include: The right to know what personal information we have collected about you, including the categories of personal information, the categories of sources from which we collected i...

See all platforms with this clause type →

Monitoring

Headspace has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
Depending on where you live, you may have certain rights regarding your personal information. These may include the right to access, correct, or delete your personal information; the right to restrict or object to our processing of your personal information; the right to data portability; and the right to withdraw consent where processing is based on consent. To exercise your rights, please visit our privacy rights request form or contact us at help@headspace.com.

— Excerpt from Headspace's Headspace Privacy Policy

ConductAtlas Analysis

Institutional analysis (Compliance & governance intelligence)

REGULATORY LANDSCAPE: Data subject rights disclosures engage GDPR Articles 15 through 22 (access, rectification, erasure, restriction, portability, objection, and automated decision-making rights) for EU and UK users; CCPA and CPRA data subject rights for California residents (access, deletion, correction, portability, opt-out of sale and sharing); and similar rights frameworks in Canada under PIPEDA and in other jurisdictions with supplemental notices. For HIPAA-covered clinical data, patients have separate rights under the HIPAA Privacy Rule including the right to access, amend, and receive an accounting of disclosures. GOVERNANCE EXPOSURE: Medium. The policy commits to honoring data subject rights across multiple jurisdictions but does not specify response timeframes or verification processes in the main policy text, which may create operational compliance gaps particularly under GDPR's 30-day response requirement and CCPA's 45-day response timeline. The existence of both HIPAA and GDPR rights frameworks for the same user in certain circumstances creates potential procedural complexity. JURISDICTION FLAGS: EU and UK users have the most robust enforceable rights under GDPR and UK GDPR, including the right to erasure and data portability. California residents have CCPA and CPRA rights with specific verification and response timelines. Canadian users have PIPEDA rights. Users in jurisdictions without specific data protection legislation have no guaranteed rights under this policy beyond what the company voluntarily provides. CONTRACT AND VENDOR IMPLICATIONS: Honoring deletion requests for mental health data requires that Headspace's data processing agreements with third-party vendors include data deletion and return obligations. If advertising or analytics vendors retain copies of user data, those copies must also be subject to deletion upon valid user request. COMPLIANCE CONSIDERATIONS: Compliance teams should verify that the privacy request intake process has defined response timelines mapped to each applicable jurisdiction, that identity verification procedures are proportionate and not overly burdensome, and that deletion requests cascade to third-party processors and vendors. For HIPAA-covered clinical data, the right of access and amendment process should be tested for consistency with the HIPAA Privacy Rule's specific requirements.

Full compliance analysis

Regulatory citations, enforcement risk, and due diligence action items.

Track 1 platform — free Try Watcher free for 14 days

Free: track 1 platform + weekly digest. Watcher: 10 platforms + same-day alerts. No credit card required.

Applicable agencies

  • FTC
    The FTC has jurisdiction over failure to honor privacy rights commitments made in privacy policies as an unfair or deceptive practice under Section 5 of the FTC Act
    File a complaint →
  • State AG
    State attorneys general enforce CCPA and CPRA data subject rights for California residents, and similar rights frameworks in other states with comprehensive privacy laws
    File a complaint →

Applicable regulations

CCPA/CPRA
California, USA
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
FTC Act Section 5
United States Federal
GDPR
European Union
HIPAA
United States Federal
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Headspace Privacy Policy
Entity
Headspace
Document last updated
May 5, 2026
Tracking information
First tracked
May 8, 2026
Last verified
May 10, 2026
Record ID
CA-P-009700
Document ID
CA-D-00216
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
c1c69938a2255531d9160216a80441cc6e236ee7a78005f747b818b71812b907
Analysis generated
May 8, 2026 10:00 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Headspace
Document: Headspace Privacy Policy
Record ID: CA-P-009700
Captured: 2026-05-08 10:00:58 UTC
SHA-256: c1c69938a2255531…
URL: https://conductatlas.com/platform/headspace/headspace-privacy-policy/user-privacy-rights-and-data-subject-requests/
Accessed: May 13, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
Medium
Categories

Other risks in this policy

Professional Governance Intelligence

Need to monitor specific governance provisions?

Professional includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Start Professional free trial

Or start with Watcher →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Headspace's User Privacy Rights and Data Subject Requests clause do?

These rights are particularly meaningful on a mental health platform because they allow users to review what sensitive data Headspace holds about them, request corrections to health information, or ask for complete deletion of their mental health records from the platform.

How does this clause affect you?

Users in the EU, UK, California, and certain other jurisdictions have enforceable rights to access, correct, delete, or port their personal data including mental health information, and can exercise these rights through Headspace's online privacy request form or by emailing help@headspace.com; the availability and scope of these rights depends on your jurisdiction.

Is ConductAtlas affiliated with Headspace?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Headspace.