Headspace collects health and mental wellness information about you that is considered sensitive under multiple laws, including GDPR in Europe and state consumer health data laws in the US.
ⓘ
This analysis describes what Headspace's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
ConductAtlas Analysis
Why it matters (compliance & governance perspective)
Mental health data is among the most sensitive personal information and misuse or breach of this data can have serious consequences for users' employment, insurance, and personal lives.
What you can do
⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
Delete Your Data
Email help@headspace.com to request deletion of your health data or to exercise other privacy rights. Reference the applicable law (e.g. GDPR, CCPA, or Washington MHMDA) in your request.
Cross-platform context
See how other platforms handle Sensitive Health Data Collection and similar clauses.
The collection of GDPR 'special category' health data and US state 'consumer health data' creates overlapping compliance obligations including consent requirements, data minimisation, breach notification, and consumer rights to access/deletion under GDPR, CCPA/CPRA, Washington MHMDA, …
Insight
Unlock the full institutional analysis
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Department Of Health & Human Services, Office For Civil Rights (hhs Ocr)
Enforces HIPAA Privacy and Security Rules, which protect health information held by healthcare providers, health plans, and their business associates.
Who can file: Anyone whose HIPAA rights may have been violated by a covered entity (healthcare provider, health plan, or healthcare clearinghouse)
What you need: Name of the entity, description of the violation, date of the incident, and your contact information. Must file within 180 days of the violation.
What to expect: HHS OCR investigates and may require the entity to take corrective action. Does not provide individual compensation. Serious violations can result in civil monetary penalties.
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
Frequently Asked Questions
What does Headspace's Sensitive Health Data Collection clause do?
Mental health data is among the most sensitive personal information and misuse or breach of this data can have serious consequences for users' employment, insurance, and personal lives.
Is ConductAtlas affiliated with Headspace?
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Headspace.