Who run the world? Girls.
Shall we tell you what we want, what we really really want?
For tech companies to use their powers for good (creating and offering genuinely useful femtech propositions and addressing gaps in health care on the basis of gender) rather than for bad (using tech to prey on insecurities by marketing tools that encourage us to set unachievable physical goals or, particularly in respect of fertility apps and products, imply these are exclusively matters for women; there is no ‘maletech’).
What is femtech?
As Ruth Bader Ginsburg said, “real change, enduring change, happens one step at a time,” the world of femtech – short for ‘feminine technology’ – has come on in leaps and bounds in recent years.
From wearable tech and mobile apps to interconnected medical devices, these technologies are specifically designed to cater to women’s health concerns and awareness across various life stages. They often leverage advancements in areas like data analytics, artificial intelligence and wearable sensors to provide personalised insights and support for women’s health-related issues.
Without even realising it, women are likely to have engaged with one or more forms of femtech products, covering a wide range of tech-based consumer facing offerings.
Take your smart phone, for example. At the end of 2023, according to figures from Statista, it was estimated that just under 50% of adults in the UK had an Apple iPhone.
The default ‘Health’ app installed on iPhones has functionalities to assist you in not just tracking your steps taken, distance travelled, heart rate, sleep patterns, medications taken (i.e. general data capture which is not gender specific), but also to track menstrual cycles, linking that to information about emotions and moods.
While there are certain core areas on which femtech often focuses, the sub-sector is broader than that. To name but a few, there are technologies on the market that help monitor and manage menopausal symptoms, pelvic floor exercise trainers, wireless electric breast pumps, mood trackers, fertility prediction apps and breastfeeding support apps. The list goes on.
Why data protection matters
Writing this as a female lawyer with a penchant for data protection compliance, I’m not planning to simply witter on about all the exciting stuff that’s out there that could help us.
I am also going to give a friendly word of warning about some of the things an aspiring femtech firm needs to think about if wanting to avoid handbags at dawn with the UK Information Commissioner’s Office (ICO).
FemTech firms handle large volumes of personal data, including special category personal data, and therefore need to comply with certain principles that are designed to safeguard individuals’ privacy and ensure responsible handling of such data.
Those principles are baked into the Data Protection Act 2018 and the UK General Data Protection Regulation (UK GDPR).
Against that backdrop, and in the wake of International Women’s Day 2024, here are 10 points on data protection for FemTech firms to consider:
1. Build compliance into your product or service – the regulator calls it ‘Privacy by Design’. Privacy considerations need to be factored into your plans right from day one of your business journey. If treated as an after-thought, the risk of non-compliance is likely to be significantly higher.
2. Identify appropriate lawful bases for processing. While consent may not always be the most appropriate basis to rely on, where sensitive personal (eg. health/medical) data is involved, it is likely to play an important role. Stringent consent mechanisms should be implemented where special category data is involved. Consent should be freely given, specific, informed, and unambiguous. Users also need to be able to easily withdraw their consent.
3. Implement robust security measures to protect all personal data, particularly as you will often be dealing with sensitive health-related data. Using encryption and embedding access controls, conducting regular security assessments, and mandating regular employee training on data protection practices should become second nature to you.
4. Get to grips with the concepts of pseudonymisation and anonymisation, as using these practices (where possible) can play an important role in keeping data secure, thereby reducing your risk.
5. Only collect data that is necessary for the intended purpose. There is no such thing as ‘nice to have’ personal data – it creates unnecessary risk. Do not collect excessive or irrelevant data about users’ health or personal lives.
6. If using third-party service providers to process personal data, appropriate data processingagreements need to be in place to remain compliant with the law as well as helping to manage those suppliers.
7. If transferring data outside the UK or the European Economic Area (EEA), appropriate safeguards must be in place, often in the form of an International Data Transfer Agreement or Standard Contractual Clauses.
8. Respect individuals rights, including their right to access their data, rectify inaccuracies, erase data (in certain circumstances), and object to processing. Make sure you have robust policies in place for responding to any such requests and that staff know how to recognise and action such a request.
9. Have procedures in place to swiftly detect, respond to, and report data breaches in a timely manner. Don’t just develop policies and procedures then file them away – ensure staff are familiar with what’s required in such a situation, so they are able to hit the ground running if something happens.
Under UK GDPR, companies must notify the ICO about certain types of data breaches without delay and may also need to inform affected individuals.
10. Provide clear and transparent information to individuals about how their data is collected, processed, and shared. This should be communicated through easily accessible privacy policies and terms of service.
The rise of the femtech sector reflects a growing recognition of the unique healthcare needs and experiences of women, as well as a desire to overcome historical gaps and disparities in healthcare services and research. FemTech innovations aim to empower women to take control of their health, make informed decisions, and access appropriate care more conveniently.
Recommended reading
- ICO Launches Public Survey Amid Care Data Access Concerns
- Hardware femtech firm partners with NHS to deliver free smart devices
- UK Gov seeks views on medical device inequality
However, with great power comes great responsibility, so successful firms in this sector need to balance a compelling product offering with the rights and freedoms (or ‘privacy’, to use less legalistic terms) of their users.
Separate to the matter of complying with data protection regulation, the perceived ‘danger’ of sharing data on fertility and period apps was put into focus from an American perspective following the US Supreme Court decision overturning Roe vs Wade. These solutions deal with particularly sensitive personal data; customer confidence and control over what actually happens to their data is key from a brand perspective.
Perhaps the femtech sector can play a small part in one day enabling us to say: “We fixed everything in the real world, so all women are happy and powerful.”





