A Warning, Not a Case
On August 4, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, or AP) published a public warning to menstruation and cycle-tracking apps, saying their handling of users' health data raises "serious concerns" and that it "does not rule out starting an investigation." Vice-chair Monique Verdier framed the stakes bluntly: "Girls and women record very intimate information in these apps. That makes them vulnerable" — especially, she added, when that data reaches advertisers unintentionally or falls into the hands of hackers who target sensitive personal data for extortion.
The warning is notable less for what it announces than for what it withholds. The AP has not opened a formal investigation, named a target app, or issued a fine. It has published a compliance checklist and left the threat of enforcement open.
The Case For Scrutiny
The AP's concern is well-founded on the facts. Cycle and fertility data is about as sensitive as personal data gets — it can reveal sexual activity, pregnancy attempts, miscarriages, and health conditions, all of which fall under Article 9 of the GDPR's "special category" data, subject to a general processing ban unless a specific legal exemption applies. Nearly a quarter of Dutch women use a cycle or fertility app, according to figures cited in the AP's warning, meaning any systemic mishandling scales to hundreds of thousands of people at once (Emerce). Free apps monetized through advertising create a structural incentive to share exactly the data users most want kept private, and a UK Information Commissioner's Office-linked study found some period-tracking titles had between 10 million and 100 million downloads on Google Play — evidence the exposure isn't hypothetical or confined to obscure apps (ppc.land). This is precisely the kind of asymmetric-information, high-sensitivity market where a regulator's job is to look closely before harm compounds.
The warning also didn't come from nowhere. In May 2026, Dutch digital-rights group Bits of Freedom filed a GDPR complaint with the AP against the app Flo, launching a public campaign — "Blijf uit mijn digitale onderbroek" ("Stay out of my digital underwear") on May 28 — alleging the app collects data on sex, cramps, and pregnancy intentions from an estimated 1.3 million Dutch cycle-app users without adequate transparency or properly timed consent (Bits of Freedom). The AP's August warning reads as a direct response to that complaint, not a freestanding initiative.
Why the AP Is Right to Stop Short of a Probe
Having steelmanned the concern, the AP's own choice of instrument here deserves credit rather than criticism — and that's the part worth defending. The three obligations the regulator laid out are not new rules: providers must show a valid legal basis for processing special category data, tell users plainly what happens to their data before they hand it over, and maintain adequate technical security. All three have applied under the GDPR since 2018 and under the Netherlands' implementing statute, the Uitvoeringswet AVG, which gives the AP fining authority up to €20 million or 4% of global annual turnover (UAVG, wetten.overheid.nl). A public reminder that existing law applies to a specific product category is a proportionate, low-cost regulatory tool — it doesn't create new compliance burdens, doesn't chill product development with novel uncertainty, and gives good-faith operators a clear, achievable bar to clear before any enforcement action follows.
That restraint matters because the alternative — treating a warning as equivalent to a finding of wrongdoing, or rushing to legislate a menstrual-app-specific rule — would punish an entire category for the practices of whichever operators turn out to be non-compliant. Cycle-tracking apps also deliver real value: for the substantial share of users managing fertility, contraception, or documented health conditions, features like symptom logging and predictive cycle modeling are genuinely useful, and many providers already operate within GDPR bounds with strict data minimization and no ad-based monetization. A blanket regulatory chill would penalize those providers alongside any bad actors.
What Comes Next
The AP now faces a choice about sequencing. If the Flo complaint from Bits of Freedom develops into an investigation, that inquiry — targeted at a specific company's specific practices — is the correct next step, not a rulemaking exercise aimed at the whole product category. Enforcement against demonstrated violations (murky consent flows, undisclosed ad-sharing, inadequate breach protections) sends a clearer signal to the market than a generalized warning ever could, while leaving compliant operators undisturbed.
The AP deserves credit for choosing disclosure over drama: it flagged a real risk, cited the specific legal duties already in force, and left the investigative option in reserve rather than triggering it preemptively. The test of whether this approach works will be whether an actual investigation — grounded in evidence against a named app, not a sector-wide sweep — follows if the underlying complaint holds up.