Privacy policy for the NHS Weight Loss Plan app
Introduction
The NHS Weight Loss Plan app is designed to help you improve your health by supporting you on your weight-loss journey.
The app provides a structured, step-by-step approach, offering weekly support and tailored advice and motivation to help you stay on track to reach your weight-loss goals.
With features like a BMI calculator, daily calorie tracking, weekly measurement and progress monitoring, the app will support and motivate you. It’s designed to help you reduce your weight in a healthy and sustainable way, focusing on building healthier habits.
The NHS Weight Loss Plan app does not require you to create an account. All your progress and data are stored locally on your device, ensuring ease of use and privacy.
Data controller
The Department of Health and Social Care is the data controller.
What personal data we collect
Technical information:
- Type of mobile device you use, and your mobile operating system (device information)
- Internet Protocol (IP) address used to connect to your device to the internet
- Analytics data used to understand how the app is used and monitor overall progress of our user base
Profile information:
The App is used without creation of a user account. When using the App, collection of the following data is optional:
- Postcode
- Height and Weight
- Age
- Sex
- Ethnic group
When using the App, you are given the option to share the following information. This is to help us understand more about pathways into the app and tailor your experience now or in the future:
- Your health motivation, for example, "I want to lose weight" or "I've been advised to lose weight"
- Other forms of weight-loss support you are currently using other than this app, for example, GP referrals, paid for apps or an online programme
- Your current activity level, for example, less than 30 minutes per week, 30 to 149 minutes per week, over 150 minutes per week
How we use your data (purposes)
Height, Weight, Age, Sex and Ethnic group are used to calculate and personalise your BMI score and classification and tailor your targets.
Legal basis for processing personal data
Under the General Data Protection Regulation (GDPR), the lawful bases we rely on for processing this information are:
- Your consent (for any information that is voluntarily provided by you)
- For the performance of a task in the public interest or for our official functions (for all other data)
As we are also processing special category data (such as information related to your health), we are also required to identify at least one additional condition under which to process this information. These are:
- Your consent (for any information that is voluntarily provided by you)
- For reasons of public interest in the area of public health (for all other data)
Data processors and other recipients of personal data
Data collected by the app is not passed on to any third parties.
International data transfers and storage location(s)
Collected data is stored and processed in the United Kingdom.
Retention and disposal policy
No data is stored in identifiable format. Your activity data is stored anonymously and indefinitely in order to monitor performance of the application and provide population level insights into the effectiveness of the service.
How we keep your data secure
Height, Weight, Age, Sex and Ethnic group data will be used alongside weight measurement progress data to produce insights on the usage of the product at a population level, but this will not be attributable to you.
No personal identifiable data is stored. Anonymised app activity data is encrypted at rest and in transit and is used to produce insights on the usage of the product at a population level.
Your rights as a data subject
By law, data subjects have a number of rights and this processing does not take away or reduce these rights under the EU General Data Protection Regulation (2016/679) and the UK Data Protection Act 2018 applies.
These rights are:
- The right to get copies of information – you have the right to ask for a copy of any information about you that is used.
- The right to get information corrected – you have the right to ask for any information held about you that you think is inaccurate, to be corrected.
- The right to limit how the information is used – you have the right to ask for any of the information held about you to be restricted, for example, if you think inaccurate information is being used.
- The right to object to the information being used – you can ask for any information held about you to not be used. However, this is not an absolute right, and continued use of the information may be necessary, with you being advised if this is the case.
- The right to get information deleted – this is not an absolute right, and continued use of the information may be necessary, with you being advised if this is the case.
Automated decision making or profiling
No decision will be made about you solely based on automated decision making (where a decision is taken about you using an electronic system without human involvement) which has a significant impact on you.
Changes to this policy
This privacy notice is kept under regular review, and new versions will be available on our privacy notice page on our website. This privacy notice was last updated on 07/03/2025.
© Crown copyright 2022
Information Risk Management & Assurance/Office of the Data Protection Officer www.gov.uk/dhsc
This publication is licensed under the terms of the Open Government Licence v3.0 except where otherwise stated. To view this licence, visit nationalarchives.gov.uk/doc/open-government-licence/version/3
Where we have identified any third-party copyright information you will need to obtain permission from the copyright holders concerned.
Page last reviewed: 15 May 2025
Next review due: 15 May 2026
Comments or complaints
If you are unhappy or wish to complain about how personal data is used as part of this programme, you should email data_protection@dhsc.gov.uk in the first instance or write to:
Data Protection Officer
1st Floor North
39 Victoria Street
London
SW1H 0EU
If you are not satisfied with the response, you can complain to the Information Commissioner's Office. Their website address is www.ico.org.uk and their postal address is:
Information Commissioner's Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF