The privacy-first wellness benefit buyer's checklist
Fourteen questions to ask any vendor before you buy a wellness benefit for a team — and a scorecard to compare two of them side by side.
Most workplace wellness programmes are bought on a demo and judged on a dashboard. Two of the largest randomised trials of them — at 12 and 18 months — found little to no effect on clinical or economic outcomes. So the questions that decide whether a benefit is worth buying are not about features — they are about who can see what, what 'active' actually counts, and what happens to the data when the contract ends.
This is the list we would want a buyer to bring to our own demo. Bring it to every vendor's, get the answers in writing, and score them side by side.
Privacy: structure, not policy
Health data is a special category of personal data under Article 9 of the GDPR. An employer that can see it is the risk, not the benefit — so every answer here should describe what the system makes impossible, not what a policy forbids.[4]
Can any admin, ever, see an individual employee's entries or metrics? The only acceptable answer is 'structurally impossible' — not 'we have a policy', not 'only with permission'.
What is the minimum group size below which aggregates are hidden — and are the figures rounded or perturbed so a small team cannot be reverse-engineered?
Who owns the account and the data: the company or the employee? What happens to an employee's history when they leave, or when you cancel?
Where is the data stored and processed, and who are the sub-processors? Is there advertising technology or data sale anywhere in the model?
If there is AI: is it consent-based per employee, revocable at any time, and never trained on your people's data?
Can an employee export everything and delete their account themselves, without going through HR?
Engagement and evidence
A dashboard can show anything. Ask what the number is made of.
How often is engagement reported, at what granularity, and can the vendor show a sample report with the minimum-group threshold actually applied?
Where does the content come from? Is advice cited to research, are experts verified, and is there a visible line between evidence and opinion?
What does it replace or duplicate — EAP, insurer apps, fitness stipends? Only a minority of employees typically take part in a workplace wellness intervention; a benefit that duplicates three others starts lower still.[3]
Commercial terms
The price on the slide is rarely the price on the invoice.
What is the all-in price per seat per month — and what costs extra: onboarding, support, reporting, AI features?
What is the seat minimum, and how are seats added or reduced mid-term?
What are the cancellation terms, and what is returned or deleted on exit — for the company and for each employee?
Can you run a pilot with a small team first, and does the pilot pricing carry over?
How to use it
- 1
Send the six privacy questions to every vendor in writing before the demo. Written answers are what your data-protection officer can act on.
- 2
Score two vendors side by side on the eight criteria. A 'policy' answer where a 'structural' one was needed is a no, not a maybe.
- 3
Ask for a sample engagement report with the minimum-group threshold applied to a team of five.
- 4
Lamplit for Business is built to answer every question here in writing — €5 per seat per month billed annually, from 10 seats, aggregate-only reporting hidden below five active members, employee-owned accounts, EU hosting — and to be scored on the same sheet as everyone else.
Want the printable version?
The PDF fits on one sheet and adds a scorecard for comparing two vendors on the eight criteria that decide it. Tell us where to send it — we follow up once, by email.
Common questions
Why is a vendor's own checklist worth anything?
Because every question here has a verifiable answer — written, in a contract or a data-processing agreement — and the scorecard works against us as much as for us. If another vendor's structure beats ours on a row, this sheet is how you would see it.
What if a vendor says its reporting is 'anonymised'?
Ask for the threshold. Anonymised without a minimum group size is a word, not a guarantee: a team of three with one active member is not anonymous.
Do we need a data-protection impact assessment?
Very likely, if the benefit processes health data about your employees. Health data is a special category under the GDPR, and the questions in the privacy section are the ones an assessment will ask you anyway.
Sources
Where an item rests on a specific source, the number in brackets points to it. Every source is linked.
- 1.Song, Z. & Baicker, K. (2019). Effect of a workplace wellness program on employee health and economic outcomes: a randomized clinical trial. JAMA, 321(15), 1491–1501. Read the paper ↗
- 2.Jones, D., Molitor, D. & Reif, J. (2019). What do workplace wellness programs do? Evidence from the Illinois Workplace Wellness Study. The Quarterly Journal of Economics, 134(4), 1747–1791. Read the paper ↗
- 3.Mattke, S. et al. (2013). Workplace Wellness Programs Study: Final Report. RAND Corporation, RR-254. Read the paper ↗
- 4.Regulation (EU) 2016/679 (General Data Protection Regulation), Article 9 — Processing of special categories of personal data. Read the paper ↗
Last reviewed: August 24, 2026
This checklist is general procurement guidance, not legal advice. GDPR obligations depend on your role as controller or processor and on local law; have your data-protection officer or counsel review any wellness-benefit contract.