Skip to main content
Buyer's checklist — online version

The privacy-first wellness benefit buyer's checklist

Fourteen questions to ask any vendor before you buy a wellness benefit for a team — and a scorecard to compare two of them side by side.

Most workplace wellness programmes are bought on a demo and judged on a dashboard. Two of the largest randomised trials of them — at 12 and 18 months — found little to no effect on clinical or economic outcomes. So the questions that decide whether a benefit is worth buying are not about features — they are about who can see what, what 'active' actually counts, and what happens to the data when the contract ends.

This is the list we would want a buyer to bring to our own demo. Bring it to every vendor's, get the answers in writing, and score them side by side.

Privacy: structure, not policy

Health data is a special category of personal data under Article 9 of the GDPR. An employer that can see it is the risk, not the benefit — so every answer here should describe what the system makes impossible, not what a policy forbids.[4]

  • Can any admin, ever, see an individual employee's entries or metrics? The only acceptable answer is 'structurally impossible' — not 'we have a policy', not 'only with permission'.

  • What is the minimum group size below which aggregates are hidden — and are the figures rounded or perturbed so a small team cannot be reverse-engineered?

  • Who owns the account and the data: the company or the employee? What happens to an employee's history when they leave, or when you cancel?

  • Where is the data stored and processed, and who are the sub-processors? Is there advertising technology or data sale anywhere in the model?

  • If there is AI: is it consent-based per employee, revocable at any time, and never trained on your people's data?

  • Can an employee export everything and delete their account themselves, without going through HR?

Engagement and evidence

A dashboard can show anything. Ask what the number is made of.

  • What does 'active' mean in the reporting — an app open, or a real logged entry? The best-run trials measured clinical and economic outcomes, not participation — and in the one that measured both, self-reported behaviour improved while clinical and spending outcomes did not.[1][2]

  • How often is engagement reported, at what granularity, and can the vendor show a sample report with the minimum-group threshold actually applied?

  • Where does the content come from? Is advice cited to research, are experts verified, and is there a visible line between evidence and opinion?

  • What does it replace or duplicate — EAP, insurer apps, fitness stipends? Only a minority of employees typically take part in a workplace wellness intervention; a benefit that duplicates three others starts lower still.[3]

Commercial terms

The price on the slide is rarely the price on the invoice.

  • What is the all-in price per seat per month — and what costs extra: onboarding, support, reporting, AI features?

  • What is the seat minimum, and how are seats added or reduced mid-term?

  • What are the cancellation terms, and what is returned or deleted on exit — for the company and for each employee?

  • Can you run a pilot with a small team first, and does the pilot pricing carry over?

How to use it

  1. 1

    Send the six privacy questions to every vendor in writing before the demo. Written answers are what your data-protection officer can act on.

  2. 2

    Score two vendors side by side on the eight criteria. A 'policy' answer where a 'structural' one was needed is a no, not a maybe.

  3. 3

    Ask for a sample engagement report with the minimum-group threshold applied to a team of five.

  4. 4

    Lamplit for Business is built to answer every question here in writing — €5 per seat per month billed annually, from 10 seats, aggregate-only reporting hidden below five active members, employee-owned accounts, EU hosting — and to be scored on the same sheet as everyone else.

Want the printable version?

The PDF fits on one sheet and adds a scorecard for comparing two vendors on the eight criteria that decide it. Tell us where to send it — we follow up once, by email.

Common questions

Why is a vendor's own checklist worth anything?

Because every question here has a verifiable answer — written, in a contract or a data-processing agreement — and the scorecard works against us as much as for us. If another vendor's structure beats ours on a row, this sheet is how you would see it.

What if a vendor says its reporting is 'anonymised'?

Ask for the threshold. Anonymised without a minimum group size is a word, not a guarantee: a team of three with one active member is not anonymous.

Do we need a data-protection impact assessment?

Very likely, if the benefit processes health data about your employees. Health data is a special category under the GDPR, and the questions in the privacy section are the ones an assessment will ask you anyway.

Sources

Where an item rests on a specific source, the number in brackets points to it. Every source is linked.

  1. 1.Song, Z. & Baicker, K. (2019). Effect of a workplace wellness program on employee health and economic outcomes: a randomized clinical trial. JAMA, 321(15), 1491–1501. Read the paper ↗
  2. 2.Jones, D., Molitor, D. & Reif, J. (2019). What do workplace wellness programs do? Evidence from the Illinois Workplace Wellness Study. The Quarterly Journal of Economics, 134(4), 1747–1791. Read the paper ↗
  3. 3.Mattke, S. et al. (2013). Workplace Wellness Programs Study: Final Report. RAND Corporation, RR-254. Read the paper ↗
  4. 4.Regulation (EU) 2016/679 (General Data Protection Regulation), Article 9 — Processing of special categories of personal data. Read the paper ↗

Last reviewed: August 24, 2026

This checklist is general procurement guidance, not legal advice. GDPR obligations depend on your role as controller or processor and on local law; have your data-protection officer or counsel review any wellness-benefit contract.

← About Lamplit for Business