Beyond Garmin Connect
Who owns your training data? The law, the export, and the gap
August 2, 2026
The short answer
If you live in the EU or the UK, the law says your training data is yours, and you have an enforceable right to get a copy of it. What actually arrives is a partial copy: the raw activity files, usually your daily sleep and heart-rate numbers if you ask a human nicely, and none of the scores the platform computed about you.
That third category is the one that matters. VO2 max history, Training Status, Body Battery, Recovery, Readiness: these are the numbers you make decisions on, and no watch company exports them. A right to your data that returns everything except the part you act on leaves the cost of switching platforms almost exactly where it was.
What the law actually gives you
Three parts of the GDPR do the work here, and they do different things. Getting them mixed up is why so much writing on this subject overpromises.
Article 15, the right of access. You can ask any company processing your personal data for a copy of it, plus the purposes, the recipients, the retention period and the source. The scope is broad: anything that is personal data about you, including numbers the company generated rather than measured. What Article 15 does not give you is a format. It says a copy, and where you asked electronically, a commonly used electronic form. A PDF of screenshots can satisfy it.
Recital 63 adds a wrinkle companies lean on. It says the right of access should not adversely affect the rights of others, including trade secrets and the copyright protecting software, then says those considerations must not result in refusing you everything. The carve-out is for the model, not for the numbers the model produced about your body. That distinction is this article's whole argument, and it is written into the regulation's own reasoning.
Article 20, the right to data portability. This is the one people mean when they say "my data is mine." It gives you your data in a "structured, commonly used and machine-readable format" and the right to send it to another company without the first one obstructing you. It is also the narrower right. It applies only where processing rests on consent or a contract and is automated, and only to data you provided. Recital 68 states that it creates no obligation to build technically compatible systems, which is how you get four brands exporting four different shapes of archive.
"Provided" is doing enormous work in that sentence. The Article 29 Working Party guidance on portability, since endorsed by the European Data Protection Board, reads it to include observed data, meaning what the sensors recorded while you used the product, and to exclude derived and inferred data, meaning what a company's own analysis produces about you. Your heart rate trace is provided. Your Training Status is not.
Article 9, health data. Sleep, resting heart rate and HRV attached to an identified person are data concerning health, which the GDPR treats as a special category that may not be processed unless a specific ground applies. For a consumer wearable that ground is normally your explicit consent, and consent is one of the two triggers that switches Article 20 on. Your most sensitive layer is the one most clearly inside portability's scope, at least for the parts a sensor observed.
One number to hold onto: under Article 12(3), a company has one month to answer, extendable by two further months for complex cases, and it must tell you if it is extending. That deadline is what separates a formal request from a support ticket.
Three layers, three completely different answers
Every training platform holds your data in three layers. Marketing copy treats them as one thing. They behave nothing alike.
| Layer | What it is | In the self-service export? | Article 20 covers it? |
|---|---|---|---|
| 1. Raw activity files | FIT, GPX, TCX per workout | Yes, everywhere | Yes, clearly |
| 2. Daily physiology | Sleep, HRV, resting HR, steps, stress | Sometimes, often via a request | Yes, as observed data |
| 3. Derived scores | VO2 max history, Training Status, Body Battery, Recovery, Readiness, load curves | No | Probably not |
Layer 1 is genuinely yours. FIT is a shared format rather than a proprietary one, every major brand writes it, and the tools that parse FIT files do not care which logo is on the watch. If you export nothing else, export this.
Layer 2 is legally yours and practically awkward. It sits in the company's database as structured records, so there is no technical reason it cannot be a file. Whether it is one varies by brand, and sometimes by help page.
Layer 3 is where the argument is. Article 20 probably does not reach it, because it is the output of the company's model rather than something you provided. Article 15 probably does, because a number describing your fitness is personal data about you whoever calculated it. But Article 15 gives you a copy in some form, not a machine-readable time series, and as far as I can find nobody has pushed a wearable company on the point. The derived layer sits in the gap: covered by the weaker right, excluded from the stronger one, shipped by nobody.
What the four export guides actually found
We wrote up all four brands from their own published documentation. The pattern repeats with unusual consistency.
| Layer 1 | Layer 2 | Layer 3 | |
|---|---|---|---|
| Garmin | FIT, TCX, GPX, KML per activity; FIT files in the account archive | Sleep, stress, HRV and Body Battery as JSON in the archive | Training status history not exportable |
| Polar | TCX, CSV, FIT, GPX per session | Stated as excluded from the account archive | Stated as excluded from the account archive |
| COROS | FIT, GPX, TCX, KML per activity; FIT or TCX in bulk | Support ticket only | No documented export path |
| Suunto | FIT or GPX per workout | Customer support request | No documented export path |
Garmin comes out of this best for a narrow reason: its bulk archive actually contains the wellness JSON, so Garmin's export hands you layer 2 without a conversation. Its own documentation is equally clear that training status history does not come out.
Polar is the most honest and, in effect, the most restrictive. Its privacy FAQ states that the account export excludes data derived by Polar algorithms and includes raw or pre-processed forms instead; its support page names sleep and activity as the casualties. The Polar export guide covers the cost: Nightly Recharge, Training Load Pro, Running Index and the rest stay behind. Polar's reading of Article 20 is defensible, and saying it out loud is more than the others manage. Choosing it is still a choice.
COROS states on its own help pages that daily data such as heart rate and steps cannot currently be exported, and routes you to a support ticket instead. The COROS guide documents that, along with the awkward detail that COROS does sync resting HR, HRV and sleep to TrainingPeaks over an API. The data leaves the building. It just does not leave in a file you hold. Suunto documents no self-service bulk export at all; its EU Data Act notice points you at customer support and lists JSON, NDJSON, GPX, FIT and CSV, which our Suunto guide traces in full.
Four companies, four different products, one shared boundary. Everyone exports the measurements. Nobody exports the interpretation.
Why the derived layer is the real lock-in
Here is the thing switching platforms actually costs you, and it is not the files.
Take VO2 max. Across 42 Garmin accounts with at least 180 days of history each, we measured the estimate changing a median of 16 times per 90 days, in median steps of 0.2 points, across 14,919 observed changes. Over each athlete's full history it moved across a median range of 9.9 points, and the median year-over-year change among the 29 athletes with a full year was 2.0 points. Method and distributions are on our research page and in the VO2 max accuracy write-up. Cohort caveat, which applies to every number in this section: these are self-selected Garmin users who connected a training-analytics service, so likely fitter and more data-curious than average.
A curve assembled 0.2 points at a time over three years is not something you rebuild from a folder of FIT files, because rebuilding it would mean owning the model. Move platforms and it restarts at whatever the new model thinks of your last few runs. The same goes for Training Status, load balance, and every recovery score you might want to compare across brands. That is the switching cost, and the export button does not touch it.
Now the part that complicates the complaint, in our favour and against it at once.
We compared Garmin's Body Battery with the overnight HRV feeding it across 82 athletes and found a median within-athlete correlation of 0.674, positive for every athlete in the sample. The Body Battery explainer has the distribution. A score that tracks one of its inputs that closely is not an irreplaceable artefact. It is a rescaling of numbers that, on Garmin at least, do arrive in your archive.
We also compared Training Readiness against how efficiently athletes actually ran that day, across 5,136 paired steady runs from 39 athletes. Median correlation: 0.056. In the same pipeline, a control comparing Readiness with the previous day's training load returned a median of −0.272 across 54 athletes, which is what you would expect given that recent load is an input to the score. The measurement worked. The signal was not there. That study is written up in our Training Readiness analysis.
Put those together and you get the version I will defend. The layer that is hardest to take with you is not obviously the layer that predicts anything. It is the layer that keeps you. A company that will not export a score, while presenting it every morning as a fact about your body, is asking for trust it has not earned and cannot be audited on. If the number is sound, exporting your own history of it costs nothing in intellectual property. If exporting it feels like giving something away, that tells you what the number is for.
What to do about it
Export layer 1 now, and set a reminder. FIT, not GPX. You can always derive a smaller format later and you can never recover data that was never in the file.
Request the account archive before you need it, not the week you switch. None of the four publish a turnaround time, and Polar's download link expires two weeks after it arrives.
For layer 2, write a request, not a ticket. If a company tells you daily health data needs a support conversation, send that conversation to the published privacy address as an explicit Article 15 request, name the date range, and note the one-month deadline in Article 12(3). A support agent can tell you a feature does not exist. A data-protection request has to be answered.
For layer 3, accept that you are the archive. Nobody exports it, so if a trend line matters to you, record it yourself: a weekly row in a spreadsheet, or a screenshot on the first of the month. Crude, and the only method that survives a migration. Writing the number down by hand also makes you notice how much it wanders.
Start any new sync earlier than feels necessary. Polar's AccessLink API returns only the last 30 days of exercises, and Strava-shaped integrations elsewhere generally do not backfill. Every week you delay connecting a second tool is a week that tool will never see. That is much of why the raw file is worth more than the dashboard, and why the Garmin Connect alternatives worth using keep their own copy.
We are not neutral here, and you should know why
We ran a Garmin analytics service until it closed on 1 August 2026. It held exactly the data this article is about: activities, sleep, HRV, training history, coach conversations. Rather than keep any of it we are deleting all personal data, finishing by 31 August 2026, with the Garmin credentials deleted first on the day syncing stopped. That was the right call and also the easy one, because we were shutting down anyway. A company still operating faces a harder version of the same decision daily, which is the point. Our disclosure page covers what we stand to gain from the arguments here.
Frequently Asked Questions
Do I legally own my training data?
"Own" is not the word the GDPR uses. It gives you rights over personal data about you: access, portability, correction, erasure. That is stronger than ownership for getting a copy, and weaker for controlling what a company does with its own analysis of it.
Does GDPR force Garmin to export my Body Battery history?
Article 20 probably does not, because a derived score is not data you provided. Article 15 arguably does, because it is personal data about you, but Article 15 requires a copy rather than a machine-readable file. No watch company currently ships derived history in any export, and I am not aware of a regulator or court decision that has settled the question.
What is the difference between Article 15 and Article 20?
Article 15 is broad and format-free: everything that is personal data about you, in some readable form. Article 20 is narrow and format-specific: only data you provided, only where processing rests on consent or contract, but in a structured, machine-readable format you can move elsewhere.
Is sleep and HRV data from a watch really "health data"?
Data concerning health is a special category under Article 9, and physiological measurements tied to an identified person sit inside that definition. That is why consumer wearables ask for explicit consent rather than relying on legitimate interest.
What happens to my training data if a platform shuts down?
Whatever the company decides, unless you exported first. Movescount closed in January 2022 and took unmigrated histories with it. A shutdown is the one scenario where the archive on your own drive is the only archive with guaranteed uptime.
Can I get my data out if I am not in the EU?
Usually yes, because companies build one export flow and ship it globally. California's privacy law gives residents a right to know and to receive a copy in a portable format, and other US states have followed. What changes elsewhere is your recourse: without a portability right behind you, an unanswered request stays unanswered.
There is a test worth running before you commit years of training to any platform. Ask its support team for a CSV of one derived metric: your Body Battery for the past year, your Training Status history, your Nightly Recharge. Not the raw inputs, the score. You will almost certainly be told it is not available.
The reply is the useful part. A company that can put your sleep JSON in a ZIP but cannot produce a column of its own numbers about you is not facing a technical limit. It is telling you which layer it considers yours, and which layer it considers the reason you stay. Read that answer as data. Unlike most of what the app tells you about your recovery, it is a measurement whose methodology you can check yourself.