A fitness tracker collects biometric data — heart rate, SpO2, movement patterns, sleep. This data is processed locally and transmitted to a companion app via Bluetooth. Annex I Part I point 1(c) requires protection of confidentiality of data. Annex III point 19 classifies health-monitoring wearables as Important Class I. If harmonised standards are not fully applied, conformity assessment by a notified body is required under Article 32.2. CRACheck generates 8 PDF documents per Annex VII. 15-25 minutes. €149. Browser-side.
€149 one-time · 8-document ZIP · 15–25 minutes · Browser-side
You enter your product data. CRACheck structures the documentation per Article 31 + Annex VII.
Correct — your tracker is not a medical device. But that is precisely why it falls under CRA Annex III point 19: "personal wearable products with a health monitoring purpose to which Regulation (EU) 2017/745 does not apply." Being excluded from medical device regulation puts you inside CRA Class I.
Annex I Part I point 1(c) requires protection of confidentiality of stored, transmitted and processed data without distinction by data type. Heart rate patterns, sleep data and SpO2 readings are personal health data under GDPR and must be protected from unauthorized access under CRA.
Article 13.5 requires due diligence on third-party components. The health sensor chip generates the biometric data, but your firmware processes, stores and transmits it. The security of the data pipeline is your responsibility.
8 PDF documents generated from your data. Each cites the specific article of Regulation (EU) 2024/2847 it complies with.
Class I confirmation per Annex III point 19. Biometric data raises the classification.
Art. 31 + Annex VII. Covers BLE connectivity, companion app data flow, biometric sensor integration.
Art. 13.2-13.3. Biometric data interception, unauthorized access to health records, firmware tampering.
Annex II. Data privacy, pairing security, factory reset.
Art. 28 + Annex V.
Vulnerability disclosure for biometric data vulnerabilities.
Art. 14 ENISA notification. Art. 14(2): early warning within 24h, notification within 72h, final report within 14 days.
CRA dates plus support period for the tracker.
See before you buy — Download sample dossier (PDF, fictional company) — Real structure, real articles, real format. Fictional data.
Generated from your data, in your browser. No data leaves your device.
Generates Annex VII documentation for your fitness tracker. Covers biometric sensors, BLE data transmission, companion app integration, cloud connectivity, data protection.
CRACheck does not perform GDPR compliance assessment, biometric data protection impact assessment or companion app security testing. CRA covers cybersecurity; GDPR covers data protection. Both apply to your tracker. CRACheck handles the CRA documentation.
We document cybersecurity. You handle GDPR separately.
Article 64 of Regulation (EU) 2024/2847.
Art. 64.2.
Art. 64.3.
Art. 64.4.
| Criterion | Wearable certification consultancy | Classify as Default and self-assess | GDPR compliance only | CRACheck |
|---|---|---|---|---|
| Cost | €8,000–€15,000 | €0 | Variable | €149 |
| Result | Class I docs + assessment. 3-5 months. | Incorrect for health-monitoring wearables. Annex III point 19 = Class I. | GDPR covers data protection. CRA covers cybersecurity. You need both. | 8 docs. 15 min. Class I documentation. Biometric data covered. |
Each model with different sensors, firmware or connectivity needs its own dossier. Fitness band, GPS watch, kids tracker — three products, three dossiers. Volume pricing: €99/product (10-pack), €79/product (30-pack).
Request Volume PricingCRACheck generates a structured document according to Article 31 and Annex VII of Regulation (EU) 2024/2847 from the information you provide. The accuracy, completeness and truthfulness of that information is your responsibility as the manufacturer.
We guarantee that the document structure follows Article 31 and Annex VII of Regulation (EU) 2024/2847 and that the legal references cited are correct. We do not guarantee that a specific document will be accepted by a market surveillance authority in a specific case or by a commercial buyer in a procurement process.
CRACheck is not legal advice. For specific situations, consult a lawyer or specialised regulatory consultancy.
Eight documents. Article 31 + Annex VII fully structured. Regulation (EU) 2024/2847. Your data stays on your device. The ZIP you download is yours forever.