Work-Out

Strava, Polarsteps and the military data security problem

Strava, Polarsteps and the military data security problem

Within a matter of weeks, two consumer applications have put the same Defence problem back in the spotlight.

In September 2026, Follow the Money reported that military personnel from several NATO countries could be identified and followed through data accessible via the travel app Polarsteps. The Dutch Ministry of Defence subsequently placed the application on its deny-list for service devices. Polarsteps disputes that private trip data was breached and states that no authentication was bypassed. 

Then, on 24 September, reporting based on an investigation by De Morgen found thousands of profiles linked to sporting activity recorded at six sensitive Belgian Defence and NATO locations since 2014. Among the profiles examined, many were public and could expose information such as names, profile details and activities around military sites.

THIS IS NOT A STRAVA PROBLEM

Strava is designed for athletes to record, analyse and share their activities. That is the defenition of collecting and sharing data.

Its current privacy policy explicitly describes sharing activity data including date, time, distance, speed, power, cadence, perceived exertion, geolocation and (where provided) health information such as heart rate. Depending on privacy settings, profile information and activities can also be visible to other users or the public. None of that is particularly surprising for a consumer fitness platform.

The problem arises when the person generating that information works in a Defence environment. A route is no longer ‘just a running path’. A start location may correspond with a military facility. A repeated training pattern may indicate where somebody works. A collection of activities can reveal routines. Combine those data with a name, role, unit, other social-media information or additional sources, and seemingly ordinary fitness information can take on an entirely different significance.

Illustrative aerial view of a military base with an orange GPS running route showing how fitness tracking can reveal sensitive location and movement data.

 

The issue is therefore not that military personnel train or use platforms to gain insights; the issue is whether Defence understands and controls where the resulting data goes.

Military Data Security & Human Performance Data | Work-Out

A digtial trail

For a long time, sensitive military data was primarily associated with obvious operational systems: intelligence, communications, weapons, vehicles or command-and-control. That boundary is becoming much less clear. Modern military personnel increasingly generate data through:

  • sports watches and wearables;
  • smartphones;
  • fitness and health applications;
  • GPS-enabled devices;
  • connected training equipment;
  • medical and performance systems;
  • sensors and smart textiles;
  • testing and assessment tools.

A single data point may reveal very little, but when those datapoints are connected, there is enormous value, and big risks.  What if that data comes into the wrong hand? what if the ‘enemy’ know exactly where to find individuals and groups, and knows exactliy their weaknesses? 

A single data point may reveal very little, but once those data points are connected, their value increases, and so does the risk. What if that information ends up in the wrong hands? What if an ‘enemy’ can identify where individuals or groups are active, recognises recurring patterns or knows their biggest vulnerabilities? This is the paradox of Human Performance data.

What creates value, is also a risk

The more complete the Human Performance picture becomes, the more important it becomes to control who can access it, where it is processed and what it can be combined with. And that is exactly the challenge.

The better Defence understands the individual, the better it can support performance, readiness, recovery and long-term health. But that also means creating an increasingly detailed and sensitive picture of that individual.

Human Performance capability therefore needs to grow together with data awareness and data control. Personnel need to understand what their devices and applications collect. Defence organisations needs to understand where that information flows. And the systems behind Human Performance need to ensure that this data does not leave the organisation’s control.

At Work-Out, we are glad to see this discussion gaining momentum. Because these are not questions that should be answered after a Human Performance system has been deployed. They need to be answered by design.

That is why The Work-Out Human Performance Platform is built around controlled data flows, role-based access, data ownership and the ability for Defence to determine where and how Human Performance data is processed.

Conclusion

Strava and Polarsteps are not the issue. They are examples of a much broader shift: military personnel generate more data than ever before, and Human Performance will only make that picture richer. That creates value, but also big responsibilities.

Defence organisations need to know where data flows, who can access it and under which conditions it can be used.

For The Work-Out, that principle is our biggest fundament.

Sources

Build secure human performance capability?

Discover how Work-Out connects readiness, training, medical, testing and cognitive information in one secure environment.

Scroll to Top

Discover more from Work-Out

Subscribe now to keep reading and get access to the full archive.

Continue reading