A recent Electronic Frontier Foundation (EFF) article reports that companies that make wearable trackers, whether for fitness or health, “are behind the times when it comes to basic privacy practices and transparency” and urges those companies to “improve those practices.”

The article, Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features, states that up to 40% of individuals in the U.S. own a wearable health device. These devices are not subject to health-related privacy protections, such as HIPAA. They can, and do, collect vast amounts of data while being worn, and the companies share that data with third parties or useit to train AI models. When users activate the device, its privacy policy outlines what information it collects, how it is used and disclosed, and who it is shared with. The user is asked to click “I agree” to the privacy policy, and unfortunately, most people don’t read it before they agree. This allows the device to collect, use, and share your data broadly, including with law enforcement.

EFF staff analyzed ten different companies that market consumer health products and found that most of them did not provide transparency reports, which provide information to consumers about how often they provide data to the government in an official or unofficial manner. Only Apple and Google publish transparency reports, and Apple, Google, and Whoop agree to notify users of law enforcement requests. According to EFF, Oura is reviewing its practices to “to provide greater visibility into how we handle these requests,” and Suunto is evaluating its transparency practices as well. EFF concludes that:

Any company that handles data that’s of interest to law enforcement and governments owes it to their users to publish transparency reports and, when legally possible, notify users when that data is requested. This is especially true of personal health data, which can reveal our movements, and be used to infer details about what we’re doing at any given moment.

The analysis also looked at whether the wearable device companies use end-to-end encryption for health data storage . It found that the Apple Watch “is the only popular fitness wearable that supports end-to-end encryption, and it’s enabled by default for all users (you are required to have two-factor authentication enabled as well, but that is also on by default for most accounts).” EFF warns users that this is only for the data stored in the Apple Health app, and not for other apps downloaded on the watch, or that are shared with other third-party apps or wearables. EFF found that Apple was the only one of all the companies reviewed, which “means those companies see and use your data,”…which “is a major privacy oversight, especially when you consider these devices collect heart rate, track sleep, and can log your location while also calculating a variety of health metrics supposedly intuiting everything from anxiety to your fitness ‘age.’”

EFF advises users to reach out to their fitness wearable to request that they offer transparency reports and provide end-to-end encryption for data storage. It also urges wearable companies to update their security practices and provide more transparency.

Photo of Linn Foster Freedman Linn Foster Freedman

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her…

Linn Freedman practices in data privacy and security law, cybersecurity, and complex litigation. She is a member of the Business Litigation Group and the Financial Services Cyber-Compliance Team, and chairs the firm’s Data Privacy and Security and Artificial Intelligence Teams. Linn focuses her practice on compliance with all state and federal privacy and security laws and regulations. She counsels a range of public and private clients from industries such as construction, education, health care, insurance, manufacturing, real estate, utilities and critical infrastructure, marine and charitable organizations, on state and federal data privacy and security investigations, as well as emergency data breach response and mitigation. Linn is an Adjunct Professor of the Practice of Cybersecurity at Brown University and an Adjunct Professor of Law at Roger Williams University School of Law.  Prior to joining the firm, Linn served as assistant attorney general and deputy chief of the Civil Division of the Attorney General’s Office for the State of Rhode Island. She earned her J.D. from Loyola University School of Law and her B.A., with honors, in American Studies from Newcomb College of Tulane University. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.