Most popular smartwatches, fitness bands, and smart rings still lack basic privacy protections despite collecting some of the most sensitive personal information about their users, according to a new analysis by the Electronic Frontier Foundation (EFF). The digital rights organization found that only a handful of wearable manufacturers are transparent about government requests for user data, while end-to-end encryption remains almost nonexistent across the industry.

 

 

The EFF reviewed the privacy practices of ten major wearable brands: Apple, Google (including Fitbit), Amazfit, Coros, Garmin, Hume, Oura, Polar, Suunto, and Whoop. Researchers examined publicly available policies and contacted each company directly to verify their findings. The review focused on two areas: whether companies publish transparency reports detailing government requests for user data and whether they protect health information with end-to-end encryption.

According to the report, only Apple and Google currently publish transparency reports showing how often they receive requests for user data from law enforcement or government agencies. Apple, Google, and Whoop also publicly state that they notify users about those requests whenever the law allows. Oura recently updated its privacy policy, saying it is evaluating the publication of transparency reports, while Suunto told the EFF it is considering similar measures. The remaining manufacturers either do not publish transparency reports or have no publicly available policy explaining how they handle government data requests.

The EFF argues that this lack of transparency is particularly concerning because wearable devices collect detailed information about their owners, including heart rate, sleep patterns, activity levels, and location history. That data has already been used in criminal investigations, and law enforcement agencies can obtain access through subpoenas or search warrants. The organization also pointed to surveillance technology vendor Penlink, which describes fitness trackers as an “overlooked source” of investigative information because they reveal movement patterns and physiological changes.

Researchers also found that end-to-end encryption is largely absent from the wearable market. Apple Watch is the only widely available consumer health wearable that provides end-to-end encryption for health data stored in Apple’s Health app. However, that protection no longer applies when users choose to share information with third-party applications or services. None of the other reviewed companies offer comparable end-to-end encryption for health data stored in the cloud, meaning the providers themselves can access the information and disclose it in response to lawful government requests.

The EFF also criticized the industry’s reliance on cloud storage. While some Garmin and Polar devices can operate without constantly syncing to the cloud, the organization said many wearables still require online storage for full functionality. Apple was the only manufacturer identified as offering users an option to keep health data solely on their phone by disabling iCloud syncing in the Health app.

Rather than calling on people to stop using wearable devices, the EFF is urging manufacturers to improve their privacy practices. The organization says companies should publish transparency reports, notify users whenever legally possible if their data is requested by authorities, and offer end-to-end encryption or robust local-only storage options so users can decide how much information they want stored in the cloud.

Leave a Reply