When it comes to protecting data collected by smart devices like smartwatches and fitness bands, the Electronic Frontier Foundation warns that most companies don’t turn a blind eye to privacy.
In the report titled “Most Smart Watches, Rings and Bracelets Lack Basic Transparency Reporting and Key Privacy Features,” the digital civil liberties group looked at several of the leading companies making smart health devices to see which ones had strict privacy policies on some of their customers’ most sensitive data.
The EFF divides its reporting into two distinct areas: how transparent companies are regarding requests for information from law enforcement and whether the data is end-to-end encrypted between the device and the company collecting and processing it.
The results are not encouraging. Only a few companies are open about when data is shared, and only one carefully secures the data so that the company itself cannot access it.
Transparency on law enforcement access to your health data
The government can make formal requests – through a subpoena or search warrant, for example – or unofficial requests regarding sensitive data collected by the devices. For fitness trackers, this can reveal information such as a person’s location as well as their heart rate at any given time.
Only two companies, Apple and Google, publish transparency reports, and a third, Whoop, promises to notify users of such requests in public documentation. Oura has committed to publishing transparency reports in the future.
Thorin Klosowski, the author of the article and a security and privacy campaigner at the EFF, told CNET in an email: “I was a little surprised that so few companies publish transparency reports, and I hope this will change in the future, since we know that many of them have data request options for law enforcement.” »
Company Uses End-to-End Encryption of Health Data
A smart device like a watch or ring is constantly collecting data, not just when you’re in the middle of a workout. Analyzing information like heart rate and breathing, especially at night while you sleep, can show signs of possible health problems like sleep apnea.
This sensitive data is often moved to cloud storage to be synced and backed up to the company’s app on your phone. The EFF highlights end-to-end encryption in the article as a way to protect against data intrusions or inappropriate access by the company.

Apple touted its work on privacy during its WWDC online developer event.
Apple/Screenshot by Stephen Shankland/CNET
The only company that has passed this mark is Apple, which encrypts the data collected by the Apple Watch in the Health app in such a way that even it cannot read the details. The EFF noted that this is limited to the built-in Health app, and not third-party apps that collect and sync similar data.
“I knew that end-to-end encryption was extremely rare,” Klosowski wrote in his email, “but I was also quite disappointed that few of them offer an offline mode of any kind, let alone a full mode. It’s one of those types of ‘easy wins’ that I think would really benefit users.”
An Apple representative did not immediately respond to a request for comment.
The EFF article notes that the companies offer encryption in transit and on the device, but they can still see and use the data. “This is the industry standard, but is not required,” it reads.
Although the EFF hopes that end-to-end encryption will become the norm, a few companies that responded to a request for comment from CNET reiterated that they take the privacy of their customers’ data seriously.

The Whoop 5.0 health tracker on the wrist
Nasha Addarich Martínez/CNET
A Whoop representative responded via email with a link to the company’s privacy policy and wrote: “We protect member data, and members ultimately control their data. We use the data to provide Whoop, improve the product, and help members better understand their health. We have a member-friendly data policy. We believe the individual owns the data and our business is not to sell member data to advertisers.”
Similarly, a Coros representative responded via email: “We process all personal information in full compliance with applicable international standards, including the EU General Data Protection Regulation (GDPR) and US laws. We maintain strict controls over data transfers, ensuring that customer details – including identifiers, physiology-related metrics and activity data – are never sold to third parties. We are also committed to testing and updating “Continuously updates our products to ensure we are using the latest security technologies and approaches.” The representative also linked to Coros’ privacy policy.
Oura’s representative said via email that the company does not sell or rent members’ personal information. “Members control third-party integrations and can disconnect them at any time,” they wrote, “and we use technical and organizational safeguards to ensure data security, including measures such as encryption, strict access controls, and anonymization or pseudonymization, where appropriate.”

The Oura Ring 4 has a titanium exterior and interior.
Carly Marsh/CNET
Garmin also highlighted its own privacy policies when contacted by CNET.
CNET health and home editor Anna Gragert, who has used and reviewed many such smart devices, said it’s important that customers don’t automatically hit that OK button when presented with company policies.
“Wearable technologies have been produced at a rate where scientific research has struggled to catch up, so there are not enough studies examining the potential downsides of these devices,” she said. “As a result, I believe many consumers are approaching these wearable devices without fully understanding the possible risks, particularly when it comes to privacy. »
CNET contacted the other companies mentioned in the EFF article, but representatives did not immediately respond to requests for comment.
The EFF article highlighted alternatives such as encrypting personal data on the synced device or phone and processing it locally. This still provides the information that these types of wearables tout without exposing the data. However, some models remain limited in this type of capabilities.
“We had a pretty good idea of the landscape, but we were still hoping the outcome would be better,” Klosowski said.

Jeff Carlson
Main writer
Jeff Carlson writes about mobile technology at CNET, from cell phone plans to emerging devices and technologies. See full bio
































