Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features
Original reporting by Electronic Frontier Foundation

Wearable health devices, from fitness trackers like Oura Rings to smartwatches from Apple and Garmin, refer to a category of consumer technology that collects intimate personal health data, often without robust privacy protections. Despite their widespread adoption by nearly 40% of Americans, these devices gather highly sensitive information—including heart rates, sleep patterns, and precise location—under a concerning lack of transparency and security standards. This data is not only routinely shared with third parties for purposes ranging from marketing to AI training, but it is also increasingly sought by law enforcement, transforming personal health metrics into a critical, yet often overlooked, source for investigations and surveillance.
Scrutinizing Protections
In response to these growing concerns, our investigation delves into the policies of ten leading wearable brands, scrutinizing two fundamental privacy safeguards: the provision of transparency reports detailing government data requests, and the implementation of end-to-end encryption to truly secure user information. The findings reveal a stark landscape: few companies openly disclose how they handle official demands for user data, with only Apple and Google consistently publishing such reports. Even more concerning is the near-total absence of end-to-end encryption, a fundamental security measure that would prevent companies themselves from ever accessing the sensitive health metrics they store. This pervasive lack of protection leaves deeply personal health data vulnerable, underscoring an urgent need for the industry to adopt stronger, user-centric privacy practices that genuinely empower users.
The comprehensive review unequivocally reveals a concerning disparity between the widespread adoption of health wearables and the industry’s commitment to user privacy. Barring a few exceptions, major manufacturers are consistently failing to provide consumers with fundamental safeguards, from transparent reporting on government data requests to crucial end-to-end encryption for deeply personal health metrics. This prevailing status quo leaves an immense volume of sensitive information—from heart rates to location data—exposed, not only to potential law enforcement scrutiny but also to opaque third-party sharing, marketing influence, or unchecked use in AI model training. The convenience and health insights these devices promise are currently delivered at an unacceptably high, and often unacknowledged, privacy cost.
Securing Future Health Tech The ramifications of this industry-wide privacy deficit are profound, extending far beyond individual user concerns. Without standardized, robust privacy frameworks, the burgeoning health tech sector risks undermining public trust, potentially hindering the very innovation intended to enhance well-being. As artificial intelligence increasingly leverages personal health data, the absence of strong encryption and clear data governance becomes a critical ethical and practical challenge, dictating who ultimately controls and benefits from future health insights. Looking ahead, industry leaders must proactively embrace privacy as a core design principle, not an afterthought. Escalating consumer demand for data sovereignty, alongside growing regulatory scrutiny worldwide, will inevitably force a reckoning. Companies that demonstrably prioritize user control and transparency will not only rebuild trust but also define the ethical and responsible trajectory for the next generation of health technology, moving from mere data collection to genuinely empowering health management.
Frequently asked questions
- What are the main privacy risks associated with using consumer health wearable devices?
- Wearable health devices collect highly personal data, including heart rate, sleep patterns, and location. Companies often share this data with third parties for marketing, to influence insurance rates, or to train AI models. This information can also be accessed by law enforcement through subpoenas or warrants, raising significant concerns about personal data privacy and potential surveillance of user movements and activities.
- Which wearable health device companies provide transparency reports on government data requests?
- Few companies manufacturing consumer health wearables publish transparency reports detailing government or law enforcement data requests. Among major brands, Apple and Google (including Fitbit) currently provide these reports. Oura and Suunto have indicated they are evaluating or considering publishing such reports in the future, aiming to offer users greater visibility into how data requests are handled and their personal health information is managed.
- Do popular fitness trackers and smartwatches offer end-to-end encryption for health data?
- End-to-end encryption (E2EE) for health data on popular consumer wearables is rare. Currently, the Apple Watch is a notable exception, offering E2EE for data stored within its Health app, provided two-factor authentication is enabled. Most other companies only provide encryption in transit and at rest, meaning they can still access user data. This industry standard allows companies to view and utilize the personal health metrics collected.