Wearables Are Becoming Health Records, But Privacy Controls Lag
CNET reported on July 30, 2026 that the Electronic Frontier Foundation is warning about weak privacy and transparency practices across many leading smartwatches, smart rings, and fitness bands. The original story focuses on a practical problem for consumers: these devices are marketed as health and fitness companions, but the data they collect can describe routines, location patterns, sleep, heart rate, and other intimate signals.
The stronger context comes from EFF's own review, which looked at ten major consumer wearable makers: Amazfit, Apple, Coros, Garmin, Google including Fitbit, Hume, Oura, Polar, Suunto, and Whoop. EFF said it reviewed public policies and contacted the companies to confirm its findings.
What EFF Found
EFF's main concern is not that wearables collect health data. It is that users often have limited visibility into who can access that data after it leaves the device.
According to EFF, only Apple and Google currently publish transparency reports among the companies it reviewed. Transparency reports matter because they disclose government requests for user information and help users understand when personal data may be exposed through legal processes. EFF also said Apple, Google, Whoop, and Oura publicly commit in some form to notifying users about law-enforcement requests when allowed.
Encryption is the second gap. EFF found that end-to-end encryption for cloud-stored wearable health data remains rare. Apple Health data is a notable exception: Apple says Health data is end-to-end encrypted in iCloud, meaning Apple does not hold the keys for that category. EFF cautions, however, that this protection can change once data is shared with third-party apps, other services, or non-Apple wearables.
For most other products, the common promise is encryption in transit and at rest. That is useful, but it still usually means the service provider can access the data in its cloud systems. EFF argues that consumers should have stronger choices, such as end-to-end encryption or local-only storage modes.
Why It Matters
Fitness data can look harmless when viewed as daily step counts or sleep scores. In aggregate, it can become a behavioral map. EFF points out that wearable information has already become relevant in investigations because heart-rate, movement, and location-adjacent records can help reconstruct what someone was doing at a particular time.
For users, the immediate takeaway is to treat wearable health data as sensitive account data, not just gadget telemetry. The privacy posture depends on the device, the companion app, cloud sync settings, third-party integrations, and whether the company publishes clear policies for government requests.
What Buyers And Developers Should Watch
Consumers comparing wearables should look beyond battery life and sensor accuracy. Ask whether the vendor publishes a transparency report, whether it notifies users about legal requests when permitted, whether health data can stay local, and whether end-to-end encryption is available for cloud sync.
Developers building health and wellness services should assume that wearable data carries legal, privacy, and safety implications. If a product needs cloud processing or AI features, the trade-off should be explicit. A privacy-respecting design should minimize data collection, explain retention, restrict third-party sharing, and give users a meaningful way to avoid unnecessary cloud storage.
The confirmed news is EFF's warning and CNET's report on it. The analysis is the broader implication: wearables are moving deeper into personal health workflows, so privacy controls are becoming part of the product's core value, not a secondary settings-page detail.