Fitness Trackers Exposed for Lacking Transparency and Security
EFF review shows most fitness trackers lack transparency and encryption for health data.
Why it matters: Privacy counsel should note growing legal risks as fitness trackers collect sensitive data with weak protections. Legal tech firms must prepare for tightening compliance demands.
- Only Apple and Google publish transparency reports on government data requests.
- Apple is the sole company offering end-to-end encryption for health data.
- Fitbit collects 22 data types; Strava collects 21, sharing for tracking with third parties.
- 74% of wearable users are concerned about data privacy, per Clutch survey.
The Electronic Frontier Foundation (EFF) analyzed privacy practices of ten major wearable health device companies. It found significant gaps in transparency and security across popular fitness trackers.
Apple and Google stand out as the only companies publishing transparency reports on government data requests related to user information, according to the EFF report published on Tech Times. Furthermore, these two, along with Whoop, have publicly committed to notifying users about law enforcement requests when legally permitted.
Apple is unique in providing end-to-end encryption for health data stored in its Apple Health app, an important safeguard highlighted by EFF. This encryption protects sensitive user data from unauthorized access even if a subpoena is issued.
Data collection practices vary widely: Fitbit collects 22 different types of data, including sensitive information but reportedly does not use it for tracking purposes. In contrast, Strava collects 21 types of data, none essential for app functionality, and shares user data with third parties for tracking, as noted in a TechRadar report. Nike Training Club also collects 20 types of data used for tracking.
Consumer concern echoes these findings. A Clutch survey reveals that 74% of wearable tech users worry about data privacy, while 71% own wearable devices and 67% use them for health and fitness tracking. As Clutch analyst Hannah Hicklen noted, "Wearables have shifted from occasional gadgets to everyday health tools," increasing the importance of robust data protections.
Oura has begun taking steps by updating its privacy policy to include user notification for law enforcement data requests and is evaluating publishing a transparency report.
These findings should alert privacy counsel and legal technology providers to the pressing need for enhanced transparency and encryption in fitness trackers. With sensitive health data broadly collected but unevenly protected, legal professionals must stay informed about compliance and risk mitigation strategies.
By the numbers:
- 10 major wearable companies reviewed by EFF
- 74% of wearable users concerned about data privacy
- 22 types of data collected by Fitbit
What's next: Oura plans to publish transparency reports and continue improving privacy policies in 2026.