When it comes to protecting data collected by smart devices such as smartwatches and fitness bands, the Electronic Frontier Foundation is cautioning that most of the companies aren’t closing their rings on privacy.
In the report, “Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features,” the digital civil liberties group looked at several of the leading companies making smart health devices to see which ones had strong privacy policies over some of customers’ most sensitive data.
The EFF breaks its reporting into two distinct areas: how transparent companies are about law enforcement requests for the information, and whether the data is end-to-end encrypted between the device and the company collecting and processing it.
The results aren’t encouraging. Only a few companies are open about when data is shared, and only one thoroughly secures the data in a way that the company itself would not be able to access it.
Transparency about law enforcement access to your health data
The government can make official demands – through a subpoena or search warrant, for example – or unofficial requests for sensitive data collected by devices. For fitness trackers, that can reveal information such as a person’s location along with their heart rate at a certain point in time.
Just two companies, Apple and Google, publish transparency reports, with a third, Whoop, promising to notify users of such requests in public documentation. Oura has committed to issuing transparency reports in the future.
Thorin Klosowski, the article’s author and a security and privacy activist at the EFF, told CNET in an email, “I was a little surprised that so few companies publish transparency reports, and I hope that changes in the future, since we know a lot of them have data request options for law enforcement.”
One company uses end-to-end encryption of health data
A smart device like a watch or ring constantly collects data, not just when you’re in the middle of a workout. Analyzing information such as heart rate and respiration, particularly at night while you’re sleeping, can surface signs of possible health issues like sleep apnea.
That sensitive data is often moved to cloud storage to be synced and backed up to the company’s app on your phone. EFF spotlights end-to-end encryption in the article as a way to protect it from data intrusions or improper access by the company.
The only company that passed this bar was Apple, which encrypts Apple Watch-collected data in the Health app in such a way that even it cannot read the details. The EFF noted that this is limited to the built-in Health app, and not third-party apps that collect and sync similar data.
“I knew that end-to-end encryption was super rare,” Klosowski wrote in his email, “but was also pretty disappointed at how few offer any sort of offline mode of any kind, let alone a full featured one. That’s one of those kind of ‘easy wins’ that I think would really benefit users.”
An Apple representative didn’t immediately respond to a request for comment.
The EFF article noted that companies offer encryption in transit and on device, but they can still see and use the data. “This is the industry standard, but it doesn’t have to be,” it reads.
Although end-to-end encryption is what the EFF hopes would be the standard, a few companies that responded to a request for comment from CNET reiterated that they take the privacy of customers’ data seriously.
A representative for Whoop responded via email with a link to the company’s privacy policy and wrote, “We protect member data, and members ultimately control their data. We use data to deliver Whoop, improve the product, and help members better understand their health. We have a pro-member data policy. We believe the individual owns the data, and we are not in the business of selling member data to advertisers.”
Similarly, a representative from Coros replied via email that, “We handle all personal information in full compliance with applicable international standards, including the EU General Data Protection Regulation (GDPR) and US laws. We maintain strict controls over data transfers, ensuring that customer details — including identifiers, metrics related to physiology, and activity data — are never sold to third parties. We are also dedicated to continually testing and updating our products to ensure that we use the most current security technology and approaches.” The rep also linked to the Coros privacy policy.
Oura’s representative said via email that the company does not sell or rent members’ personal information. “Members are in control of third-party integrations and can disconnect them at any time,” they wrote, “and we use technical and organizational safeguards to keep data safe and secure, including measures such as encryption, strict access controls, and anonymization or pseudonymization where appropriate.”
Garmin also pointed to its own privacy policies when contacted by CNET.
CNET Senior Editor for Health and Home Anna Gragert, who has used and reviewed many such smart devices, said it’s important that customers don’t automatically hit that agree button when presented with company policies.
“Wearable technology has been produced at a rate at which scientific research has had trouble catching up, so there aren’t enough studies looking into the potential downsides of these devices,” she said. “As a result, I think many consumers approach these wearables without fully understanding the possible risks, especially regarding privacy.”
CNET reached out to the other companies mentioned in the EFF article, but representatives didn’t immediately respond to requests for comment.
The EFF article highlighted alternatives like keeping personal data encrypted on the device or synced phone, and processing it locally. That still delivers the insights that these types of wearables are touting without exposing the data. However, some models remain limited in that type of capability.
“We had a pretty good idea of the landscape, but still hoped it would turn out better than it did,” Klosowski said.