Your smartwatch knows your heart rate, sleep patterns, and stress levels in real time. The Electronic Frontier Foundation just documented that the companies selling these devices to millions of Americans are doing remarkably little to keep that intimate data away from corporate trackers and third parties.
This matters now because the fitness wearable market has exploded. Watches, bands, and rings designed to monitor your health digitally are everywhere—and more Americans than ever own at least one. But the privacy safeguards protecting that data are lagging far behind the technology itself. The gap isn’t a technical inevitability. It’s a choice.
- Transparency Gap: Most fitness tracker manufacturers do not publish transparency reports showing third-party data requests, unlike major tech platforms that do so annually.
- Business Model Conflict: The real revenue in wearables comes not from device sales but from monetizing the continuous behavioral and biometric data stream each device generates.
- Consent Without Visibility: Users who agree to share health data with manufacturers have no mechanism to audit whether that data is cross-referenced, sold to brokers, or used to infer insurance or employment risk.
The EFF’s latest analysis, published in their EFFector newsletter and detailed in a podcast conversation with Senior Security and Privacy Activist Thorin Klosowski, reveals a systemic problem: most smartwatches, rings, and fitness bands lack basic transparency reports and key privacy protections that are technically feasible to implement right now.
Here’s what that means in practical terms. Your fitness tracker collects some of the most intimate data about your body—heart rate variability, resting pulse, sleep duration, workout intensity, even stress levels inferred from physiological signals. That data streams continuously from your wrist to company servers. Once it arrives, the companies that made your device have minimal legal obligation to tell you what happens next. Do they share it with insurers? Sell it to advertisers? Use it to build behavioral profiles? Most fitness tracker makers don’t publish transparency reports showing third-party data requests, the way tech giants like Google and Meta do for government surveillance demands.
The absence of these reports is telling. A 2025 living systematic review of privacy in consumer wearable technologies found that critical protections—including data minimization, user control rights, third-party data sharing disclosures, and breach notification—are inconsistently implemented or entirely absent across the consumer wearable market. The research underscores that the problem is not technical complexity but a lack of industry-wide standards and enforcement.
Why Transparency Reports Matter for Health Data
Transparency reports serve a specific function: they create accountability. When a company publishes how many times law enforcement requested user data, and how many requests they complied with, it creates a public record. Journalists can scrutinize it. Regulators can use it as a benchmark. Users can make informed choices. Most major social media and cloud platforms publish these reports annually. Most fitness tracker manufacturers do not. That asymmetry leaves your heart rate data in a legal and ethical gray zone.
This echoes a structural problem that emerged during the Cambridge Analytica scandal. In that case, Facebook had collected vast psychological and behavioral profiles on millions of users—data that users didn’t know was being weaponized for political microtargeting. The company’s own privacy policies were technically compliant but deliberately opaque. Users couldn’t see what was being inferred about them or how it was being used. As the legacy of Cambridge Analytica demonstrates, consent without transparency is not consent at all. Fitness tracker companies are operating in that same gray zone today. You consent to sharing health data with the manufacturer. But you have no visibility into whether that data is being cross-referenced with other datasets, sold to data brokers, or used to infer behavioral patterns about you—your stress levels, your exercise habits, your sleep quality. That’s valuable information for insurance companies, employers, and advertisers.
• A survey of wearable activity trackers published in ACM Digital Library documents that users’ behaviors toward fitness data sharing with third parties are poorly understood by the users themselves, with most unaware of the downstream destinations of their data.
• The same research identifies a persistent gap between stated privacy policies and actual data-sharing practices in the wearable sector.
• Systematic review findings confirm that data security and breach notification standards in consumer wearables remain significantly weaker than in regulated health data environments such as hospital systems.
What Companies Could Do—and Are Choosing Not To
The EFF’s investigation highlights what companies could do but aren’t. Basic privacy protections exist. End-to-end encryption for health data in transit and at rest is technically standard in other industries. Data minimization—collecting only the information necessary for the stated purpose—is a principle embedded in European privacy law and increasingly adopted in U.S. regulations. Transparency reports are a proven mechanism. So is allowing users to download their own data in portable formats, or to delete it entirely. None of these are novel or expensive.
Yet the fitness tracker market has largely resisted them. Why? The business model depends on data accumulation. The more intimate data a company collects, the more valuable it becomes to third parties. Insurance companies want to know your daily step count and resting heart rate. Employers want to see your sleep patterns and stress metrics. Advertisers want to target you based on your fitness level and health concerns. That’s where the real money is—not in selling you a $200 smartwatch, but in monetizing the behavioral stream that watch generates. The structural parallel to how Cambridge Analytica exploited behavioral data is direct: in both cases, the product being sold to users was never the real product. The data was.
Is Your Health Data Already Being Used Against You?
The podcast episode featuring Thorin Klosowski digs into the specifics of what’s missing. Most smartwatches and fitness bands lack the kind of granular privacy controls that would let you decide what data gets shared with whom. You can’t easily opt out of third-party data sharing without deleting your account entirely. You can’t see which companies have requested your data. You can’t audit how your health information is being used downstream.
For you as a user, this creates a hidden liability. If you wear a fitness tracker, you’re generating a continuous stream of health data that’s far more detailed than anything you’d share with your doctor. That data is being stored, potentially shared, and possibly used to make inferences about your health status, your financial risk, even your employability. Insurance companies have already begun using wearable data to adjust premiums. Some employers have started offering discounts on health insurance if employees agree to share fitness tracker data. That sounds benign until you realize the data can be used against you—higher premiums if your activity levels drop, or if your stress metrics spike.
• The EFF’s Thorin Klosowski identifies the core failure as structural: fitness tracker companies have no regulatory obligation to publish what third parties receive user data, leaving users with no mechanism for informed consent beyond accepting or rejecting the device entirely.
• The absence of data portability and deletion tools means users cannot exercise rights that European law treats as fundamental—and that U.S. regulators are increasingly examining as the wearable market scales.
• Pending federal legislation such as the SECURE Data Act raises additional concerns: privacy advocates warn that some proposed national frameworks could preempt stronger state-level protections, potentially weakening the floor for health data privacy rather than raising it.
The Regulatory Question the Market Cannot Answer Alone
The EFF’s findings suggest that fitness tracker makers have a choice to make. They can continue operating in the current model, where user data is a commodity and privacy is an afterthought. Or they can adopt the basic protections that already exist in other industries: transparency reports, data minimization, encryption, user control. The technology isn’t the barrier. The barrier is business incentive.
What’s striking is that this isn’t a new problem. For over 35 years, the EFF has documented the intersection of technology, civil liberties, and the law. The fitness tracker privacy gap is a contemporary version of a very old story: companies collecting intimate data about people, without clear consent or visibility, because the business model depends on it. The Cambridge Analytica scandal made that pattern visible at scale. Fitness trackers are doing something similar, just with biometric data instead of psychological profiles—and with far less public scrutiny so far.
The EFF’s investigation is available in full in the EFFector newsletter, with an extended podcast conversation on Spotify, Apple Podcasts, Amazon Music, and via RSS. The broader question hanging over this moment is whether fitness tracker manufacturers will face regulatory pressure to adopt basic privacy protections, or whether the market will continue to reward companies that treat health data as a commodity. Given the speed at which wearable adoption is accelerating, that question will be answered soon.