EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency

Pierluigi Paganini July 27, 2026

EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency.

Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major smart watches, rings, and bands makes the case plainly: these devices collect deeply personal health data, but most vendors still don’t give users the protections or transparency they should expect from the start.

“Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data.” reads the report published by EFF. “It’s time they step up and start providing transparency reports and stronger encryption options.”

The EFF looked at ten popular consumer health-device makers, including Apple, Google/Fitbit, Garmin, Oura, Polar, Suunto, and Whoop, then checked public policies and followed up by email. That matters because this isn’t a narrow complaint about one weak product line or one sloppy vendor. It’s a broader look at a market that keeps asking people to hand over sensitive data while offering very uneven safeguards in return.

What the group found is pretty simple: only Apple and Google currently publish transparency reports, and only Apple Watch supports end-to-end encryption for health data stored in its Health app. In practice, that means Apple’s users get a stronger privacy model than the rest of the market, while most competitors still rely on protections that stop outsiders but not the company itself from seeing the data.

“Only two of the companies we surveyed, Apple and Google (which also owns Fitbit), currently publish transparency reports. AppleGoogle, and Whoop promise to notify users of law enforcement requests in publicly available documentation.” states EFF.

That gap matters because health data is now a real target in investigations, and wearable data can help reconstruct where someone was, how they moved, and even what they were doing at a given time. If a company won’t say how often it gets legal demands, users are left guessing, and that’s a strange way to build trust around products that track sleep, movement, heart rate, and location all day.

“And that’s it. Apple is the only one. No other popular consumer health wearable offers end-to-end encryption for the data it collects and stores online. Not Google. Not Garmin.” continues the report. “Not Oura. Most of these companies instead offer encryption in transit and at rest, but this means those companies can still see and use your data. This is the industry standard, but it doesn’t have to be.”

The EFF’s point is not that every company must copy Apple feature for feature. It’s that if these firms are going to sell devices that track health, movement, and sleep, they should at least offer transparency reports and a real end-to-end encryption option. Right now, the market mostly offers partial protections, vague assurances, and the usual “we take privacy seriously” line, which is doing a lot of work for a very small sentence.

The real problem is that the industry is still treating privacy as a differentiator instead of a baseline requirement. With many major tech companies already publishing information about government data requests, wearable manufacturers have little reason to remain opaque. Users deserve clear protections, not vague assurances.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Smart Wearables)



you might also like

leave a comment