EFFector Volume 38, Issue 14🏃 Fitness Tracker Privacy FailsWelcome to an all-new EFFector, your regular digest on everything digital rights from the Electronic Frontier Foundation. In our 849th issue: The rapid rise of police drone programs, a disappointing ruling on electronic device searches at the U.S. border, and how fitness trackers are falling down when it comes to protecting our health data. |
|---|
|
When you lose your rights online, you lose them in real life. Become an EFF member today! |
|---|
Featured Story: Most Fitness Wearables Lack Key Privacy Features
Oura Rings, Garmin GPS fitness watches, Apple Watches, Whoop bands—every year, more and more tech devices are promising to monitor our health and fitness, guide us toward healthier living, and provide useful health metrics to take to our doctors. But few of these tools provide the sorts of privacy and security promises we demand from all technology, let alone tech that captures personal health data. There are many potential privacy issues with these sorts of devices, including whether the companies who make them share or sell information to third parties. But here we focused on two specific facets of health data privacy: 1) whether the company shares information with law enforcement and governments and 2) if they offer end-to-end encryption, which means the company itself can’t access that health data to begin with. After reading through dozens of product review sites, we identified 10 companies that seem to make the majority of recommended consumer health products on the market: Amazfit, Apple, Coros, Garmin, Google (including Fitbit), Hume, Oura, Polar, Suunto, Whoop. We reviewed each company’s public facing policies, then emailed them to confirm those findings. In the end, we found that only four of these companies (Apple, Google, Whoop, and Oura) promise to notify users of law enforcement requests in publicly available documentation. And just two of those companies, Apple and Google (which also owns Fitbit), currently publish transparency reports on how often they hand users' data to the government. Support for end-to-end encryption—a method that ensures your personal data is only accessible by you, and not the company who makes the device and manages the cloud storage—is more rare than transparency reports among wearable device makers. The Apple Watch is the only popular fitness wearable that supports end-to-end encryption. And that’s it. No other popular consumer health wearable offers end-to-end encryption for the data it collects and stores online. Not Google. Not Garmin. Not Oura. Most of these companies instead offer encryption in transit and at rest, but this means those companies can still see and use your data. This is the industry standard, but it doesn’t have to be. The companies that make these wearables, whether they’re designed for fitness or health, need to improve. At the bare minimum, companies need to publish transparency reports detailing how often they receive requests from law enforcement and commit to notifying users whenever that happens. More companies should also offer end-to-end encryption for the health data they’re storing. Health data is some of the most personal data we produce, and most wearables companies are behind the times when it comes to basic privacy practices and transparency. Now is the time to improve those practices.
EFF Updates👮POLICE DRONES: Since April 2025, more than 800 police departments have received FAA waivers to operate drone-as-first-responder (DFR) programs, recently released records show. That means hundreds of police drone programs could soon be launched in the U.S., jeopardizing privacy in communities across the country. As flying cameras, drones can capture footage from areas typically inaccessible to a casual patrol officer—backyards, roofs, through windows—at distances that leave subjects of surveillance completely unaware of the spy in the sky. 🛃 BORDER SEARCHES: A federal appeals court recently ruled that U.S. border agents can search your phone by hand, no suspicion required. The Fourth Circuit issued this disappointing opinion in U.S. v. Belmonte Cardozo, a case in which EFF filed an amicus brief. We argued that electronic device searches at the border should require a warrant based on probable cause, but at minimum, regardless of whether an officer searches by hand or with forensic software, the same Fourth Amendment standard should apply. Unfortunately, the court rejected that argument and ruled that a lower standard applies to manual searches, allowing the government to conduct extraordinarily invasive electronic device searches without any suspicion of wrongdoing, simply because the border officer chooses to search by hand. 👂 ACOUSTIC SURVEILLANCE: In a victory for privacy, Flock Safety has announced that it will end a pilot for high-powered microphones to listen for sounds of "human distress" throughout cities. Good riddance. This was a misguided and dangerous feature because of the civil liberties concerns it poses, the possibility it could summon armed police to every loud interaction happening on the street, and because in several places this type of spying would be illegal under state eavesdropping laws. 🪪 STATE AGE GATES: The California legislature has stepped back from a plan that would have dangerously expanded its age-gating law, removing language that could have compounded serious threats to users’ speech, privacy and security just to browse the internet. A.B. 1856 will now move forward through the legislature without its most problematic pieces. To be clear, EFF still believes the underlying law that A.B. 1856 amends, A.B. 1043, is unconstitutional and threatens online anonymity, privacy, and security. |
|---|
Support the Electronic Frontier FoundationWe're making sure technology serves all people—not just the powerful. Your contribution funds the attorneys, activists, and technologists who defend privacy, free expression, and human rights online—for everyone. Since 1990, EFF has led the charge for your digital rights. We're powered by members, and we need you in this fight. |
|---|
"A lot of companies will have a promise that they don’t share or sell data but [end-to-end encryption] is a mathematical assurance that they really don’t have a lot of data to sell."EFF's Thorin Klosowski on why more fitness tracker companies should offer end-to-end encryption to protect our health data. Hear our conversation with Thorin on the latest episode of the EFFector podcast.
MiniLinks🗣️ Free Speech
🔒 Privacy 🌍 International
🗝️ Security
AnnouncementsEFF Events
Corporate Giving and Sponsorships
|
|---|
Fresh EFF Gear Is HereShow off your support for EFF with hot digital rights merch from our online store. Just in: an EFF circuit-board brain sticker with a textured finish that's as distinctive to touch as it is to look at. In addition to EFF shirts and hoodies, we have a wide variety of freedom-supporting swag in stock, including (extremely popular) liquid core gaming dice, HTTP playing cards, and a tactile Lady Justice braille sticker. |
|---|
AdministriviaEFFector is a publication of the Electronic Frontier Foundation. Editor: editor@eff.org Membership and donation queries: membership@eff.org General EFF, legal, policy, or online resources queries: info@eff.org
Reproduction of this publication in electronic media is encouraged. MiniLinks do not necessarily represent the views of EFF.
About EFFThe Electronic Frontier Foundation is the leading nonprofit defending online civil liberties. We promote digital innovation, defend free speech, fight illegal surveillance, and protect rights and freedoms for all as our use of technology grows. Find out more at https://www.eff.org/.
This message is printed from 100% recycled electrons. EFF appreciates your support and respects your privacy.
|
|---|



