Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Feb 20, 2026 · 6 min read

EFF: Only 2 of 10 Wearable Makers Are Transparent

A July 15, 2026 Electronic Frontier Foundation audit of ten smartwatch, ring, and fitness band makers, including Apple, Google/Fitbit, Oura, Garmin, and Whoop, found only two publish transparency reports on law enforcement data requests, and only Apple Watch offers end to end encryption for health data.

An editorial still life photograph of a smartwatch, a fitness band, and a smart ring arranged together on a neutral surface with subtle indigo tones

Nearly every fitness watch on the market promises to know you better than you know yourself: your heart rate at 3 a.m., how well you slept, how many steps you took to your car. A new audit from the Electronic Frontier Foundation, published July 15, 2026, asked a simpler question: when police or a government agency comes asking for that data, does the company that collects it tell you? For eight of ten major wearable makers, the answer is effectively no.

Key Takeaways

  • The Electronic Frontier Foundation's July 15, 2026 report found only two of ten wearable makers reviewed, Apple and Google, which owns Fitbit, currently publish transparency reports covering law enforcement data requests.
  • EFF evaluated Amazfit, Apple, Coros, Garmin, Google/Fitbit, Hume, Oura, Polar, Suunto, and Whoop on transparency reporting and encryption practices.
  • Apple Watch is the only popular wearable EFF found that offers end to end encryption for health data stored in its Health app, meaning Apple itself cannot read it.
  • Roughly 40 percent of US adults own a wearable health device, according to survey data cited in the report, yet EFF found none of that data carries special legal protection beyond general state privacy laws.
  • Oura updated its privacy policy in June 2026 to promise more visibility into law enforcement requests, and Suunto told EFF it is evaluating whether to publish a transparency report of its own.

What Did the EFF Study Actually Test?

EFF's audit did not grade wearables on data breaches or marketing practices. It asked two narrow, concrete questions of each company: do you publish a transparency report telling users how often governments ask for their data, and can you technically hand over a user's health data even if you wanted to keep it private. Those two questions cut through the marketing language every wearable brand uses about protecting your privacy and instead measure what happens the moment a subpoena or warrant lands on a company's desk.

Which Wearable Makers Did EFF Evaluate?

The report reviewed ten manufacturers spanning smartwatches, fitness bands, and smart rings: Amazfit, Apple, Coros, Garmin, Google, which now owns Fitbit, Hume, Oura, Polar, Suunto, and Whoop. That list covers the devices most likely sitting on your wrist or finger right now, from mainstream Apple Watches and Fitbits to the increasingly popular Oura Ring and endurance sport brands like Garmin, Coros, and Polar.

Of that list, EFF found only Apple and Google currently publish a transparency report. The rest, including popular names like Garmin, Whoop, and Oura, do not disclose how many government requests for user data they receive or how often they comply. Whoop and Oura are already facing separate legal scrutiny over how they handle biometric data, after California class actions accused both companies of sharing fitness and health signals with advertising platforms without consent.

Why Do Transparency Reports Matter for a Watch?

A transparency report is a company's public accounting of how many times governments and law enforcement have asked for user data, and how the company responded. Tech giants like Google and Apple have published these for their core services for over a decade, largely because journalists, researchers, and regulators pushed them to. Wearable makers have mostly avoided the same scrutiny, even though the data on a fitness tracker, precise location history, heart rate, sleep patterns, can place a person at a specific location at a specific time.

EFF's report notes that wearable data is already showing up in criminal investigations and civil disputes, used to help establish where someone was and what physical state they were in. Without a transparency report, users have no way to know how often that happens or how readily their device maker cooperates.

Why Does Encryption Matter If the Data Is Already Collected?

The second test in EFF's audit is arguably the more consequential one: end to end encryption. If your health data is end to end encrypted, the company storing it cannot read it, which means it generally cannot hand over readable data even if compelled to, only encrypted files it cannot open. EFF found that among the ten companies reviewed, only Apple Watch offers this protection, and only for health data stored in Apple's Health app.

Every other wearable in the study stores health data in a form the company itself can access. That does not mean those companies are misusing the data today. It means that if a court order arrives, or if the company itself decides to use the data for other purposes such as insurance partnerships or advertising, there is no technical barrier standing between your heart rate history and someone else's use of it.

Is Any Company Moving in the Right Direction?

Two companies signaled they know the current standard is not good enough. Oura revised its privacy policy in June 2026, telling EFF it is actively evaluating ways to provide greater visibility into how it handles these requests, like through a transparency report. Suunto gave EFF a similar answer, saying it continuously evaluates its transparency practices and may publish a report in the future. Neither has committed to a timeline, and EFF's report treats both statements as promises to watch rather than results to celebrate.

What Should You Do If You Already Own a Wearable?

You do not need to throw out your smartwatch to act on this. A few concrete steps make a real difference:

  • Check whether your device offers any form of end to end encryption for health data, and enable it if it exists. Right now that effectively means Apple Watch users checking their Health app settings.
  • Read the data sharing section of your wearable's privacy policy, specifically what happens to your data if the company is acquired, partners with an insurer, or receives a government request.
  • Look up whether your manufacturer publishes a transparency report before your next purchase. EFF's findings are a useful starting checklist.
  • Turn off features you do not need, such as continuous location tracking or third party data sharing toggles, which are often on by default.

The Bigger Picture

Wearables occupy a strange legal gray zone. They collect data that looks and feels medical, heart rate, sleep, blood oxygen, but because a tech company rather than a hospital is collecting it, most of the legal protections that apply to medical records simply do not apply. EFF's audit is a reminder that with roughly 40 percent of US adults now wearing one of these devices, the gap between how sensitive this data is and how little oversight most companies apply to it has become a mainstream problem, not a niche one. Until more manufacturers follow Apple and Google's lead on transparency reporting, and more build in encryption the way Apple has, the burden of protecting that data falls on the people wearing it.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.