EFF Tests 10 Major Wearable Brands And Finds Only Apple Offers End-To-End Encryption: Oura Rings, Garmin Watches, Whoop Bands And Others Collect Heart Rate, Sleep And Location Data But Share It With Third Parties, Insurers And Law Enforcement Without Telling You How Often
According to the Electronic Frontier Foundation, a review of ten major consumer health wearable brands; Amazfit, Apple, Coros, Garmin, Google/Fitbit, Hume, Oura, Polar, Suunto, and Whoop; found that most fail to meet basic privacy standards, lacking both end-to-end encryption and transparency reports on how often they hand user data to governments and law enforcement.
Only Apple offers end-to-end encryption for health data, and only for data stored in the Apple Health app; the only wearable company of ten surveyed to do so. Only Apple and Google currently publish transparency reports detailing government data requests. The EFF notes that roughly 40 per cent of Americans own some form of commercially available wearable health device, yet none of those devices carry special health-related privacy protections; they are not covered by HIPAA.
Oura has committed to publishing a transparency report following journalist pressure and updated its privacy policy in June 2026 to notify users of law enforcement requests. Suunto expressed openness to potential future transparency reports. The other six companies did not respond or had no policy.
Law enforcement already uses heart rate data, step tracking and movement patterns from wearables as evidence in criminal investigations. The surveillance company Penlink has explicitly called fitness trackers an “overlooked source” of investigative data. These devices are not simply health tools; they are always-on movement and biometric trackers worn by tens of millions of people, with weaker privacy protections than a basic social media account.
Check out our previous coverage of tech on The Trusted Times.

