EFF Report Finds Most Smart Wearables Lack End‑to‑End Encryption and Transparency
What Happened — The Electronic Frontier Foundation (EFF) evaluated ten leading consumer health‑device makers (Apple, Google/Fitbit, Garmin, Oura, Polar, Suunto, Whoop, etc.) and found that only Apple provides end‑to‑end encryption for health data and only Apple and Google publish transparency reports. The majority of vendors rely on protections that stop outsiders but still allow the company itself to access sensitive health metrics.
Why It Matters for Compliance & Audit Readiness
- The gap highlights a real‑world privacy control deficiency that SOC 2 CC‑5 (Privacy) and GDPR/CCPA obligations expect organizations to address through documented consent, data‑subject request processes, and encryption.
- Continuous evidence of vendor privacy practices (e.g., transparency reports, encryption attestations) is essential for audit readiness and for demonstrating due diligence in third‑party risk programs.
- Verisq’s CookiePLUS capability can automate consent capture, DSAR workflow, and privacy‑policy monitoring to provide the audit‑ready artifacts EFF says are missing.
Who Is Affected — Consumer‑health wearables market; users of smart watches, rings, and fitness bands; vendors in the health‑tech space; enterprises that integrate wearable data into employee wellness programs.
Recommended Actions
- Inventory all wearable vendors and map their privacy statements to SOC 2 CC‑5 and GDPR/CCPA requirements.
- Require end‑to‑end encryption or documented encryption‑in‑transit controls as a contractual clause.
- Implement a consent‑management solution that logs user opt‑ins and can generate DSAR responses on demand.
- Request and retain vendor transparency reports as part of continuous monitoring evidence.
Source: Security Affairs – EFF: Most Smart Wearables Still Fall Short on Privacy and Transparency
Technical Notes — The assessment examined public privacy policies, transparency‑report availability, and encryption claims; no specific CVEs or exploit techniques were identified. The primary data types at risk are health metrics (heart rate, sleep, location) that can be linked to individuals.