Samsung Health App Threatens Data Deletion Over AI‑Consent Toggle, Then Backtracks
What Happened – In mid‑July Samsung added a new toggle in its Health app titled “Consent to the Use of Health Data for AI Training and Modelling.” Users who turned the toggle off were shown a warning that their health data would be deleted and cloud sync would stop unless legal retention required otherwise. After a wave of user backlash, Samsung clarified that withdrawing consent only stops data being used for AI training; normal sync and data retention continue.
Why It Matters for Compliance & Audit Readiness
- The episode highlights the need for documented consent‑management controls that satisfy SOC 2 CC6 (Privacy) and can be demonstrated to auditors.
- It underscores the importance of continuous evidence collection (e.g., consent logs, data‑retention policies) to prove that data handling aligns with declared privacy practices.
- The incident maps directly to Verisq’s CookiePLUS privacy capability, which helps organizations capture, manage, and audit user‑consent decisions across apps and services.
Who Is Affected – Consumer‑technology firms that operate health‑tracking apps, and the millions of end‑users whose biometric and clinical‑style data reside in those apps.
Recommended Actions
- Review and formalize your consent‑capture workflow; ensure any opt‑out does not trigger loss of core service functionality.
- Map the consent process to SOC 2 CC6 controls and collect immutable logs as audit evidence.
- Conduct a privacy‑impact assessment (PIA) for any AI‑training use of personal health data and update your public privacy notices accordingly.
Source: Malwarebytes Labs
Technical Notes
- No technical vulnerability was disclosed; the risk stemmed from a policy change that linked consent status to data deletion.
- The health data types involved include step counts, sleep metrics, medication logs, menstrual cycles, and other personally‑identifiable health information.
Source: Malwarebytes Labs