Privacy protections for wearable devices are weak, study says

Wearables are collecting a huge amount of personal information, but regulations are lax, privacy groups say

The rapidly expanding wearable device market raises serious privacy concerns, as some device makers collect a massive amount of personal data and share it with other companies, according to a new study.

Existing health privacy laws don't generally apply to wearable makers, the study says. While consumers are embracing fitness trackers, smart watches, and smart clothing, a "weak and fragmented" health privacy regulatory system in the U.S. fails to give consumers the privacy protections they may expect, said the study, released Thursday by the Center for Digital Democracy and the School of Communication at American University.

"Many of these devices are already being integrated into a growing Big Data digital health and marketing ecosystem, which is focused on gathering and monetizing personal and health data in order to influence consumer behavior," the study says. 

As consumers buy more smart wearables and the devices' functionality becomes increasingly sophisticated "the extent and nature of data collection will be unprecedented," the study adds.

"Americans now face a growing loss of their most sensitive information, as their health data are collected and analyzed on a continuous basis, combined with information about their finances, ethnicity, location, and online and off-line behaviors," said Jeff Chester, CDD's executive director and co-author of the report. "Policy makers must act decisively to protect consumers in today's big data era."

In the U.S., privacy law is piecemeal, with separate laws for different types of information, such as financial, student, or health data, the study notes. U.S. privacy laws governing health information are "limited and fragmented, with significant gaps in coverage," the study says. "The degree to which users of wearable devices will be able to make informed privacy decisions ... will ultimately depend on the effectiveness of government and self-regulatory policies."

While wearable users may believe health information collected by the devices are protected by the U.S. Health Insurance Portability and Accountability Act (HIPAA), that's not the case, Chester said by email.

HIPAA applies only to so-called covered entities, basically health-care providers like doctors and hospitals, he said. "These consumer wearable devices aren’t covered by HIPAA and the marketing that goes on has no protections," Chester added.

In a June report, the U.S. Department of Health and Human Services noted that "health information is increasingly collected, shared, or used by new types of organizations beyond the traditional health care organizations" covered by HIPAA.

A spokeswoman for fitness tracker maker Fitbit noted the company has worked with privacy group the Center for Democracy and Technology to define privacy best practices for wearables. The company believes users should control their data, she said.

"Fitbit is committed to protecting the privacy of our users' data and the trust of our customers is paramount," Fitbit said in a statement. "It has always been our policy not to sell user data."

Wearable maker Apple didn't immediately respond to a request for comment on the report.

The authors of the study called for new privacy standards applied to big data information collection. Companies collecting health and other personal data should be more transparent about their collection and use of data, and the U.S. should consider a new data-protection authority to replace the country's fragmented privacy protections, the study's authors said.

"While we need to do everything possible to educate and empower consumers to take control of their personal data, we cannot expect individuals to bear the entire burden of managing their privacy ini the big-data era," the study says.

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Most Popular Reviews

Latest News Articles


PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?