Privacy protections for wearable devices are weak, study says

Wearables are collecting a huge amount of personal information, but regulations are lax, privacy groups say

The rapidly expanding wearable device market raises serious privacy concerns, as some device makers collect a massive amount of personal data and share it with other companies, according to a new study.

Existing health privacy laws don't generally apply to wearable makers, the study says. While consumers are embracing fitness trackers, smart watches, and smart clothing, a "weak and fragmented" health privacy regulatory system in the U.S. fails to give consumers the privacy protections they may expect, said the study, released Thursday by the Center for Digital Democracy and the School of Communication at American University.

"Many of these devices are already being integrated into a growing Big Data digital health and marketing ecosystem, which is focused on gathering and monetizing personal and health data in order to influence consumer behavior," the study says. 

As consumers buy more smart wearables and the devices' functionality becomes increasingly sophisticated "the extent and nature of data collection will be unprecedented," the study adds.

"Americans now face a growing loss of their most sensitive information, as their health data are collected and analyzed on a continuous basis, combined with information about their finances, ethnicity, location, and online and off-line behaviors," said Jeff Chester, CDD's executive director and co-author of the report. "Policy makers must act decisively to protect consumers in today's big data era."

In the U.S., privacy law is piecemeal, with separate laws for different types of information, such as financial, student, or health data, the study notes. U.S. privacy laws governing health information are "limited and fragmented, with significant gaps in coverage," the study says. "The degree to which users of wearable devices will be able to make informed privacy decisions ... will ultimately depend on the effectiveness of government and self-regulatory policies."

While wearable users may believe health information collected by the devices are protected by the U.S. Health Insurance Portability and Accountability Act (HIPAA), that's not the case, Chester said by email.

HIPAA applies only to so-called covered entities, basically health-care providers like doctors and hospitals, he said. "These consumer wearable devices aren’t covered by HIPAA and the marketing that goes on has no protections," Chester added.

In a June report, the U.S. Department of Health and Human Services noted that "health information is increasingly collected, shared, or used by new types of organizations beyond the traditional health care organizations" covered by HIPAA.

A spokeswoman for fitness tracker maker Fitbit noted the company has worked with privacy group the Center for Democracy and Technology to define privacy best practices for wearables. The company believes users should control their data, she said.

"Fitbit is committed to protecting the privacy of our users' data and the trust of our customers is paramount," Fitbit said in a statement. "It has always been our policy not to sell user data."

Wearable maker Apple didn't immediately respond to a request for comment on the report.

The authors of the study called for new privacy standards applied to big data information collection. Companies collecting health and other personal data should be more transparent about their collection and use of data, and the U.S. should consider a new data-protection authority to replace the country's fragmented privacy protections, the study's authors said.

"While we need to do everything possible to educate and empower consumers to take control of their personal data, we cannot expect individuals to bear the entire burden of managing their privacy ini the big-data era," the study says.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Grant Gross

IDG News Service
Show Comments

Brand Post

Most Popular Reviews

Latest Articles


PCW Evaluation Team

Luke Hill


I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?