1. United States
  2. R.I.
  3. Letter

Protect Americans’ Wearable Health Data

To: Rep. Magaziner, Sen. Whitehouse, Sen. Reed

From: A constituent in Warwick, RI

July 29

I urge Congress to enact comprehensive federal protections for the health, biometric, activity, and location data collected by fitness wearables, including smartwatches, fitness trackers, rings, and similar devices. These products record heart rates, sleep patterns, exercise histories, stress indicators, reproductive-health information, and precise movements. Such data can reveal where people travel, when they sleep, whom they encounter, and what medical conditions they may be experiencing. Americans should not lose control of this deeply personal information merely because it was collected by a commercial device rather than a healthcare provider. Congress should require the following protections: 1 A probable-cause warrant for government access. Law-enforcement agencies should not obtain wearable health, biometric, activity, or location data through informal requests or ordinary subpoenas. Access should require a particularized warrant, except during a narrowly defined emergency involving an imminent threat of death or serious bodily injury. 2 Mandatory consumer notification. Whenever a company receives a warrant, court order, subpoena, emergency demand, or other government request for someone’s wearable data, it should notify that individual, identify the requesting agency, describe the information sought, and disclose what was provided. Courts should delay notice only upon finding a specific threat to an investigation, with any delay limited in duration and subject to renewed judicial review. 3 Public transparency reports. Wearable companies should regularly disclose the number and type of government demands received, the legal authority asserted, the number of users affected, compliance rates, rejected or challenged requests, emergency demands, and secrecy orders. 4 End-to-end encryption by default. Wearable data stored on devices, phones, company servers, cloud backups, or synchronized accounts should be encrypted so that only the consumer can access it. Companies should not retain decryption keys, and Congress should prohibit encryption backdoors. Consumers should also have a fully functional local-storage option. 5 Consumer ownership and meaningful consent. Companies should not sell, license, share, or use wearable data for advertising, insurance or employment decisions, artificial-intelligence training, or unrelated product development without specific, informed, and revocable consent. Consent must not be buried in lengthy terms of service or required to access essential product functions. 6 Data minimization and accountability. Consumers must be able to access, export, correct, and permanently delete their information. Violations should be enforceable by the Federal Trade Commission, state attorneys general, and affected individuals through a private right of action. Americans should not have to surrender bodily privacy to benefit from modern health technology. Our heart rates, sleep patterns, movements, and health indicators belong to us. Please establish a strong national privacy standard that returns control of wearable data to the people who produce it.

Share on BlueskyShare on TwitterShare on FacebookShare on LinkedInShare on WhatsAppShare on TumblrEmail with GmailEmail

Write to Seth Michael Magaziner or any of your elected officials

Send your own letter

Resistbot is a chatbot that delivers your texts to your elected officials by email, fax, or postal mail. Tap above to give it a try or learn more here!