WASHINGTON, June 19 — A patchwork of state privacy laws passed over the past three years has closed many of the paths that once let calorie-counting and fitness apps sell what users log, but a persistent carve-out for “de-identified” data still allows some of that information to reach third-party data brokers, privacy advocates and federal regulators said this week.

The gap turns on a distinction written into most of the new statutes: data that has been stripped of direct identifiers is generally treated as outside the laws’ core restrictions, even though researchers have repeatedly shown that de-identified behavioral records can be re-linked to individuals when combined with other data sets.

“The de-identification label does a lot of work that the underlying technique often cannot support,” said Priya Nandakumar, a policy counsel at the Electronic Privacy Information Center, a Washington nonprofit. “A daily stream of meal timestamps, weight entries and location-tagged workouts is high-dimensional. It is frequently re-identifiable, and yet it can move to brokers without triggering the consent rules that apply to the raw record.”

The Federal Trade Commission has warned health-app developers that the FTC Act’s prohibition on unfair or deceptive practices applies regardless of a privacy policy’s wording, and that promises to “anonymize” data can themselves be deceptive if the data remains re-identifiable. The commission has brought several enforcement actions against health and wellness apps in recent years but has not issued a rule specifically governing de-identified logging data.

At the state level, coverage is uneven. Washington’s My Health My Data Act, which took effect in 2024, defines “consumer health data” broadly and requires separate consent before such data is shared or sold, but it, too, exempts data that has been de-identified in line with the statute’s standard. California, Connecticut, Colorado and Texas have adopted comprehensive privacy laws with their own de-identification provisions, meaning a user’s protections can vary by state of residence.

What users can do now

Advocates say the practical remedy is to use the opt-out and deletion tools the laws do provide, app by app. Most comprehensive state laws give residents the right to request deletion of their data and to opt out of its sale or of “targeted advertising.” Those requests generally must be honored within 45 days.

Nandakumar recommended three steps: submit a deletion request directly to each health app in use; opt out of sale and sharing in the app’s privacy settings, where that toggle exists; and, for residents of states that operate one, register with an authorized opt-out mechanism or a state data-broker registry. California and a handful of other states now maintain registries that require brokers to list themselves and honor bulk deletion requests.

The FTC has urged consumers to review app permissions and to treat health data as sensitive by default. “Consumers should not have to become privacy engineers to keep their own health information private,” Nandakumar said. “But until the de-identification standard is tightened, exercising these rights individually is the strongest tool most people have.”


Priscilla Goyal-Norris reported from Washington.