Samsung Health AI Training Controversy: Refuse Data Consent, Lose Your Health Records
Samsung Health AI Training Controversy…
Samsung Health threatens to delete user health records if they refuse AI training data consent.
Samsung Health is facing backlash for a policy that threatens to delete users' entire health history if they refuse to authorize their data for AI model training. This "agree or lose everything" approach is being criticized as coerced consent, raising serious compliance concerns under GDPR and CCPA, and highlighting the growing tension between Big Tech's AI data hunger and users' fundamental privacy rights.
Overview
Samsung Health's recent privacy policy update has sparked widespread controversy. According to a Hacker News discussion (163 upvotes, 47 comments), Samsung Health is using a highly contentious approach when requesting user consent for AI training data: if users refuse to allow their personal health data to be used for AI model training, the app threatens to delete their entire accumulated health history.
This "agree or get out" bundling strategy forcibly ties AI training data consent to core service functionality, directly crossing the line on data privacy and user rights. For users who have long relied on Samsung Health to track workouts, sleep, heart rate, and other health metrics, this amounts to data hostage-taking.
The Core Dispute: What Is "Bundled Consent"?
Why Coerced Consent Is Unacceptable
A fundamental principle in data privacy is that user consent must be "freely given." This is a core requirement of GDPR and other mainstream privacy regulations.
The General Data Protection Regulation (GDPR), which came into force in the EU in May 2018, is one of the world's strictest data privacy laws. Article 7(4) explicitly states that when consent to data processing is bundled with the performance of a contract, and that data processing is not necessary for fulfilling the contract, such consent cannot be considered freely given. The legislative logic behind GDPR is that in relationships where there is a clear power imbalance between companies and users, "consent" can easily become a tool for superficial compliance. GDPR therefore requires consent to meet four conditions: freely given, specific, informed, and unambiguous. If any one of these is missing, the consent is invalid and the related data processing is unlawful.
When a company bundles a non-essential data processing activity (such as AI model training) with the availability of core services, the user's "consent" loses its voluntary nature and becomes coerced consent.
Samsung's current approach is a textbook example. Recording, viewing, and exporting health data should be basic functions of Samsung Health, with no inherent connection to whether that data is used for AI training. Yet Samsung has forcibly bundled the two, compelling users to choose between "providing their data" and "losing years of records."
Why Health Data Deserves Extra Protection
Health data is among the most sensitive categories of personal information. Under the GDPR framework, it is classified as "special category data," and processing it requires a stricter legal basis and more explicit user authorization.
Specifically, GDPR Article 9 places health data alongside genetic data, biometric data, and racial information in this special category, prohibiting its processing in principle — with processing only permissible in clearly defined exceptional circumstances (such as explicit user consent or public health interests). Behind this classification is lawmakers' deep recognition of health information's "highly sensitive nature": if health data is leaked or misused, it can lead to employment discrimination, insurance denial, social stigma, and other serious consequences — far exceeding the harm caused by ordinary personal information. In the United States, while there is no unified federal consumer health privacy law (HIPAA primarily governs medical institutions), states like California and Washington have enacted dedicated health data protection legislation imposing additional restrictions on consumer health app data collection.
Heart rate, sleep patterns, exercise history, weight changes — this data not only concerns personal privacy but can also be used to infer health conditions, lifestyle habits, and even potential disease risks. Incorporating such highly sensitive data into AI training pipelines by default requires an extremely high level of transparency and user trust as a prerequisite.
Why Tech Giants Are Hungry for Training Data
The AI Race Fuels "Data Hunger"
Samsung's move reflects a broader reality: in the AI race, tech giants are desperately hungry for high-quality training data. As large-scale models and vertical AI applications proliferate, real-world, structured user data has become a scarce resource. Health data, with its strong continuity, clear structure, and high information density, is ideal raw material for training health-focused AI models.
Samsung officially launched its Galaxy AI strategy in 2024, deeply integrating generative AI capabilities into core Galaxy device features — including real-time call translation, Circle to Search, and AI image editing, among others. In the health domain, Samsung's ambitions are particularly evident: the goal is to transform the Galaxy Watch and Health app into a "health co-pilot" capable of delivering personalized health insights, early anomaly detection, and chronic disease management guidance. The central challenge in achieving this vision is building the high-quality, large-scale, cross-population health datasets required for model training. Compared to building a data collection infrastructure from scratch, directly leveraging the historical health records of hundreds of millions of existing Galaxy users is the lowest-cost, highest-quality path — and that is the underlying commercial logic behind Samsung's willingness to risk reputational damage with such an aggressive consent strategy.
The Imbalance Between Commercial Interests and User Rights
A company's commercial interests should never come at the expense of users' basic rights. The sophistication of Samsung's strategy lies in its precise exploitation of the behavioral economics concept of the Sunk Cost Fallacy. Years of workout logs, sleep data, and heart rate trends accumulated in Samsung Health have already come to represent a psychologically valuable "personal health record" for users. Faced with the threat of deletion upon refusal, users' emotional attachment to and practical reliance on that historical data subconsciously suppresses their rational resistance.
This design of treating data as a "hostage" belongs to the same ethical spectrum as subscription services that say "cancel and lose all your points" — but because it involves highly sensitive health information, its manipulative nature is far more egregious, going well beyond the typical gray area of product design.
This approach drew sharp criticism from the Hacker News community, with many tech professionals arguing that it has crossed the line of acceptable data practices.
Legal and Compliance Risk Analysis
Potential Violations Across Multiple Jurisdictions
Samsung's policy faces compliance risks in multiple jurisdictions:
- EU GDPR: Explicitly requires that consent be freely given and prohibits bundling service provision with consent (Article 7(4))
- US California CCPA/CPRA: California's Consumer Privacy Act (CCPA) took effect in 2020, and its upgraded version, the California Privacy Rights Act (CPRA), was fully implemented in 2023. CPRA separately classifies "sensitive personal information" as a protected category, explicitly including health and medical information. CPRA grants consumers a "right to limit" the use of sensitive information — users can require companies to restrict the use of sensitive data to what is necessary to provide the requested service, prohibiting secondary marketing use or sharing with third parties. As a tech giant with annual revenues exceeding $100 billion, Samsung is unquestionably subject to these compliance requirements.
- Health Data-Specific Regulations: Some jurisdictions impose additional protection requirements specifically for health-related data
If regulators determine that Samsung's "refuse and delete" strategy constitutes coerced consent, Samsung will face the dual pressure of investigation and penalties.
The Long-Term Cost to User Trust
More far-reaching than legal risk is the erosion of user trust. In contrast to Samsung's aggressive strategy, the industry already has several comparatively restrained data governance practices. Apple's Health platform has long maintained a policy of storing health data on users' local devices, with cloud sync handled via end-to-end encryption, and has explicitly stated it does not use user health data for advertising or AI training purposes — a position that has become an important brand asset in its competitive differentiation. Garmin and Fitbit (now part of Google) also maintain the basic principle of not bundling core functionality with AI training consent.
User trust in the health tracking space is essentially a fragile "privacy contract" — users exchange their body data for health insights, with the premise that the data won't be used for purposes beyond their expectations. A health app's core competitive advantage lies in users' willingness to entrust it with their most private physical data. Samsung's decision to break this implicit contract may accelerate user migration toward competitors with clearer privacy stances, causing irreparable damage to Samsung's long-term health ecosystem.
User Action Guide
Faced with this Samsung Health policy change, affected users can take the following steps:
- Export your data immediately: Before making any decision, prioritize backing up all health records using the app's built-in data export function
- Carefully evaluate the scope of consent: Read the privacy policy thoroughly to clearly understand how your data will be used and shared
- Assess alternative products: If you're dissatisfied with current privacy practices, consider other health tracking apps with more transparent data handling
- Actively exercise your data rights: In regions where GDPR and similar regulations apply, users have the legal right to access, export, and delete their data
Conclusion
The Samsung Health incident is a defining example of the data ethics dilemma of the AI era. As tech giants' appetite for training data continues to grow, finding a genuine balance between commercial interests and user rights has become an unavoidable challenge for the entire industry.
A healthy path for AI development should be built on transparent, voluntary, and revocable data authorization — not on bundling and coercion to forcibly extract data. The widespread controversy Samsung has ignited may well become an important inflection point that pushes the industry to reassess its data practices. Users' data sovereignty should not become a casualty of the AI arms race.
Related articles

From Chat to Agent: Automating Your Entire Business Workflow with AI Agents
Veteran AI practitioner Remy breaks down the leap from chat models to AI agents: how agents work, the three pillars of context, tools, and skills, MCP connections, and hands-on architecture to make you a 100x employee.

Understand Anything: The AI Skill That Turns Code into Interactive Knowledge Graphs
Understand Anything is a high-star open-source GitHub skill that runs static analysis on any codebase and generates interactive knowledge graphs. It supports Claude Code, Cursor, Copilot and other agents, letting engineers ask questions in natural language with path references.

Kimi K3 Released: How a 2.8 Trillion Parameter Open Model Reshapes AI Cost-Effectiveness
Moonshot AI unveils Kimi K3: a 2.8 trillion parameter, 1M context, natively multimodal open model. With KDA architecture and ultra-low cost, it rivals GPT-5.6 and Fable 5, redefining AI cost-effectiveness.