Xiaomi Band 9 Pro Beta Enhances Message Privacy Protection: Analysis of Legal Risks and Compliance Points for User Data Security
Recently, the beta testing of a new version of the Xiaomi Mi Band 9 Pro has been initiated, with official claims that message privacy protection features will be strengthened, drawing attention from smart wearable device users to personal data security. In an era where IoT devices are widespread, wearable products such as bands and watches collect real-time data on heart rate, sleep, location, and even communication content, and the legal issues behind this cannot be ignored. From a lawyer's perspective, this article analyzes the boundaries of privacy protection for smart devices, pathways for users to defend their rights, and manufacturers' compliance obligations, with reference to the Personal Information Protection Law, the Cybersecurity Law, and other regulations.
What data do smart wearable devices collect? How does the law define the boundaries of privacy?
The functions of smart bracelets have long surpassed step counting and heart rate monitoring. Taking the Xiaomi Band 9 Pro as an example, it can receive phone notifications, display message content, and may record health metrics, exercise routes, and even payment information. According to Article 4 of the Personal Information Protection Law, personal information refers to various information recorded electronically or by other means that relates to an identified or identifiable natural person. Heart rate data constitutes sensitive personal information. Under Article 28 of the same law, the processing of sensitive personal information requires separate consent from the individual, as well as notification of the necessity and the impact on the individual's rights and interests.
In practice, device manufacturers often obtain one-time authorization through user agreements, but many users do not read the terms carefully. The law requires that "informed consent" be genuine, voluntary, and explicit; if manufacturers enable message synchronization or health data sharing by default, it may constitute a violation. In 2023, the Cyberspace Administration of China reported multiple apps for illegally collecting personal information, among which smart wearable devices were a major problem area. Lawyers remind that manufacturers should obtain authorization through prominent methods such as pop-ups and separate checkboxes, rather than hiding it in lengthy agreements.
Message Privacy Protection Beta Testing: What Compliance Obligations Do Manufacturers Have?
Xiaomi's current beta test emphasizes "enhancing message privacy protection," indicating that manufacturers have recognized that message notifications may leak sensitive content. For example, if WeChat chats or SMS verification codes are displayed directly on a smartwatch screen, bystanders can easily see them. Under Article 51 of the Personal Information Protection Law, processors must adopt technical measures such as encryption and de-identification to ensure security. When developing new versions, manufacturers need to ensure encrypted data transmission, secure local storage, and provide users with the option to disable notification previews.
Additionally, Article 21 of the Cybersecurity Law requires network operators to take measures to prevent computer viruses and network attacks. As IoT terminals, smart bands, if containing vulnerabilities, may be exploited by hackers to steal data. In 2024, a brand's smart band was exposed for a Bluetooth protocol vulnerability that led to the leakage of users' locations. Therefore, internal testing is not only for functional optimization but also for security hardening. Lawyers recommend that manufacturers conduct regular penetration testing, establish a vulnerability response mechanism, and issue patches in a timely manner.
For users, beta versions may be unstable, and privacy protection features may not be fully developed. Users participating in the beta test should carefully read the testing agreement to understand the scope of data collection. If privacy leakage risks are discovered, users may report them to the cyberspace administration authorities or seek compensation in accordance with the Consumer Rights Protection Law.
How can users use legal measures to address privacy breaches?
If the privacy function of the bracelet's message feature has defects, causing user information leakage, what rights can the user claim? First, according to Article 1034 of the Civil Code, the privacy rights of natural persons are protected by law. No organization or individual may infringe upon others' privacy through disclosure, publication, or other means. If the manufacturer fails to fulfill its security protection obligations, the user may demand cessation of the infringement, an apology, and compensation for losses.
Secondly, Article 69 of the Personal Information Protection Law stipulates that processors who handle personal information in violation of regulations and cause damage shall bear presumed fault liability. This means that users only need to prove the fact of damage, while manufacturers must prove they are without fault. For example, if a verification code is stolen due to a vulnerability in a smart bracelet and the user's deposit is lost, the user may sue the manufacturer for compensation. In 2022, a court in Beijing heard a similar case and ruled that a smart device manufacturer compensated the user with emotional distress damages for failing to encrypt stored user health data.
In practice, users often face difficulties in providing evidence. Lawyers advise that upon detecting anomalies, users should immediately take screenshots, preserve logs, and notify the manufacturer. Additionally, complaints can be filed with the Ministry of Industry and Information Technology or the Cyberspace Administration of China, as these authorities will order corrective actions. For collective incidents, consideration may be given to initiating public interest litigation; the China Consumers Association once filed public interest litigation over apps' illegal collection of information and received support from the court.
Enterprises developing smart devices: How to avoid crossing legal red lines?
For smart hardware companies, compliance is not only a legal requirement but also a market competitiveness factor. The privacy protection beta testing of the Xiaomi Band reflects an industry trend. Enterprises should adopt the "privacy by design" concept, integrating compliance requirements into the product development stage. Specifically, they must: 1. Collect minimally—only gather necessary data; for example, health monitoring does not require access to contacts permissions; 2. Provide clear notification—explain data use in plain language, avoiding "blanket" authorizations; 3. Strengthen security—use national cryptographic algorithms to encrypt data transmission and regularly audit third-party SDKs.
Additionally, Article 27 of the Data Security Law requires the establishment of a data security management system. Enterprises should appoint a data protection officer and formulate emergency response plans. If data is to be provided to overseas recipients, a security assessment must also be passed. The 2024 Regulations on Promoting and Regulating Cross-Border Data Flows further refine these requirements: smart device manufacturers that store user data on overseas servers must file a declaration in advance. Lawyers note that the cost of compliance is far lower than the price of violation, with fines of up to 50 million yuan or 5 percent of the previous year's turnover.
Lawyer's Advice: An Action Guide for Individual Users and Enterprises
For ordinary users, when purchasing a smart wristband, one should choose reputable brands, carefully read the privacy policy, and disable unnecessary permissions. During use, regularly update the firmware and avoid using public Wi-Fi to sync data. If privacy leakage is discovered, contact customer service promptly and request data deletion. In cases involving property loss, report to the police immediately and preserve evidence.
For enterprises, it is recommended to hire professional legal counsel and conduct regular compliance reviews. Guangdong Zhiming Law Firm has deep expertise in technology and data legal services, having provided data compliance solutions for multiple smart hardware companies and assisted in responding to regulatory investigations. We remind you that privacy protection is not a "beta test" feature, but a legal bottom line. Against the backdrop of tightening regulation, those who achieve compliance early will win user trust.
Privacy protection for smart wearable devices is both a technical proposition and a legal subject. The new changes in the Xiaomi Band 9 Pro serve as a wake-up call for users: every instance of data sharing should be built upon informed consent. In the face of legal risks, users must proactively defend their rights, enterprises must actively fulfill their responsibilities, and together we must build a secure digital ecosystem.