Consent or Deletion: Samsung Health and the Rise of Coerced Data Consent
Your heart rate. Your sleep patterns. Your step count. Your menstrual cycle. Samsung Health holds some of the most intimate data your body produces. So when the app reportedly started framing a choice as “agree to let us train AI on your data, or we’ll delete it,” a lot of people rightly stopped scrolling. Slap the word “consent” on a screen all you want. If saying no means losing years of records, that isn’t much of a choice.
What actually set this off
The problem isn’t AI training itself. It’s the condition attached to it.
Normally, consenting to AI training is an optional extra. You decline, and the app keeps working exactly as before. That’s how it’s supposed to go. But the structure at the center of this controversy is different: refuse the AI training request, and your access to — or the retention of — the health data you’ve already accumulated is reportedly put at risk.
Picture a bank pulling the same move. “Agree to let us use your transaction history to build new products. Refuse, and we’ll close your account.” That’s bundling your right to use the service with your consent to have your data exploited. Legally and ethically, those are two entirely separate things, and mashing them into one button is the whole issue.
“Freely given” is the principle being bent
Privacy law has a load-bearing idea baked into it: consent has to be freely given. Europe’s GDPR spells this out explicitly. If you make access to a service conditional on consent that isn’t actually necessary to provide that service, regulators are instructed to treat that consent as suspect — not freely given.
This is where the term “forced consent” comes in. You’ll also hear it called a take-it-or-leave-it model. The logic is simple: if a user has no real alternative, the fact that they tapped “I agree” doesn’t make it genuine agreement. It makes it surrender. Samsung Health’s reported approach lands squarely on that line, because it holds a concrete loss — the deletion of your data — as leverage.
Why health data raises the stakes
Not all data carries the same weight, and health data sits near the top of the sensitivity scale. Most privacy regimes — GDPR’s “special category data,” HIPAA-adjacent protections in the US, Korea’s own sensitive-information rules — treat it with heightened scrutiny for one blunt reason: once it leaks or gets misused, you can’t undo it.
There’s a second trap: health data doesn’t port. Hate a social network? Delete it, switch to another, move on. But three years of sleep logs, workout history, and resting-heart-rate trends can’t meaningfully be carried into a rival app. The moment a company understands that asymmetry, your bargaining power evaporates. That’s exactly why the threat to delete stings — the switching cost is doing the coercing.
The new default of the AI era
Reading this as one app’s misstep undersells it. It’s closer to a flare going up over the whole field.
As the generative-AI race intensifies, every platform is parched for training data. And the easiest reservoir is the one already sitting inside the company’s own services: your records. In the old model, data reuse was quietly buried in the terms of service and left there. The new model goes a step further — it engineers the consent, either by nudging you structurally toward “yes” or, as here, by attaching a penalty to “no.” On the surface it says “the choice is yours.” Underneath, the design is built to produce one specific answer. There’s a name for that: a dark pattern.
What you can actually do right now
Anger is fair, but leverage is better. Three practical moves.
First, read the consent screen instead of reflex-tapping “Agree to all.” Check whether AI-training consent and basic app functionality are genuinely separated, or deliberately fused.
Second, back up your data. With Samsung Health or any health app, exporting your records on a schedule strips most of the weight out of a deletion threat. No hostage, no ransom. Third, if it crosses a line, file a complaint — Korea’s PIPC, an EU data protection authority, or your local regulator. Enforcement almost always starts with users making noise.
The takeaway
The real stakes here aren’t about Samsung specifically. They’re about whether “consent or deletion” gets to quietly become an industry standard. How much are we expected to hand over as the price of a convenient app — and why is it always the company, never us, that gets to set that price? The next time an app slides a consent button in front of you, it’s worth holding that question in your head for a second before you tap.
Comments
Loading comments...