Verdict: Tier B — risk score 32/100.
Data sent to Xiaomi servers in Europe — adequate GDPR compliance.
| Device | Redmi Watch 5 Active |
|---|---|
| Privacy tier | Tier B |
| Risk score | 32/100 (lower is more private) |
| Audit date | 2026-04-29 |
| Auditor | Tomás Maria Vaz de Noronha |
| Methodology | 3-pass forensic network audit (DNS + traffic + 6-dim classification) |
| License | CC-BY-4.0 — free re-use with attribution |
| PCAP availability | Anonymised, on request to bona-fide researchers |
Data sent to Xiaomi servers in Europe — adequate GDPR compliance.
This finding is based on a 3-pass forensic network audit conducted in an isolated network environment in Lisbon, Portugal. The methodology captures every DNS query, monitors total traffic during active and idle states, and classifies each contacted domain across 6 dimensions (GDPR, surveillance, tracking, minimization, transparency, traffic-behaviour).
Sold by Ainode — Tier B (Privacy Audited). All data flows are documented and disclosed to the buyer at point of sale.
All 8 audited devices → /reviews