Privacy & Compliance · Study deck

Privacy vs Security in IoT

Privacy limits what connected devices collect, infer, keep, and share, even when access is secure.

Privacy Priya is your guide for this deck.

Introduction To Privacy cover: Priya separating identity tokens from useful sensor readings with privacy controls.
iotclass.org

After studying this chapter

Learning objectives

A privacy review connects the purpose of sensing with limits people can understand.

  • Privacy must bound authorized collection and use.The lock can reject fake credentials while still keeping more arrival history than its door-protection purpose requires.
  • Connected readings can reveal routines through patterns.Timing, location, and device state may expose household behavior even when no direct name is stored.
  • Controls must include people without app accounts.Visitors, care workers, and other bystanders still need understandable sensing boundaries and practical ways to raise questions.
  • A privacy decision needs evidence and a responsible owner.The review record connects each purpose and control to a test, ownership, and a condition for renewed review.

I am reviewing a smart lock that records every arrival in a shared home. I need to justify the history as well as protect access to the lock.

iotclass.org

Major section

A Door Lock Is Not a Curtain

A secure smart lock can still keep more arrival history than its purpose needs.

  • Door protection does not justify every household record.A forced-door warning can be useful without creating a permanent map of family, visitor, and care-worker routines.
  • The user benefit must justify each stored field.Purpose, time detail, receiver, allowed use, and storage period need to be recorded before data enters the path.
  • People beyond the account holder need understandable boundaries.Visitors and care workers can be sensed even though they never opened or configured the app.
  • Optional sharing choices must preserve urgent local protection.Turning sharing off should reduce collection or use while keeping the door safety behavior the resident still needs.

I am watching residents, visitors, and care workers enter the shared home. I keep urgent door protection available while asking which arrival details the feature actually needs.

iotclass.org

Major section

Testing a Choice Across Every Copy

Test a privacy choice by following the next event through every stored copy.

  • A new event can test whether a choice takes effect.The one-room review disables an optional use, then checks what happens when another person enters.
  • The data path can hold several independent copies.The device, app, service, report, backup, and partner route all need evidence of the intended collection or retention limit.
  • A changed setting is not enough evidence by itself.Collection or sharing can continue elsewhere unless the next event is checked across the complete data path.
  • Changed purpose or sharing must reopen the review.A new receiver, field, place, time detail, or storage period can alter the original privacy decision.

I am switching off one optional use and generating another arrival event. I follow that event through the device, app, backups, and partner route to check the choice.

iotclass.org

Major section

Why Privacy Is Different from Security · Why IoT Raises the Stakes

The comparison separates access protection from data-use limits; begin with the security controls.

  • Security must control access and system behavior.Authentication, encryption, patching, and network controls can protect against unauthorized access, tampering, loss, and disruption.
  • Privacy controls which data uses are justified.Collection, inference, retention, and sharing need purpose limits even when an authorized system can access the record.
  • Accountability connects the two disciplines.Both privacy and security decisions need owners, tests, exceptions, and review triggers in the evidence record.
  • Authorized access can still support an unjustified use.The secure lock’s arrival history may exceed the agreed purpose when it is shared or retained indefinitely.
Privacy and security comparison showing security access control, privacy data control, shared accountability, and user trust.
Privacy and security comparison showing security access control, privacy data control, shared accountability, and user trust.
iotclass.org

Major section

Privacy Across Device Tiers

Device visibility changes how people discover sensing and exercise control.

  • Visible devices can still have hidden data destinations.Phones and watches are noticeable, while app, library, and third-party flows may remain difficult for the person to see.
  • Appliances combine visible hardware with less visible services.Accounts, automations, support access, and cloud relationships can sit behind a thermostat or speaker in a shared home.
  • Small sensors can observe people without attracting attention.Badges, tags, and building sensors may have little direct interaction while collecting a detailed record over time.
  • Notices and controls must fit the device’s visibility.A permission prompt can suit a phone, while a small environmental sensor may need a nearby notice and contact route.

I am comparing a phone, a household appliance, and a small building sensor. I ask what the person can notice before choosing how to explain sensing and control.

iotclass.org

Major section

Hidden Services Behind Visible Hardware

Review the hidden service paths behind a visible device.

  • Phone reviews must expose app and library behavior.Permissions, destinations, retention, and third-party SDK paths belong in the review even when the device itself is obvious.
  • Household devices need clear account and support roles.Automation, remote support, and shared-household use can change who handles data from otherwise familiar hardware.
  • The physical indicator must agree with the app’s controls.A person needs to understand what is sensing or sharing from the device state as well as the settings page.
  • Local fallback and partner sharing need separate boundaries.The review must connect practical controls to cloud services while retaining the local behavior people still need.

I am reviewing the app behind a visible household device. I connect its physical indicator to account roles, cloud services, and sharing choices so the controls are understandable.

iotclass.org

Major section

Making Small Sensors Noticeable

Small sensors need nearby signs that make sensing understandable before collection begins.

  • Many unobtrusive sensors can reveal detailed movement patterns.Tags, badges, and building sensors may combine low visibility with scale and long operating lifetimes.
  • Nearby notices can explain sensing without a device screen.A room notice, label, or status light can make a small environmental node’s collection visible before an app is opened.
  • A public map or contact route can support bystanders.People who did not configure the sensor still need a way to learn what is sensed and who operates the device.
  • The record must explain how people can challenge collection.Objection, pause, and explanation routes need to work for visitors and workers as well as the device owner.

I am entering a shared room with small environmental sensors. I look for a notice, visible label, or owner contact before expecting a visitor to understand the collection.

iotclass.org

Major section

Awareness, Defaults, and Product Labels · The First Privacy Questions

The question chain starts with data and purpose, then reaches controls and review evidence.

  • The first questions connect data with purpose and people.The review identifies what is collected or inferred, why it is needed, and who can be affected.
  • Actors and duration define the wider data path.Receivers, sharing destinations, and raw-data retention need to be visible before a technical safeguard is selected.
  • Controls must give people practical choices.The person’s ability to see, change, export, delete, pause, or limit data belongs beside the supporting safeguards.
  • Evidence must show that the stated boundaries work.The final record needs a proving test and a change that will reopen the decision after launch.
First IoT privacy review questions showing data, purpose, people, actor, duration, sharing, control, safeguard, and evidence.
First IoT privacy review questions showing data, purpose, people, actor, duration, sharing, control, safeguard, and evidence.
iotclass.org

Major section

Inference Risk · Watch the Pattern, Not Only the Field

The inference path turns readings into personal insights; start at the individual measurements.

  • Repeated readings can become revealing patterns.Timing and context connect individual events before the system draws an insight about a person or household.
  • A pattern can reveal occupancy without a stored name.Repeated device behavior may show when someone is home, asleep, or away from the sensed space.
  • Personal insights can enable unwanted uses.The diagram connects inferred routines with risks such as prediction, targeting, or surveillance beyond the original purpose.
  • The review loop must reduce unnecessary exposure.Less detail, lower frequency, shorter retention, reduced linkage, or limited access can restrict the patterns available for inference.
Inference path showing readings becoming patterns, patterns becoming insights, insights creating risk, and review reducing exposure.
Inference path showing readings becoming patterns, patterns becoming insights, insights creating risk, and review reducing exposure.
iotclass.org

Activity 1 · Draw it

✎ Trace an inference

I want you to find where an ordinary reading becomes a revealing pattern.

Sketch the path from smart-lock arrival readings to a household routine and a privacy risk. Mark where less detail or shorter retention could reduce exposure.

3 minutes · Pen and paper · Answer: Activity 1

Your answer
iotclass.org

Major section

Data Minimization Lever: Sampling Rate

Choose the coarsest meter readings that still support the billing purpose.

  • Fine sampling can expose appliance behavior despite encryption.One sample per second can make kettle, refrigerator, or television signatures distinguishable to an authorized data holder.
  • Coarser readings can still support the billing purpose.One sample per 15 minutes can support time-of-use billing while remaining too coarse to identify most individual appliances.
  • The sampling choice changes the amount of retained detail.The chapter compares roughly 2.6 million samples per month with about 2,880 samples at the coarser rate.
  • Minimization removes information that encryption leaves available.A stronger cipher does not prevent the authorized utility from analyzing detailed decrypted readings that were collected without a necessary purpose.

I am reviewing the encrypted smart meter’s billing purpose. I compare one-second readings with 15-minute totals before deciding how much appliance detail should exist.

iotclass.org

Major section

Metadata and Re-Identification Limits

Encrypted payloads still leave observable traffic patterns.

  • Event-triggered packet timing can reveal motion.A transmission that occurs only when the sensor fires can disclose presence through its arrival time alone.
  • Message size and frequency can expose activity.Observable traffic patterns may distinguish device types and behavior even when every payload remains encrypted.
  • An observer does not need decryption to learn from metadata.The privacy-relevant information may be when packets appear rather than the content protected by the cipher.
  • Privacy review must include the traffic pattern.Timing, size, and rate belong beside collected fields when reviewing what the complete sensing path can reveal.

I am watching an encrypted motion sensor that transmits only when it fires. I can review the visible packet pattern without reading the protected payload.

iotclass.org

Major section

Nameless Records Can Remain Identifying

Removing direct names does not erase the identifying pattern in a behavioral trace.

  • Unique routines can reconnect records across datasets.A nameless behavioral trace can still be linked to identity through correlation with other identifying information.
  • Timing and location can distinguish a household.Removing direct names does not remove the repeated device behavior that makes a particular record recognizable.
  • Reducing uniqueness can limit re-identification risk.Aggregation, generalization, or added noise can reduce the identifying detail that remains after obvious identifiers are removed.
  • An anonymity claim needs evidence about remaining patterns.The review must test whether a person, household, or role can still be singled out from the behavioral trace.

I am reviewing a behavioral trace after its name column is removed. I check whether its locations and timing can still connect the record to a household.

iotclass.org

Major section

The Privacy Learning Route · Baseline Standards for IoT Review

The learning route builds on fundamentals; follow each stage toward enforceable boundaries.

  • The opening stages establish data flows and purpose boundaries.Introduction and fundamentals connect vocabulary, minimization, retention, and accountability to the same review record.
  • Principles and mapping are foundations for engineering choices.The route then covers regulation mapping, privacy techniques, and mobile exposure before the later design stages.
  • Design and safeguards must make boundaries enforceable.Privacy by Design changes architecture, while safeguards and zero trust make access and trust boundaries observable.
  • Every stage must contribute review evidence.The learning order does not postpone governance; each step strengthens the decision, its controls, and its supporting record.
Privacy learning route showing introduction, fundamentals, principles, regulation mapping, techniques, mobile privacy, privacy by design, safeguards, and zero trust.
Privacy learning route showing introduction, fundamentals, principles, regulation mapping, techniques, mobile privacy, privacy by design, safeguards, and zero trust.
iotclass.org

Major section

Simple Review Example · Compact Rule

The record links a room-sensor purpose to a tested control; read from feature to review trigger.

  • The record begins with the lighting feature and its purpose.Motion state, room identifier, timestamp, and device status support immediate lighting and area-level facility planning.
  • Local processing and summaries can reduce workplace tracking.The room sensor must upload area summaries, suppress small groups, avoid user-level tracking, and delete raw events quickly.
  • The person’s control must connect to a safeguard and test.Notice, a contact path, and review of new analytics make the stated privacy boundary challengeable in practice.
  • The final fields must assign ownership and renewed review.A named owner must revisit changes to data, purpose, destination, or behavior rather than freezing the record at release.
Privacy review record with fields for feature, data, purpose, control, safeguard, test, owner, and review trigger.
Privacy review record with fields for feature, data, purpose, control, safeguard, test, owner, and review trigger.
iotclass.org

Activity 2 · Label it

✎ Complete the room-sensor record

I want you to connect each privacy promise to a record someone can check.

Draw five boxes labelled purpose, data, privacy decision, control, and evidence. Fill them for the room sensor that controls lights and supports facility planning.

4 minutes · Pen and paper · Answer: Activity 2

Your answer
iotclass.org

Deck summary

Key takeaways

A useful privacy decision limits data and proves that the limit works.

  • Access protection and justified use answer different questions.A secure lock or meter can still retain or expose more behavioral detail than the stated purpose needs.
  • Collection must match the required detail and history.The meter’s billing example uses coarser readings instead of storing appliance-level traces merely because the hardware can sample faster.
  • The review must cover people and evidence beyond obvious fields.Inference, metadata, backups, partner copies, and bystanders can remain relevant even when direct identifiers are absent.
  • Controls need tests and an owner for future changes.Purpose, data fields, summary logic, retention, responsibility, and review triggers keep the privacy decision usable after launch.

I am closing the room-sensor review with the lighting purpose still clear. I keep only the required detail and make the notice, retention decision, and owner testable.

iotclass.org

Retrieval practice

Recall check 1 of 5

Privacy Priya says: answer from memory, then check your reasoning.

Q1A meter for time-of-use billing currently samples once per second, exposing appliance-level behavior. Which change most reduces the privacy risk while still serving billing?

AKeep one-second sampling but use a stronger encryption algorithm.
BKeep the data but rename the account holder field.
CLower the sampling rate to the coarsest that billing needs.
DCollect additional sensors to add context.
Show answer

Answer: C Data minimization matches granularity to purpose.

iotclass.org

Retrieval practice

Recall check 2 of 5

Privacy Priya says: answer from memory, then check your reasoning.

Q2A motion sensor encrypts its payloads but only transmits when it detects movement. How can an eavesdropper who cannot decrypt anything still learn when someone is home?

APacket timing reveals motion events even when payloads stay encrypted.
BThe eavesdropper must have broken the encryption.
CThe sensor is leaking plaintext despite the encryption.
DMetadata carries no information once payloads are encrypted.
Show answer

Answer: A This is metadata leakage.

iotclass.org

Retrieval practice

Recall check 3 of 5

Privacy Priya says: answer from memory, then check your reasoning.

Q3A smart home product encrypts all sensor data but keeps detailed room-by-room behavior history forever. What is still missing from the privacy review?

APurpose, minimization, retention, and control.
BNothing. Encryption fully solves privacy.
COnly a faster network connection.
DA larger data store for future analysis.
Show answer

Answer: A Security controls and privacy controls overlap, but they answer different questions.

iotclass.org

Retrieval practice

Recall check 4 of 5

Privacy Priya says: answer from memory, then check your reasoning.

Q4A smart meter encrypts every reading end to end, yet the utility can tell when the household sleeps and which appliances run. How is this possible?

AEncryption only stops unauthorized access
BThe encryption must have been broken by an attacker.
CSmart meters cannot be encrypted, so the data is plaintext.
DStronger encryption would remove the behavioral inference.
Show answer

Answer: A The utility decrypts the data as an authorized party.

iotclass.org

Retrieval practice

Recall check 5 of 5

Privacy Priya says: answer from memory, then check your reasoning.

Q5Why can a device-state log be privacy-relevant even if it does not store names?

APatterns reveal routines, occupancy, and behavior.
BOnly names count as personal data.
CState logs never leave the device.
DPrivacy applies only to payment records.
Show answer

Answer: A IoT data can become privacy-relevant through repeated patterns and context, not only through direct identifiers.

iotclass.org

Print reference

Answers

Answer key.

  1. C · Data minimization matches granularity to purpose.
  2. A · This is metadata leakage.
  3. A · Security controls and privacy controls overlap, but they answer different questions.
  4. A · The utility decrypts the data as an authorized party.
  5. A · IoT data can become privacy-relevant through repeated patterns and context, not only through direct identifiers.
iotclass.org

Print reference

Activity 1 answer

Model answer.

Draw it: Model sketch: arrival readings → repeated timing pattern → household routine → unwanted targeting or surveillance. Reducing time detail or retaining fewer events limits the pattern available for inference.

iotclass.org

Print reference

Activity 2 answer

Model answer.

Label it: Purpose: immediate lighting and area trends. Data: motion state, room identifier, timestamp, device status. Decision: local processing, area summaries, small-group suppression, quick raw deletion. Control: notice and contact path. Evidence: summary logic, retention decision, owner, and review trigger.

iotclass.org