UX Design · Study deck
IoT Privacy: User Rights and Privacy by Design
A user agreed to a clear purpose and the product collects only what it needs.
UX Uma is your guide for this deck.

After studying this chapter
Learning objectives
You will be able to:
- Explain: the battery explained: "Sammy, imagine if someone followed YOU around writing down everything you did -- where you went at recess, who you talked to, what you ate for lunch.
- Explain: Scenario: A smart baby monitor startup must implement GDPR-compliant consent for their video/audio streaming product sold in the EU.
- Explain: You now know why access, erasure, portability, restriction, and objection need workflows across device, gateway, cloud, backup, and processor systems.
- Explain: Portability is achieved when the record can move and retain its meaning, not merely when a download button produces bytes.
Major section
User Rights in IoT Systems
IoT systems must implement mechanisms to fulfill these rights.
- Portability is achieved when the record can move and retain its meaning, not merely when a download button produces bytes.
Major section
Checkpoint: Rights Handling
You now know why access, erasure, portability, restriction, and objection need workflows across device, gateway, cloud, backup, and processor systems.
- You now know why deletion must cover production records, backup rotation, third-party processors, device caches, and user-visible timelines.
- Rights workflows prove whether privacy controls survive beyond the dashboard.
- The next design question is how to embed those controls before launch instead of bolting them on after complaints.
Major section
Checkpoint: Privacy by Design
You now know how proactive design, privacy defaults, embedded controls, transparency, and user-centric choices translate into IoT architecture.
- You now know why a Privacy Impact Assessment must challenge sensors, data flows, necessity, risks, mitigations, and documentation before release.
- Privacy by Design sets the architecture.
- The next section stress-tests that architecture against the ambient, inferential, and multi-party realities of connected spaces.
Major section
GDPR Consent for Baby Monitors
Freely Given: Each optional feature has independent checkbox (not bundled).
- Scenario: A smart baby monitor startup must implement GDPR-compliant consent for their video/audio streaming product sold in the EU.
- Setup screen shows: "To use BabyCam Pro, you agree to our Privacy Policy and Terms of Service. [Continue]".
- Sleep insights will stop.
Major section
GDPR Consent for Baby Monitors (continued)
Sends confirmation email: "Your data has been deleted as of [timestamp]".
- Not Freely Given: Consent bundled with service—can't use monitor without agreeing to everything.
- Not Specific: Single "agree to all" for 4 different data uses.
- Informed: Plain language explains what, who, how long.
- This change takes effect immediately.".
Major section
GDPR Consent for Baby Monitors (continued)
Easy withdrawal prevents lock-in resentment.
- Account will be closed.".
- Risk Avoided: €20M (4% of revenue) or €10M GDPR fine (whichever is higher).
- Granular consent controls respect user autonomy.
- The cost of compliance ($80K) is tiny compared to the cost of non-compliance (€10-20M fine + reputational damage).
Major section
Deep dive: Lawful Basis for IoT Data
GDPR requires one of six lawful bases for processing personal data.
- Using Legitimate Interest for Surveillance: ✗ "We have legitimate interest to record all your conversations for product improvement".
- Using Contract Performance for Marketing: ✗ "You bought our thermostat, so we can email you ads".
- Problem: Marketing is NOT necessary to fulfill the contract.
Major section
For Kids: Meet the Sensor Squad!
"No way!" said Sammy. "That would be creepy!".
- The Sensor Squad had built an amazing classroom helper that tracked how much each student participated.
- "Hey!" said student Maya. "I didn't say you could watch me all day!
- If Maya says no, she should still get the same education.
Major section
For Kids: Meet the Sensor Squad! (continued)
Temperature Terry was confused. "But I'm helping the teacher know who needs more encouragement!".
- the battery explained: "Sammy, imagine if someone followed YOU around writing down everything you did -- where you went at recess, who you talked to, what you ate for lunch.
- the LED added the most important rule: "And 'No' must be a real option!
- Consent means you have a REAL choice, not 'agree or else!'".
Deck summary
Key takeaways
IoT systems must implement mechanisms to fulfill these rights.
- You now know why access, erasure, portability, restriction, and objection need workflows across device, gateway, cloud, backup, and processor systems.
- You now know how proactive design, privacy defaults, embedded controls, transparency, and user-centric choices translate into IoT architecture.
- Freely Given: Each optional feature has independent checkbox (not bundled).
- Sends confirmation email: "Your data has been deleted as of [timestamp]".
Retrieval practice
Recall check 1 of 5

UX Uma says: answer from memory, then check your reasoning.
Q1A user exercises their GDPR right to erasure ('right to be forgotten') with a smart home company. The company deletes their account data from the production database. Three months later, the user discovers their data still exists in the company's backup systems and was shared with a cloud analytics provider. What should the company have done?
Show answer
Answer: C Correct!
Retrieval practice
Recall check 2 of 5

UX Uma says: answer from memory, then check your reasoning.
Q2A user wants to switch from SmartWatch Brand A to Brand B. They request their fitness data under GDPR's data portability right. Brand A provides a download containing: step counts, heart rate measurements, and sleep data. However, Brand A's proprietary 'wellness score' algorithm output is not included. Is this compliant with data portability requirements?
Show answer
Answer: B Correct!
Retrieval practice
Recall check 3 of 5

UX Uma says: answer from memory, then check your reasoning.
Q3During a Privacy Impact Assessment for a smart city traffic monitoring system, the team identifies that license plate recognition could enable tracking individual vehicles across the city. The project manager argues: 'We're only using it for aggregate traffic flow analysis, not individual tracking.' How should the privacy team respond?
Show answer
Answer: C Correct!
Retrieval practice
Recall check 4 of 5

UX Uma says: answer from memory, then check your reasoning.
Q4A research team publishes a dataset of 'anonymized' smart meter readings from 5,000 homes. They removed all customer IDs and addresses, keeping only timestamps and energy consumption values. A privacy researcher claims this data can be re-identified. Which attack is most likely to succeed?
Show answer
Answer: B Correct!
Retrieval practice
Recall check 5 of 5

UX Uma says: answer from memory, then check your reasoning.
Q5Place each consent element where it lives so you can connect the user promise to a real control and an auditable record.
Show answer
Answer: A Separate what the user is told, the choice they can make, and system enforcement and evidence so you can detect consent that is only interface copy.
Q6Complete the consent form validation for an IoT privacy dashboard:
Show answer
Answer: A GDPR consent requires an affirmative action, so optional consent boxes must start unchecked and be selected by the user.
Print reference
Answers
Answer key.
- C · Correct!
- B · Correct!
- C · Correct!
- B · Correct!
- A · Separate what the user is told, the choice they can make, and system enforcement and evidence so you can detect consent that is only interface copy.
- A · GDPR consent requires an affirmative action, so optional consent boxes must start unchecked and be selected by the user.