Privacy & Compliance · Study deck

GDPR Compliance for IoT

Picture a sleep band that stores movement and place.

Privacy Priya is your guide for this deck.

safeguardsgdpr
Privacy Priya, the module guide, in a scene from this chapter.
iotclass.org

After studying this chapter

Learning objectives

You will be able to:

  • treat GDPR privacy principles as law rather than best-practice suggestions
  • run a GDPR compliance workflow covering roles, special-category data, and breach response
  • identify the failure modes that break a GDPR compliance claim
  • Explain: A friendly screen is not enough if the owner cannot learn what is held, correct a wrong fact, obtain a copy, or end an unneeded use.
iotclass.org

Major section

Start Simple

A friendly screen is not enough if the owner cannot learn what is held, correct a wrong fact, obtain a copy, or end an unneeded use.

  • Fix any step that needs hidden staff knowledge.
  • The law depends on role, place, data, and current guidance.
  • Under the Hood explains special data, organization roles, serious failures, and where expert advice is required.
iotclass.org

Major section

Overview: Privacy Principles as Law

Personal data is any information relating to an identifiable person, which for IoT includes far more than names: device identifiers, location, and sensor readings that can single someone out all count.

  • The General Data Protection Regulation, usually shortened to GDPR, is a European data protection law that turns privacy principles into binding obligations for anyone who handles the personal data of people it covers.
  • Learning GDPR's shape therefore transfers: the roles, rights, and evidence habits below recur, with local variation, across many of the regimes an IoT product might need to satisfy.
  • The party that decides why and how personal data is processed.
iotclass.org

Major section

Overview: Privacy Principles as Law (continued)

The central idea is that personal data is handled on behalf of the person it describes, called the data subject, and may be processed only with a lawful basis and within the data protection principles.

  • You are free to build, but to a published standard, with safe defaults, and you must be able to show your work to an inspector.
  • For a connected wearable, that means mapping the device sensor stream, companion app, cloud analytics, support console, and export/delete workflow as one processing system.
  • The controller carries the main accountability for meeting the obligations.
iotclass.org

Major section

Practitioner: The Compliance Workflow

Compliance becomes manageable when you run a consistent workflow for each feature that handles personal data, recording the decision at each step so the result can be demonstrated later.

  • Records of processing, decisions, and controls.
  • Every processing of personal data needs a lawful basis.
  • A common practitioner mistake is to reach for consent automatically.

Key terms

Usage analytics
Usage analytics are not essential.
iotclass.org

Major section

Practitioner: The Compliance Workflow (continued)

Basis: contract for the core feature, not a consent pop-up the user cannot meaningfully refuse.

  • Consent must be freely given, specific, informed, and as easy to withdraw as to give, which is hard to achieve honestly on a small device.
  • A thermostat needs occupancy to function.
  • Usage analytics are not essential.
iotclass.org

Major section

Under the Hood: Roles, Special Data, Breaches, and Failure Modes

The relationship is governed by a contract that sets out these responsibilities.

  • The deeper layer explains the responsibilities that follow from your role, the extra care some data demands, and what happens when something goes wrong.
  • Mechanism That Makes It Real.
  • Disabled-state tests showing the default constrains behavior.

Why it matters

A frequent IoT error is assuming a cloud provider, as a processor, removes the maker's duties; it does not, because the maker remains the controller for the data its devices collect.

iotclass.org

Major section

Under the Hood: Roles, Special Data, Breaches, and Failure Modes (continued)

Treating this as a design obligation, checked with evidence, is what turns it from a slogan into compliance.

  • The recurring theme is accountability: an obligation you cannot demonstrate is, in practice, an obligation you have not met.
  • Working access, correction, erasure, and portability across all stores.
  • Documentation an auditor can review.
iotclass.org

Major section

Under the Hood: Roles, Special Data, Breaches, and Failure Modes (continued)

The regulation requires protection to be built into processing from the outset and to be the default state, rather than something a user must seek out.

  • A processor acts on the controller's documented instructions and must not use the data for its own purposes, must protect it, and must help the controller meet its duties.
  • A fulfilled request that reaches device, hub, and cloud.
  • Records of processing, decisions, and DPIAs.
iotclass.org

Major section

Under the Hood: Roles, Special Data, Breaches, and Failure Modes (continued)

Erasure that clears the cloud but leaves device and backup copies.

  • Some personal data is treated as more sensitive, such as data about health, and it carries stronger conditions for processing.
  • IoT makes this common: a wearable that infers heart rate or sleep is handling health-related data, and a home sensor may reveal religious or lifestyle patterns.
  • Access controls and protection mapped to sensitivity.
iotclass.org

Deck summary

Key takeaways

A friendly screen is not enough if the owner cannot learn what is held, correct a wrong fact, obtain a copy, or end an unneeded use.

  • Personal data is any information relating to an identifiable person, which for IoT includes far more than names: device identifiers, location, and sensor readings that can single someone out all count.
  • The central idea is that personal data is handled on behalf of the person it describes, called the data subject, and may be processed only with a lawful basis and within the data protection principles.
  • Basis: contract for the core feature, not a consent pop-up the user cannot meaningfully refuse.
iotclass.org

Retrieval practice

Recall check 1 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q1An IoT company outside Europe sells a fitness band to customers in the European Union and decides what the band collects and why. What is its likely role and exposure?

AIt is likely a controller within GDPR's scope
BIt is exempt, because the company is based outside Europe
CIt is only a processor, because the data is stored in a cloud service
DIt has no obligations until a customer complains
Show answer

Answer: A GDPR can reach organizations outside Europe that offer goods or services to people in the EU, and the party deciding why and how is the controller.

iotclass.org

Retrieval practice

Recall check 2 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q2A team wants to use consent as the lawful basis for the core function of a device that the customer cannot use without it. Why is this often the wrong choice?

AConsent is mainly for marketing data
BA clear pop-up provides sufficient informed choice
CConsent is for a real, withdrawable choice
DLawful basis does not matter as long as data is encrypted
Show answer

Answer: C Consent that cannot be refused is not freely given; the core feature is better grounded in a basis that fits a service the customer chose.

iotclass.org

Retrieval practice

Recall check 3 of 3

Privacy Priya says: answer from memory, then check your reasoning.

Q3A user exercises the right to erasure. The team deletes the cloud record but leaves copies on the device and in backups. Why does this fall short, and what is the fix?

AIt is fine, because the main cloud copy was deleted and that is what the user sees
BThe fix is to tell the user the data is mostly deleted
CErasure only ever applies to cloud data, never to devices
DErasure must reach device, cloud, and backup copies
Show answer

Answer: D A right to erasure honored only in the cloud is not honored; the data still exists on the device and in backups unless the request path reaches each store.

iotclass.org

Print reference

Answers

Answer key.

  1. A · GDPR can reach organizations outside Europe that offer goods or services to people in the EU, and the party deciding why and how is the controller.
  2. C · Consent that cannot be refused is not freely given; the core feature is better grounded in a basis that fits a service the customer chose.
  3. D · A right to erasure honored only in the cloud is not honored; the data still exists on the device and in backups unless the request path reaches each store.
iotclass.org