IAPP-GDPR Web Banners-300x250-FINAL

By Jedidiah Bracy, CIPP/US, CIPP/E

Stakeholders met in Washington, DC, on November 19 to explore and hash out the privacy and security implications of the Internet of Things (IoT). The rapidly emerging landscape of connected sensors and embedded technology has garnered the attention of the Federal Trade Commission (FTC) of late, but the complexity of the IoT ecosystem was readily apparent during the proceedings. 

Called for and led by the FTC, the roundtable was broken into four main panels—the smart home, connected health and fitness, connected cars and connected privacy and security—and featured remarks from FTC Chairwoman Edith Ramirez, Commissioner Maureen Ohlhausen and Bureau of Consumer Protection Director Jessica Rich.

It was clear from the outset that one main concern threaded throughout the day was the need for more robust security protections with IoT technology. One common answer among most panelists was more calls for Privacy by Design by companies—particularly small- and medium-sized businesses and startups. The testimony made clear that larger companies such as GE, Microsoft, Google and Toyota have been putting resources into developing connected devices with privacy and security in mind, but concerns about the nascent industry loomed.

Scott Peppet, Stanley Crosley and Joseph Lorenzo Hall

Electronic Frontier Foundation Senior Staff Attorney Lee Tien said he’s “worried that industries moving into this space are not as mature about security as others like Microsoft.”  Tactical Network Solutions Vulnerability Researcher Craig Heffner added that companies need to push their vendors to improve security as more embedded devices come out, and warned that, often, smaller companies try to cut costs and so hire the cheapest developers.

“They’ll make rookie mistakes,” he said, “because they’re rookies.”

Michelle Chibba, policy and special projects director for the Office of the Information and Privacy Commissioner of Ontario, cited her agency’s research of apps in the smart grid, which found that many SMEs did not have sophisticated privacy and security knowledge and often lacked chief privacy officers.

University of Washington School of Law Prof. Ryan Calo offered an uber-version of Privacy by Design. He said businesses should start thinking about privacy when thinking about their businesses models. He said businesses should ask, “What am I selling? Am I building a data engine that can be monetized?” while adding, “The data lifecycle starts at your business plan.”

Scott Peppet, professor at the University of Colorado School of Law, said he spent the summer analyzing the privacy policies of the top 30 fitness devices and found that many either did not have a privacy policy at all or had one that inaccurately described their data collection and use. “A lot of these companies have not figured out their business model yet,” he warned, adding a caution about how poorly notice-and-choice performs in this realm. Further details of his work will be published in February, he said.

In fact, providing notice and choice to consumers and businesses in a highly complex and connected environment is next to impossible, according to several panelists. Other basic Fair Information Privacy Practices (FIPPs) are being challenged as well.

Privacy and Security in a Connected World panel

In tandem with the event, the Future of Privacy Forum (FPF) released a whitepaper proposing a new privacy paradigm for the IoT. The analysis, written by FPF Co-Chairman and panelist Christopher Wolf and Executive Director Jules Polonetsky, CIPP/US, argues that the FIPPs are getting outdated and that to provide meaningful notice—particularly in a landscape that often doesn’t have interfaces to provide notice or offer choice—is simply not feasible.

Wolf, who offered his analysis on the connected cars panel, applauded the FTC’s initiatives in the IoT realm thus far but said he “would not like to see the FTC’s mission to be the granular technology prescriber.”

Not all agreed, however, with altering the FIPPs.

“It’s a truism that U.S. privacy law is about notice and choice,” Calo said. “We have amazing technology that allows a blind man who speaks English to speak to a German, but at the same time, we’re in the Gutenberg era” when it comes to terms of service and privacy notices. “There is a real opportunity to do notice right,” he said, adding, “We need to innovate around privacy notices.”

FTC Bureau of Consumer Protection Director Jessica Rich

Will the FTC issue new regulations?

Vint Cerf, a keynote during the roundtable and Google’s chief Internet evangelist, said that social conventions, not government regulation, will ultimately protect consumer privacy. He said we’re living in an era when such social conventions need to be worked out.

“While regulation might be helpful,” he said, “an awful lot of the problems that we experience with privacy is a result of our own behavior.”

The FTC’s Rich answered the question and closed the intensive day by noting the agency will not issue new regulations on IoT in the near term but noted it will provide a report sometime in 2014. 

Read more by Jedidiah Bracy:
Google: NSA Could Cause Splinternet
Establishing Trust with U.S. Privacy Regulators
Federal and State Regulators Talk Data Security Lessons
Hack the Trackers Taps Into the Post-Snowden Zeitgeist


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Advertise in IAPP Publications

Find out how to get your message in front the people you want to reach. Download a media kit now.

Get more News »

Find a KnowledgeNet Chapter Near You

Network and talk privacy at IAPP KnowledgeNet meetings, taking place worldwide.

Women Leading Privacy

Events, volunteer opportunities and more designed to help you give and get career support and expand your network.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

The Training Post—Can’t-Miss Training Updates

Subscribe now to get the latest alerts on training opportunities around the world.

New Web Conferences Added!

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Staff

Get your team up to speed on privacy by bringing IAPP training to your organization.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

Learn more about IAPP certification »

Get Close-up

Looking for tools and info on a hot topic? Our close-up pages organize it for you in one easy-to-find place.

Where's Your DPA?

Our interactive DPA locator helps you find data protection authorities and summary of law by country.

IAPP Westin Research Center

See the latest original research from the IAPP Westin fellows.

Looking for Certification Study Resources?

Find out what you need to prepare for your exams

More Resources »

GDPR Comprehensive: Registration Open

New! Intensive two-day GDPR training led by the sharpest minds in the field. It's a can't-miss event.

The Congress Is Cancelled

The IAPP Europe Data Protection Congress 2015 is cancelled. Click through to learn more.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

Exhibit at an Event

Put your brand in front of the largest gatherings of privacy pros in the world. Learn more.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»