iapp-privacycore
ONETrust_Webcon-3_23_17_Ad_300x250_OneTrust_v2
S17_Banner_300x250-COPY

The Internet of Things (IoT) was front-and-center on Wednesday during a Senate Committee on Commerce, Science and Transportation hearing that featured testimony from a wide spectrum of witnesses across industry sectors. At issue in the now Republican-controlled Senate committee hearing was whether the IoT and its many benefits can flourish unfettered in a free marketplace or if regulations are needed to mandate strong security, ensure privacy protections and manage other more technical issues around spectrum availability.

CDT's Justin Brookman

CDT's Justin Brookman

As became clear during the testimony, the IoT realm goes beyond consumer protection and privacy. It has also become a major factor in industrial and agricultural operations. On the whole, however, panelists agreed that a single national IoT regulatory plan would not be the answer, but strong security in all devices will be paramount.

“We have to design security in at the beginning and throughout a connected device’s lifecycle,” said Intel IoT Group Vice President and General Manager Doug Davis.

Overall, there appeared to be some bipartisan support for not regulating the IoT industry just yet. Sen. Cory Booker (D-NJ) said, “This is a phenomenal opportunity for a bipartisan approach. My concerns are what my Republican colleagues’ are. We should encourage this growth, not restrict it.”

Booker, in fact, called for the hearing alongside Sens. Kelly Ayotte (R-NH), Deb Fischer (R-NE) and Brian Schatz (D-HI).

The regulatory approach of the 1990s was also used as an example for how to proceed with the IoT now. “We got policy right with the Internet in the 1990s,” said George Mason’s Mercatus Center Senior Research Fellow Adam Thierer, “now we need to get it right for the IoT. We need a light-touch, market-driven approach without trying to anticipate problems.”

The Congressional inquiry comes less than two weeks after the Federal Trade Commission (FTC) released its much-anticipated report on the IoT, which didn't go so far as to call for immediate regulations, and a day after FTC Chief Technologist Ashkan Soltani released a blog post on IoT security concerns, particularly regarding the shelf life of a product. “If a critical vulnerability is discovered,” Soltani wrote in his FTC post, “will an update be provided? … Should modern refrigerators have a shelf life, much like the food contained within?”

George Mason's Adam Thierer

George Mason's Adam Thierer

At times, some senators did take swipes at the FTC’s role in regulating the IoT environment. Ayotte asked whether there’s enough data security certainty for businesses under Section 5 of the FTC Act. Thierer said the case law coming out of FTC settlements is an evolving set of references for business to use.

According to the panelists, big IoT winners will be retail and the industrial and agricultural sectors, as well as wearable health-tracking devices and connected cars.

Sen. Gary Peters (D-MI) pointed out that vehicle-to-vehicle (V2V) communication has the potential to curb 80 percent of automobile accidents and noted the automobile industry has been proactive in creating privacy-protecting guidelines for smart cars.

Center for Democracy & Technology’s Justin Brookman said it’s great to see the industry active on the issue but also discussed the personal nature of cars. “I’d like to see more consumer control over whether a company knows your location,” he said, for example, citing controversial comments made last year by Ford’s CEO on knowing “where you are.”

Brookman supported the safety potential for connected cars but warned against including personal information in V2V communications. “My car needs to know a car is swerving toward me,” he explained, “but it doesn’t need to know that it’s Adam’s car swerving at me.”

Sen. Ed Markey (D-MA)

Sen. Ed Markey (D-MA)

Just days after releasing a damning report on connected car security and privacy protections, Sen. Ed Markey (D-MA) took an opportunity to once again warn that the auto industry needs to do more to ensure smart cars are safe for consumers. “If you can figure out an algorithm that can send information around the world,” he said, “then you can figure out an algorithm to protect consumers’ information.”

Data ownership was also a theme that ran through the morning’s hearing. Sen. Joe Manchin (D-WV) said clearly big money is made off of consumers’ personal data. “For those who want privacy,” he asked, “where is that money going?”

Some of the panelists agreed that, often, consumer value resides in the inherent improvement of services through such personal data.

Brookman noted that activity trackers can serve as a good example of how best to give consumers control over their data. Let the consumer decide whether she wants to share her personal data. Businesses can add a value proposition, though. If you share your data, we’ll give you five dollars off your next purchase, he suggested.

Though no regulation appears to be in the IoT's near future, it's clear that it's on just about everyone's radar. How well organizations, both big and small, ensure their products and services are reasonably secured may well determine whether regulation eventually will be needed.

Written By

Jedidiah Bracy, CIPP/E, CIPP/US

Comments

If you want to comment on this post, you need to login.

Related

Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find a KnowledgeNet Chapter Near You

Talk privacy and network with local members at IAPP KnowledgeNet Chapter meetings, taking place worldwide.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

The Privacy Core™ Library Has Evolved

Privacy Core™ e-learning essentials just expanded to include seven new units for marketers. Keep your data safe and your staff in the know!

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

Upcoming Web Conferences

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Team

Get your team up to speed on privacy by bringing IAPP training to your organization.

Let’s Get You DPO Ready

There’s no better time to train than right now! We have all the resources you need to meet the challenges of the GDPR.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

FIP Designation

Recognizing the advanced knowledge and issue-spotting skills a privacy pro must attain in today’s complex world of data privacy.

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.

CIPP/E + CIPM = DPO

The IAPP’S CIPP/E and CIPM are the ANSI/ISO-accredited, industry-recognized combination for DPO readiness. Learn more today.

Learn more about IAPP certification »

IAPP-OneTrust Website Scanning & Cookie Compliance Tool

Scan your website for cookies, tags, forms and policies and create a custom, dynamically updated cookie policy based on the results of your scans.

Are You Ready for the GDPR?

Check out the IAPP's EU Data Protection Reform page for all the tools and resources you need.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

More Resources »

Global Privacy Summit 2017

The world’s premier privacy conference returns with the sharpest minds and unparalleled programs—plus a whole new spin on Active Learning!

Canada Privacy Symposium 2017

The Symposium returns to Toronto! Take advantage of Early Bird rates before March 31 and join your fellow privacy pros for a stellar program.

The Privacy Bar Section Forum 2017

The Privacy Bar Section Forum is SOLD OUT and the wait list is closed. If you got on the wait list, we'll keep in touch about your status. Good luck!

Asia Privacy Forum 2017

Join us in Singapore for exclusive networking and intensive education on data protection trends and challenges in the Asia Pacific region.

Privacy. Security. Risk. 2017

We're bringing the best of the best in privacy and infosecurity to sunny San Diego. Early registration for P.S.R. opens in May.

Europe Data Protection Congress 2017

Your source for European policy debate, multi-level strategic thinking and thought-provoking discussion. Registration opens in early June.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»