Share these talks and lectures with your colleagues
Invite colleaguesInternet of things data protection and privacy in the era of the General Data Protection Regulation
Abstract
The emerging internet of things (IoT) technology has immense potential for unprecedented business offerings in various domains. To provide reliable IoT products and services that comply with regulatory demands, businesses must meet users’ data protection and privacy needs. With the General Data Protection Regulation (GPDR) coming into force from 24th May, 2016 and applicable from 25th May, 2018, IoT businesses must strategise privacy alignment for their products or services by incorporating in their design the privacy and data protection capabilities necessary for regulatory compliance and gaining user trust. This paper discusses the associated data protection and user privacy concerns, making reference to such IoT service offerings as smart retail, the smart home, smart wearables, smart health devices, smart television and smart toys. The three steps to privacy alignment strategy discussed in this paper comprise the privacy inquisition (PI) analysis model, the IoT privacy impact assessment (iPIA) and the privacy state transition process through which IoT businesses pass on their path to attaining ‘perfect alignment’ with respect to the GDPR data protection requirements and user privacy needs. Privacy inquisition, iPIA and privacy state transition should be performed on a periodic basis, preferably under the guidance of a privacy governance board with supervisory authority and representation from the organisation’s board of directors, the controller and the data protection officer.
The full article is available to subscribers to the journal.
Author's Biography
Abhik Chaudhuri is Chevening fellow and domain consultant in cyber security, privacy and policy at Tata Consultancy Services. Abhik has more than 14 years of IT consulting experience and holds an MBA from the Indian Institute of Management at Kozhikode. Abhik provides thought leadership in developing global cyber security and privacy standards at ISO/IEC JTC1/SC27. He is a Corporate Member of Cloud Security Alliance’s International Standardization Council, and an IEEE member of the IoT Community and Experts in Technology and Policy Forum.