Internet of Things Part I: IoT Privacy Concerns

Business Law Revision Legal

The Legal Landscape for IoT Privacy in the United States

The IoT’s privacy implications are not merely theoretical — they are increasingly subject to legal enforcement. In the United States, there is no single comprehensive federal IoT privacy statute, but a web of laws governs specific aspects of data collection by connected devices. The FTC Act’s prohibition on unfair or deceptive trade practices, 15 U.S.C. § 45, is the primary federal tool. Under this authority, the FTC has brought enforcement actions against companies that collected consumer data through connected devices in ways that contradicted their privacy representations or that were unreasonably harmful to consumers.

State law adds substantial complexity. California’s Consumer Privacy Act of 2018 (CCPA), as amended by the California Privacy Rights Act of 2020 (CPRA), gives California residents the right to know what personal information is collected, to opt out of its sale, and to request deletion. A connected device that collects geolocation, health, or biometric data from California residents triggers CCPA obligations regardless of where the manufacturer is located. Violations of the CCPA can result in civil penalties of up to $7,500 per intentional violation, and the law grants a private right of action for data breaches resulting from failure to implement reasonable security measures.

Sensitive Categories of IoT Data

Not all data collected by IoT devices carries the same legal weight. Several categories of data trigger heightened obligations under existing law:

  • Health data. Wearables that collect physiological information — heart rate, sleep patterns, blood oxygen levels — may qualify as electronic protected health information under HIPAA if they are used in connection with a covered healthcare provider or health plan. Outside HIPAA, the FTC’s Health Breach Notification Rule, 16 C.F.R. Part 318, requires vendors of personal health records and their service providers to notify affected individuals, the FTC, and in some cases the media, following a breach of unsecured identifiable health information. The FTC has actively enforced this rule against health app developers and wearable device companies.
  • Biometric data. Illinois’ Biometric Information Privacy Act (BIPA), 740 ILCS 14/1 et seq., is the most consequential state biometric privacy law in the country. BIPA requires informed written consent before collecting biometric identifiers — fingerprints, voiceprints, retina scans, and facial geometry — and prohibits their sale. Critically, BIPA provides a private right of action with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation. IoT devices that use facial recognition or voice matching trigger BIPA obligations for Illinois users. Class action litigation under BIPA has produced billion-dollar settlements against major technology companies.
  • Children’s data. The Children’s Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, requires verifiable parental consent before collecting personal information from children under 13. IoT devices — smart toys, children’s tablets, connected learning tools — that are directed to children or that have actual knowledge of collecting children’s data are covered regardless of whether a traditional website is involved. The FTC has fined IoT device manufacturers under COPPA for collecting children’s data without consent.

The Data Aggregation Problem

As the original post noted, the most serious privacy concern from IoT is not any single data point but the aggregation of individually innocuous data points into a detailed behavioral profile. The law has struggled to keep pace with this reality. Most U.S. privacy laws focus on specific categories of sensitive data rather than on the aggregate risk of combining non-sensitive data. But the FTC has articulated a principle — in its 2012 report “Protecting Consumer Privacy in an Era of Rapid Change” — that the aggregation of multiple data streams can itself constitute a sensitive data practice that triggers heightened obligations.

The FTC’s enforcement action against InMobi in 2016 illustrated this principle in an IoT context. InMobi used location data from mobile devices — individually innocuous — to build profiles that allowed advertisers to target users based on their precise whereabouts without consent. The FTC found this to be an unfair trade practice and imposed a $950,000 civil penalty. The same logic applies directly to IoT: a company that aggregates location, sleep, exercise, purchase, and voice command data from a suite of connected devices, even if no single stream is sensitive, may be engaging in a practice that the FTC considers unfair to consumers who had no reasonable way to anticipate the aggregate picture that would be assembled.

Privacy Policy Requirements for IoT Products

Any company deploying a connected device that collects personal information from U.S. consumers should have a privacy policy that accurately describes the data collected, the purposes of collection, the categories of third parties with whom data is shared, and the user’s rights with respect to that data. This is not optional. The FTC regularly brings enforcement actions against companies whose actual data practices are inconsistent with their posted privacy policies, characterizing the inconsistency as a deceptive trade practice under Section 5(a). Beyond the FTC, state attorneys general in California, Colorado, Connecticut, Virginia, and Texas have independent enforcement authority under their state privacy statutes.

For IoT products, the privacy policy should also address: firmware and software update practices; data retention periods; the security measures applied to data in transit and at rest; the geographic location of data storage (relevant for GDPR compliance if EU users are involved); and the company’s data breach notification procedures. Vague assurances that data is “used to improve the user experience” are increasingly inadequate and invite regulatory scrutiny.

If your company collects data through connected devices and needs help assessing your legal exposure or drafting compliant privacy policies, contact Revision Legal’s internet law attorneys through the form on this page or call 855-473-8474.

Extra, Extra!
Related Posts

How to Respond to a Cease and Desist Letter

How to Respond to a Cease and Desist Letter

Receiving a cease and desist letter can feel alarming. One minute you are running your business as usual, and the next you are staring at a legal demand accusing you of trademark infringement, copyright violation, breach of contract, or some other wrong. The situation can escalate quickly if not handled properly. But receiving a cease […]

Read more about How to Respond to a Cease and Desist Letter

Put Revision Legal on your side