CIPP/E Study Guide
Ch 17.9 - Connected objects & VVAs

Internet of Things (IoT)

The IoT is physical objects ('connected objects') that connect, sense and transmit data - wearables, smart meters, connected vehicles, and VVA-paired devices. Sensor data is often personal data (a smart meter sampling every two seconds can reveal the TV show being watched). Connected objects are terminal equipment, so the ePrivacy Directive applies to storing/accessing info on them; the strictly necessary exemption covers executing a user's voice request, but improvement or advertising needs consent. Transparency is hard on screenless devices. Bases: contract for executing requests, legitimate interest sometimes, often consent. Security is a major challenge.

IoT / VVA roles (EDPB)
RoleFunction
VVA provider/designerDevelops the VVA technology
VVA application developerCreates applications using the VVA technology
IntegratorManufactures the connected object and integrates the VVA app
OwnerResponsible for the physical space where the object is deployed
UserVerbally interacts with the VVA service
ePrivacy & the strictly necessary exemption

Connected objects are terminal equipment. The ePrivacy Directive applies to storing/accessing info on them. Storage/access needed to understand and execute a user's verbal request falls under the strictly necessary exemption - but using data to improve a service or build advertising profiles needs notice and consent.

  • Make it apparent the object is collecting data (lights, sounds, icons) - screenless devices are a transparency challenge
  • Contract (Art 6(1)(b)) can cover executing registered users' requests, including personalisation that is an intrinsic and expected element
  • Legitimate interest often fails for precise location or special category data (WP29)
  • Voice data used to uniquely identify a person engages Article 9
  • Security is hard: many devices on one network, rarely patched, always 'listening', remote attacks possible

Key terms - quick answers

What is “IoT”?
Internet of Things - physical objects with technology to connect to a network and transmit information, often via sensors.
What is “VVA”?
Virtual voice assistant - technology paired with connected objects to understand and execute voice commands.
What is “Terminal equipment”?
Devices (including connected objects) at the user's end; storing/accessing info on them engages the ePrivacy Directive.
What is “Strictly necessary exemption”?
ePrivacy exemption covering storage/access necessary to provide a service the user explicitly requested (e.g. executing a voice command).