Skip to content
Literature · International Data Privacy Law EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Aurelia Tamò-Larrieux, Designing for Privacy and its Legal Framework: Data Protection by Design and Default for the Internet of Things

Methinee Suwannakit — International Data Privacy Law

Methinee Suwannakit — International Data Privacy Law

International Data Privacy Law
DOI

How it connects

Full text

The Internet of Things (IoT) literally means things or objects that connect to each other via the internet. The Organization for Economic Co-operation and Development (OECD) Digital Outlook 2015 report defines IoT as ‘all devices and objects whose state can be altered via the Internet, with or without the active involvement of individuals’.1 As a matter of fact, IoT market is growing rapidly. International Data Corporation (IDC) predicts that worldwide technology spending on the IoT will reach 1.2 trillion dollars in 2022.2 Although connected devices or smart devices placed in offices or homes offer convenience and comfort to users, IoT raises several concerns with user’s privacy and data protection. Moreover, while users benefit from smart wearable devices for tracking their physical activities, they do not want to share their health-related data with other third parties. Responding to privacy and data protection concerns, policymakers are therefore keen to develop legal frameworks to protect personal data in the smart digital environment. However, laws alone cannot lead to changes in practice because data protection stems from the design of technology. In regards with a relationship between law and technology, Lessig3 argues that regulations of behaviour in cyberspace impose through code (technology). Thus, changing the ‘architecture’ of technology could be effective in altering a particular behaviour. Law also has an important role in changing the ‘architecture’ of technology by requiring an architect to modify his or her ‘architecture’. Similar to this idea, the new notion of ‘data protection by design’, codified in Article 25(1) of the EU General Data Protection Regulation (GDPR), requires a controller to ensure that data protection is implemented into the design of new products both ‘at the time of the determination of the means for processing’ and ‘at the time of the processing itself’. As a result, each smart product is required to design effective technical protection in the first place to prevent every possible way of data breach. Nevertheless, despite introducing the new concept of data protection by design, GDPR does not provide any prescription on how to apply the concept in practice. In other words, it does not clarify on how the architecture of technology should be designed. Accordingly, practical guidance is needed to be developed.