ICO Launches Consultation to Shape Data Protection for Smart Technology
London, 16 June 2025 - The Information Commissioner’s Office (ICO) has initiated a vital public consultation on new draft guidance aimed at governing consumer Internet of Things (IoT) products and services. This move marks a significant step in clarifying how UK data protection law applies to the ever-expanding market of smart devices, from connected speakers to fitness trackers.
The UK's data protection regulator is calling on manufacturers, developers, small businesses, and the public to provide feedback on the proposed rules. The central aim is to ensure personal information is used responsibly and that privacy is embedded into smart products from the very beginning. The consultation, which opened on 16 June 2025, will run for twelve weeks, closing on Sunday, 7 September 2025.
This initiative responds to widespread public concern that many smart products collect excessive personal data, often without users having meaningful control or understanding. Stephen Almond, the ICO’s Executive Director for Regulatory Risk, has emphasised the need to build consumer trust through enhanced transparency and robust security.
For small businesses and freelancers developing or selling these technologies, this consultation is a critical opportunity to influence a practical and effective regulatory framework. This article breaks down the proposed ICO smart device guidance, what it means for you, and how you can contribute.
Understanding the Scope: What are Consumer IoT Devices?
Before diving into the guidance, it’s important to clarify what we mean by the ‘Internet of Things’. In simple terms, IoT refers to the network of physical objects—or ‘things’—embedded with sensors, software, and other technologies for the purpose of connecting and exchanging data with other devices and systems over the internet.
In a consumer context, this includes a vast array of devices now common in UK homes and small offices:
Smart Home Hubs: Devices like Amazon Echo or Google Nest that respond to voice commands.
Wearable Technology: Fitness trackers, smartwatches, and health monitors that collect biometric data.
Connected Security: Smart doorbells, security cameras, and alarm systems that record video and audio.
Smart Appliances: From refrigerators that track food inventory to washing machines controlled via an app.
Each of these devices processes personal data, sometimes of a highly sensitive nature. The challenge, which the ICO’s guidance seeks to address, is ensuring this data processing complies with the principles of the UK General Data Protection Regulation (UK GDPR).
Key Pillars of the Draft ICO Smart Device Guidance
The ICO’s proposals are built on foundational UK GDPR principles, translating them into specific expectations for the IoT sector. The draft guidance provides a clear roadmap for compliance, focusing on several core areas that businesses must address.
1. Data Protection by Design and by Default
This is not a new concept; it is a cornerstone of the UK GDPR. However, the guidance applies it directly to the product development lifecycle of smart devices. It states that privacy and security cannot be an afterthought. Manufacturers and developers must build data protection into the core architecture of their products from the initial design phase.
This means conducting Data Protection Impact Assessments (DPIAs) early and often, especially for devices that process sensitive data or use novel technologies like AI. For a small business developing an app to control a smart health monitor, for instance, this involves asking critical questions: How can we minimise data collection? How can we ensure the data is secure both on the device and in transit? The ICO expects these considerations to be documented and demonstrable. Many IoT devices now leverage machine learning, making it crucial for developers to understand their obligations. For a deeper understanding of this area, our guide on implementing AI governance under UK GDPR offers practical advice.
2. Transparency and Fairness
How do you provide clear privacy information on a device with no screen, like a smart lightbulb? This is a key challenge the guidance tackles. The ICO insists that information about what data is collected, why it is collected, and who it is shared with must be clear, honest, and easily accessible before a consumer makes a purchase or completes setup.
This could involve using QR codes on packaging that link to a comprehensive privacy notice, or layered information within the device’s companion app. The language used must be plain and simple, avoiding legal jargon. The principle of fairness also means organisations must not use data in ways that would be unexpected or detrimental to the individual. For more on this, the official ICO Guide to UK GDPR provides foundational resources.
3. Data Minimisation
A central tenet of the UK GDPR is that you should only collect and process personal data that is absolutely necessary for your stated purpose. The draft guidance reinforces this for IoT, pushing back against the tendency for devices to collect vast amounts of data just in case it might be useful later.
Does a smart coffee machine need access to your contacts list? Does a connected toy need to record ambient audio when not in use? The ICO’s answer is almost certainly no. Businesses will need to justify every piece of personal data they collect and be prepared to defend those decisions. This principle protects consumers and also reduces the risk for businesses; the less data you hold, the lower the impact of a potential data breach.
4. Security and the ‘Secure by Design’ Approach
IoT devices are a well-known target for cyber-attacks, often due to poor security practices. The guidance builds on the UK's existing 'Secure by Design' approach, which is now enshrined in law via the Product Security and Telecommunications Infrastructure (PSTI) Act 2022.
The ICO expects robust security measures, including:
Banning universal default passwords: Devices must require users to set a unique, strong password upon setup.
Secure communication channels: Data must be encrypted both in transit and at rest.
A vulnerability disclosure policy: A clear process for security researchers to report flaws.
Regular security updates: A commitment to providing patches for the device’s reasonable lifespan.
Failure to secure a device could lead to a significant data breach, and businesses must be prepared. Understanding your obligations under UK GDPR for data breach notification is essential for any organisation operating in this space.
5. Upholding User Rights
The UK GDPR grants individuals several rights over their data, including the right to access, rectify, and erase their personal information. The draft guidance clarifies that IoT manufacturers must provide clear and accessible tools for users to exercise these rights.
This might be through a user-friendly dashboard in a companion app or a web portal. A user must be able to easily request a copy of the data their fitness tracker has collected or ask for the deletion of all recordings from their smart doorbell. The processes for handling these Data Subject Access Requests (DSARs) must be efficient and compliant.
Why Your Feedback Matters: A Call for Input
The ICO is not creating these rules in a vacuum. It is actively seeking input from the very businesses and individuals who will be most affected. This is a crucial window of opportunity to ensure the final guidance is both effective for protecting consumers and workable for businesses, particularly small and medium-sized enterprises (SMEs).
For Small Businesses and Developers: This is your chance to highlight the practical challenges of implementation. Are the expectations for providing privacy information realistic for a start-up? Are the security requirements proportionate to the risks posed by your specific product? Providing concrete examples and suggesting alternative approaches can lead to more nuanced and practical final guidance.
For Marketers and Website Operators: If you integrate with IoT platforms or use data from smart devices for advertising, this guidance will impact you. Consider how the rules on transparency and consent will affect your data sources and marketing strategies. It’s vital that your perspective is heard.
How to Respond to the Consultation
Engaging with the consultation process is straightforward. The ICO is inviting feedback from all stakeholders until the deadline of 7 September 2025.
Responses can be submitted directly via the survey on the Citizen Space platform, which can be accessed through the consultations section on the ICO's official website. We encourage all UK-based businesses, freelancers, and developers in the IoT space to review the draft guidance in detail and submit a considered response.
By contributing, you not only help shape a clearer regulatory landscape but also demonstrate a proactive commitment to data protection, ultimately building greater trust with your customers. This consultation is a key moment to ensure the future of smart technology in the UK is both innovative and respectful of individual privacy.
For organisations looking to ensure their current practices are up to scratch, Infinitic Consultancy offers expert guidance on navigating the complexities of UK GDPR. Our consultants can help you understand your obligations, from crafting clear privacy notices to implementing data protection by design. Getting compliance right is not just about avoiding fines; it's about building a sustainable, trustworthy business. A good starting point is to review the ICO's own advice, which we break down in our practical guide to ICO GDPR compliance.
--- CopyEdit CopyEditSEO Settings: Focus Keyword: ICO smart device guidance SEO Title: ICO Smart Device Guidance Consultation: A UK Business Guide (60 characters) Meta Description: The ICO seeks input on new UK GDPR rules for IoT. Our guide explains the draft ICO smart device guidance and what it means for your UK business. (156 characters) Slug: ico-smart-device-guidance-consultation-uk-business Transition Words: Yes Paragraph Length: Short and clearly spaced Active Voice: Predominantly used Keyword Density: 1.2% Image Alt Attributes: A graphic showing various smart devices with a UK GDPR shield icon, illustrating the ICO smart device guidance. Total Token Count: 1350 Keyphrase Distribution: Even Focus Keyphrase in Subheadings: Yes SEO Title Width: Within optimal limit