Privacy by design
A UK Department for Digital, Culture, Media and Sport (DCMS) report on IoT certification referenced a survey of 1,000 consumers. The consumers identified prioritized requirements for IoT information that would be beneficial during a purchase. One of these requirements included transparency of privacy, to cover the following:
- Type of personal data collected
- Whether data is shared with third parties
- Whether consumers can opt out of sharing
Each of these data points is covered under a PbD approach. PbD is based on a set of privacy principles. PbD is also a requirement for GDPR. Aligning a VDOO certification with PbD principles would provide consumers and businesses with data to prove that a vendor has met a minimum set of privacy requirements. This alignment is difficult, however, since privacy encompasses the entire IoT system (rather than only the device that collects the information):Â
Principle | Description |
Proactive not reactive; preventive and not remedial  | Within the context... |