What it means
IoT products routinely process personal data such as account details, device identifiers, location, camera footage or health measurements. GDPR requires a lawful basis, transparency, data minimisation, security, retention limits and support for data subject rights, and it applies to sellers outside the EU that target EU users.
Applies to
- Companion apps and cloud accounts
- Cameras, trackers and wearables that process personal data
- Manufacturers and service providers offering devices to EU users
What it does not cover
- Radio or safety market access
- Sector rules such as the ePrivacy Directive for cookies and communications
- Local implementation laws that add national requirements
Verification checklist
- Map what personal data each product collects and where it goes
- Define the lawful basis and document it
- Publish a privacy notice that matches the actual data flows
- Implement retention, deletion and export capabilities
- Assess transfers outside the EU and the safeguards used