Security and privacy

EU General Data Protection Regulation

The core EU law on processing personal data, including data collected by connected devices, apps and cloud services.

CodeGDPR
RegionEuropean Union
TypeMandatory
Issued byEU data protection authorities
Last verified2026-10-10
Quick answerCertification · last verified 2026-10-10

The core EU law on processing personal data, including data collected by connected devices, apps and cloud services. Status: Mandatory. Issued or recognised by EU data protection authorities.

CodeGDPR
RegionEuropean Union
TypeMandatory
Issued byEU data protection authorities
GroupSecurity and privacy
Last verified2026-10-10
How to cite this pageIoT Atlas. "EU General Data Protection Regulation". https://hi-spark.net/certification/gdpr.html Last verified 2026-10-10.

What it means

IoT products routinely process personal data such as account details, device identifiers, location, camera footage or health measurements. GDPR requires a lawful basis, transparency, data minimisation, security, retention limits and support for data subject rights, and it applies to sellers outside the EU that target EU users.

Applies to

  • Companion apps and cloud accounts
  • Cameras, trackers and wearables that process personal data
  • Manufacturers and service providers offering devices to EU users

What it does not cover

  • Radio or safety market access
  • Sector rules such as the ePrivacy Directive for cookies and communications
  • Local implementation laws that add national requirements

Verification checklist

  • Map what personal data each product collects and where it goes
  • Define the lawful basis and document it
  • Publish a privacy notice that matches the actual data flows
  • Implement retention, deletion and export capabilities
  • Assess transfers outside the EU and the safeguards used