With No National Data Law, Ethical Concerns May Keep US IoT Grounded
Lawyers say the days of the U.S. being a Wild West of data collecting and sharing are ending, and IoT device makers in particular are beginning to focus on data privacy management.
September 25, 2019 at 11:30 AM
4 minute read
There's more data flowing to third parties from internet of things (IoT) devices in the U.S. compared to devices used in the U.K., according to a new report. But the days of the U.S. being a data sharing "open season" may be numbered.
The "Information Exposure From Consumer IoT Devices: A Multidimensional, Network-Informed Measurement Approach" report conducted by Northeastern University and Imperial College London found that U.S. IoT devices contacted more third-parties than their UK counterparts, possibly because they aren't held to the European Union's strict data privacy regulations. The two universities studied the data flows and encryption of 46 smart devices purchased and used in the U.S. and 35 IoT devices purchased and used in the U.K.
London-based Freshfields Bruckhaus Deringer partner and data practice leader Giles Pratt noted that smart home devices used in the study could collect personal data that would fall under the General Data Protection Regulation (GDPR)'s scope, and as such should have data collection and protection controls in place when collecting EU citizens' data.
"[Companies] will probably pause and engage in designing their devices with privacy in mind, and by default you should be able to calibrate your device in respect to privacy and default opt-out," he said of the GDPR.
To be sure, the U.S. doesn't have a federal privacy law similar to the GDPR, though New York-based Freshfields Bruckhaus partner Tim Harkness noted the legal landscape in the U.S. is complex. with state laws like the California Consumer Privacy Act (CCPA) and federal regulations on health care, finance and underage children's data.
Still, even without a federal data privacy law governing all U.S. citizens' data, some companies are taking the initiative and adjusting their data privacy management to fit international regulators' and consumers' expectations.
Harkness noted that while some companies haven't made data privacy their top concern, others have used the GDPR as a benchmark for devices not even intended for release in the EU.
"They are now looking at their approach to personal data with an international viewpoint of if they should be GDPR compliant even though their product may not be released initially in the EU," he said.
Companies are taking that approach to match not only regulatory requirements, but to answer ethical questions consumers may have about a device's snooping abilities. Pratt noted some IoT device makers are manufacturing devices that include default opt-out for data sharing and other measures to earn consumers' trust.
What's more, "big national companies are thinking about what's beyond regulations like the GDPR to make sure their products are safe," Harkness added.
What comes after the GDPR, may in fact originate from the U.S. "I would have thought the days of people thinking the U.S. was open season for data have started to disappear, particularly with the new laws coming down the pike," Pratt said, citing the upcoming CCPA.
While new regulations may hinder what IoT devices can do, some do not believe this will translate into stunting innovation. As companies adjust to the new "modern age" where regulators are focusing on data privacy, Harkness doesn't think companies' innovations are hampered by the data they can't collect.
"I think more is not necessarily better," he explained. "It's really about who can use the data that enhances the consumer experience because those sophisticated with the data or are sophisticated about what the rules are, know what they need to collect."
This content has been archived. It is available through our partners, LexisNexis® and Bloomberg Law.
To view this content, please continue to their sites.
Not a Lexis Subscriber?
Subscribe Now
Not a Bloomberg Law Subscriber?
Subscribe Now
NOT FOR REPRINT
© 2025 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.
You Might Like
View AllTrending Stories
- 1Fulton DA Seeks to Overturn Her Disqualification From Trump Georgia Election Case
- 2The FTC’s Noncompete Rule Is Likely Dead
- 3COVID-19 Vaccine Suit Against United Airlines Hangs on Right-to-Sue Letter Date
- 4People in the News—Jan. 10, 2025—Lamb McErlane, Saxton & Stump
- 5How I Made Partner: 'Be Open With Partners About Your Strengths,' Says Ha Jin Lee of Sullivan & Cromwell
Who Got The Work
Michael G. Bongiorno, Andrew Scott Dulberg and Elizabeth E. Driscoll from Wilmer Cutler Pickering Hale and Dorr have stepped in to represent Symbotic Inc., an A.I.-enabled technology platform that focuses on increasing supply chain efficiency, and other defendants in a pending shareholder derivative lawsuit. The case, filed Oct. 2 in Massachusetts District Court by the Brown Law Firm on behalf of Stephen Austen, accuses certain officers and directors of misleading investors in regard to Symbotic's potential for margin growth by failing to disclose that the company was not equipped to timely deploy its systems or manage expenses through project delays. The case, assigned to U.S. District Judge Nathaniel M. Gorton, is 1:24-cv-12522, Austen v. Cohen et al.
Who Got The Work
Edmund Polubinski and Marie Killmond of Davis Polk & Wardwell have entered appearances for data platform software development company MongoDB and other defendants in a pending shareholder derivative lawsuit. The action, filed Oct. 7 in New York Southern District Court by the Brown Law Firm, accuses the company's directors and/or officers of falsely expressing confidence in the company’s restructuring of its sales incentive plan and downplaying the severity of decreases in its upfront commitments. The case is 1:24-cv-07594, Roy v. Ittycheria et al.
Who Got The Work
Amy O. Bruchs and Kurt F. Ellison of Michael Best & Friedrich have entered appearances for Epic Systems Corp. in a pending employment discrimination lawsuit. The suit was filed Sept. 7 in Wisconsin Western District Court by Levine Eisberner LLC and Siri & Glimstad on behalf of a project manager who claims that he was wrongfully terminated after applying for a religious exemption to the defendant's COVID-19 vaccine mandate. The case, assigned to U.S. Magistrate Judge Anita Marie Boor, is 3:24-cv-00630, Secker, Nathan v. Epic Systems Corporation.
Who Got The Work
David X. Sullivan, Thomas J. Finn and Gregory A. Hall from McCarter & English have entered appearances for Sunrun Installation Services in a pending civil rights lawsuit. The complaint was filed Sept. 4 in Connecticut District Court by attorney Robert M. Berke on behalf of former employee George Edward Steins, who was arrested and charged with employing an unregistered home improvement salesperson. The complaint alleges that had Sunrun informed the Connecticut Department of Consumer Protection that the plaintiff's employment had ended in 2017 and that he no longer held Sunrun's home improvement contractor license, he would not have been hit with charges, which were dismissed in May 2024. The case, assigned to U.S. District Judge Jeffrey A. Meyer, is 3:24-cv-01423, Steins v. Sunrun, Inc. et al.
Who Got The Work
Greenberg Traurig shareholder Joshua L. Raskin has entered an appearance for boohoo.com UK Ltd. in a pending patent infringement lawsuit. The suit, filed Sept. 3 in Texas Eastern District Court by Rozier Hardt McDonough on behalf of Alto Dynamics, asserts five patents related to an online shopping platform. The case, assigned to U.S. District Judge Rodney Gilstrap, is 2:24-cv-00719, Alto Dynamics, LLC v. boohoo.com UK Limited.
Featured Firms
Law Offices of Gary Martin Hays & Associates, P.C.
(470) 294-1674
Law Offices of Mark E. Salomone
(857) 444-6468
Smith & Hassler
(713) 739-1250