Internet of Things – start-ups may need to ‘smart up’ when it comes to privacy compliance
The Office of the Australian Information Commissioner is encouraging businesses to adopt a ‘privacy-by-design’ approach
With the emergence of the ‘internet connected world’, increasing attention is now being paid to the potential privacy concerns associated with the Internet of Things (IoT).
On Friday, 23 September 2016, the Office of the Australian Information Commissioner released some of the results of its investigation into the IoT, which was undertaken in collaboration with 25 privacy enforcement authorities from around the world.
In Australia, the OAIC examined 45 different IoT devices, including for example, fitness and health monitors, ‘smart’ travel locks and thermostats. The suppliers of these devices ranged from large multinational corporations to start-up business. The results of the OAIC’s investigation showed that for 71% of those devices, there was no privacy policy that adequately explained how personal information was managed in the course of an individual’s interactions with the device.
The OAIC is now encouraging all businesses, including start-ups, to adopt a ‘privacy-by-design’ approach. This goes to the need to consider potential privacy issues from the outset of the ideas/design process. Failing to do so may result in costly and/or inconvenient privacy compliance related issues later on in the development lifecycle.
The OAIC has also specifically drawn the attention of start-up business owners to the fact that ‘they may be subject to the Privacy Act if they trade in personal information or deal with health information, and will definitely be covered once they reach an annual turnover of more than $3 million, and will then be required to build in privacy procedures’.
In developing an IoT privacy framework, businesses should be aware of, and carefully consider, the unique characteristics of their IoT product offering. That is, there is no ‘one-size fits all’ approach, and whilst issues pertaining to privacy are by no means insurmountable, it pays to give such issues the attention they deserve from the outset.
The OAIC has also indicated that they will be developing a number of resources for start-up businesses to assist them to implement best privacy practice.
Given the results of the OAIC’s investigation, we also anticipate that further regulatory attention is likely to be paid to suppliers of IoT products and solutions in the near future.
By Jack Evans
Key contacts
Related articles
Before and after the proposed changes to the Franchising Code of Conduct
By Greg Hipwell, Jessica Reid, Elizabeth Lilley & Elise Pascoe
On 10 November 2020, the Commonwealth Government released for public comment, the draft regulations it proposes will...
ACCC’s 2021 enforcement priorities – what you need to know
By Shaun Temby, Christopher Marsh
ACCC’s enforcement priorities for 2021
2018 In Review: Australian Competition & Consumer Commission
By Shaun Temby
In Review take a look at the ACCC’s leading cases and activities in 2017
New year, new contracts – tips and tricks for ICT contracting in 2021
By Caroline Atkins, Gavan Mackenzie, Nick Topfer & Belinda Chapman, Bridget Sullivan, Samantha Haddon, Angelina Yang
ICT contracting tips and tricks from 2020
Partner and Sector Leader - Technology
Sydney