← Back to Regulatory Updates

Regulatory Update • June 2026

ICO Finalises Privacy Expectations for Smart Devices

Published: 11 June 2026 Topic: Smart Devices / Privacy by Design Source: ICO Guidance

The ICO has published final guidance setting clearer privacy expectations for manufacturers and developers of consumer smart devices.

The guidance focuses on privacy by design, meaningful consent, transparent information, data minimisation, security and giving people genuine control over how their personal data is used.

Reading time 2 minutes

What changed

The ICO has published final guidance for consumer Internet of Things products and services, setting clearer expectations for manufacturers and developers that use personal data through connected devices.

The guidance covers products such as smart speakers, connected televisions, fitness trackers, smart doorbells, home hubs and domestic appliances. It sets out expectations around privacy by design, data minimisation, meaningful consent, transparent information, security and tools that allow people to exercise their information rights.

What is a smart device?

A smart device is a connected product that collects, uses or shares information through an internet connection. This can include devices used in the home, wearable technology, connected entertainment systems and apps or cloud services that support them.

Why this matters

Smart devices can collect detailed information about people’s routines, behaviour, health, location, household activity and preferences. The ICO’s guidance makes clear that privacy should be considered from the earliest stages of product design, rather than added later through a privacy notice or settings page.

The guidance is relevant not only to device manufacturers, but also to app developers, operating system providers, cloud providers and other organisations involved in the consumer IoT supply chain. For wider developments across privacy, technology and data protection, see our Regulatory Updates page.

What organisations should do

Organisations involved in smart-device products or services should review whether privacy, consent and security are built into the product lifecycle.

  • Check whether data collection is limited to what is genuinely necessary for the product or service.
  • Use protective privacy settings by default wherever possible.
  • Make consent clear, specific, freely given and easy to withdraw.
  • Provide privacy information in plain language at relevant points throughout the user journey.
  • Assess whether a Data Protection Impact Assessment is required, particularly where sensitive data or children may be involved.
  • Review whether security measures such as updates, encryption and multifactor authentication are maintained throughout the product’s lifetime.

Practical takeaway

Smart-device privacy cannot rely on hidden settings or a lengthy privacy notice. Organisations should be clear about what data they collect, why they need it, how people can control it and how security will be maintained over time.

Grounded in

ICO final guidance on consumer Internet of Things products and services, including expectations around privacy by design, data minimisation, valid consent, transparent information, DPIAs and ongoing security.

Sources

Future Implementation Support Waitlist