What changed
The ICO has published final guidance for consumer Internet of Things products and services, setting clearer expectations for manufacturers and developers that use personal data through connected devices.
The guidance covers products such as smart speakers, connected televisions, fitness trackers, smart doorbells, home hubs and domestic appliances. It sets out expectations around privacy by design, data minimisation, meaningful consent, transparent information, security and tools that allow people to exercise their information rights.
What is a smart device?
A smart device is a connected product that collects, uses or shares information through an internet connection. This can include devices used in the home, wearable technology, connected entertainment systems and apps or cloud services that support them.
Why this matters
Smart devices can collect detailed information about people’s routines, behaviour, health, location, household activity and preferences. The ICO’s guidance makes clear that privacy should be considered from the earliest stages of product design, rather than added later through a privacy notice or settings page.
The guidance is relevant not only to device manufacturers, but also to app developers, operating system providers, cloud providers and other organisations involved in the consumer IoT supply chain. For wider developments across privacy, technology and data protection, see our Regulatory Updates page.
What organisations should do
Organisations involved in smart-device products or services should review whether privacy, consent and security are built into the product lifecycle.
- Check whether data collection is limited to what is genuinely necessary for the product or service.
- Use protective privacy settings by default wherever possible.
- Make consent clear, specific, freely given and easy to withdraw.
- Provide privacy information in plain language at relevant points throughout the user journey.
- Assess whether a Data Protection Impact Assessment is required, particularly where sensitive data or children may be involved.
- Review whether security measures such as updates, encryption and multifactor authentication are maintained throughout the product’s lifetime.
Practical takeaway
Smart-device privacy cannot rely on hidden settings or a lengthy privacy notice. Organisations should be clear about what data they collect, why they need it, how people can control it and how security will be maintained over time.
Grounded in
ICO final guidance on consumer Internet of Things products and services, including expectations around privacy by design, data minimisation, valid consent, transparent information, DPIAs and ongoing security.
Sources
- Information Commissioner’s Office: setting out our expectations for the smart device industry , 11 June 2026.
- Information Commissioner’s Office: guidance on consumer Internet of Things products and services .