GDPR and the transformation of IoT security

GDPR and the transformation of IoT security

GDPR’s eighth anniversary puts IoT security design back under scrutiny. As connected device fleets expand, compliance is increasingly tied to secure identity, encrypted data, update support, supplier assurance, and lifecycle risk management.


IN Brief:

  • GDPR’s eighth anniversary arrives as IoT deployments continue to expand across consumer, industrial, medical, transport, and energy systems.
  • Connected device compliance now increasingly depends on secure identity, encryption, update mechanisms, supplier assurance, and incident response.
  • Regulation can set minimum expectations, but resilient IoT products require security and privacy decisions to be made during design.

By the time this June issue lands, GDPR’s eighth anniversary will have passed, but the regulation’s afterlife is still shaping how connected products are designed, sold, supported, and defended. What began as a major reset for data protection has become part of a wider compliance environment in which privacy, cybersecurity, software maintenance, and product assurance are increasingly difficult to separate.

As connected devices have moved deeper into homes, factories, vehicles, medical environments, and energy infrastructure, the regulatory burden around them has also widened. The EU AI Act, Cyber Resilience Act, Data Act, and national product security regimes all point towards a more demanding model of accountability, where a product’s compliance position depends not only on what it does at launch, but how it behaves when deployed, updated, integrated, and eventually exposed to attack.

Across the IoT market, the scale of deployment is stretching that model further. Transforma Insights has forecast that active IoT devices will rise from 17.7 billion at the end of 2024 to 40.6 billion by 2034, adding billions of endpoints that collect data at the edge, connect through third-party platforms, and often operate beyond a conventionally managed IT perimeter. Each additional device may be small, low-cost, and functionally narrow, but across a fleet it becomes part of a much larger system of identity, access, data movement, and operational risk.

Iain Davidson, Head of Product Marketing at Wireless Logic, says the threat landscape has changed sharply since GDPR became applicable. “In the years since the GDPR came into force, the threat landscape has changed drastically. In the IoT sector, we’re seeing this through growing device fleets, edge data collection, opaque models, cross-border data flows and devices operating outside the traditional IT perimeter. New technologies like AI are also creating risks to data privacy and protection that move faster than regulation.”

Where compliance once risked being treated as a late-stage documentation exercise, connected product security now has to be reflected in the engineering decisions made before hardware ships or firmware enters the field. Secure device identity, encrypted data in transit and at rest, segmented network access, signed firmware updates, patch management, supplier assurance, anomaly detection, and rehearsed incident response processes all become more effective when they are part of the design brief, rather than controls applied after architecture is already fixed.

Within that shift, standards and regulation still have a central role, but they cannot carry the whole burden of risk management. Davidson argues that enterprises need “a clear and systematic risk logic,” allowing them to “understand business context, identify where the real cyber and privacy risks sit – and then apply proportionate controls to build resilience and protect data.” The useful word is proportionate: a low-power sensor, an industrial gateway, and an AI-enabled medical device will not justify identical controls, but each needs a defensible view of what data it handles, who can reach it, how it is updated, and what happens when compromise occurs.

Once those questions are brought forward into product development, privacy and security become less of a constraint on innovation and more of a test of design discipline. A device that collects only the data it needs, stores it for a defined period, limits access by role, supports updates, and can be isolated during an incident is easier to justify to customers, regulators, and supply chain partners. The alternative is a familiar one: a product that appears compliant at release, then becomes increasingly difficult to defend as its software ages, integrations multiply, and attackers find the gaps between legal obligation and technical reality.

Eight years on from GDPR, the compliance environment around IoT is no longer waiting for one regulation to define the next move. The direction is already visible across privacy law, cyber rules, product security standards, and emerging AI governance. Regulation can set the floor, but resilience will depend on how well manufacturers turn those requirements into design choices before devices enter a market heading towards tens of billions of connected endpoints.

This article originally appeared in the May/June 2026 edition of IN Electronics. Read the full issue here.


Stories for you


  • ROHM board reduces buck-boost mounting area

    ROHM board reduces buck-boost mounting area

    ROHM’s compact evaluation board reduces buck-boost converter mounting area substantially. The five-component reference design occupies 12.87mm² while retaining low quiescent current and high efficiency.


  • ams OSRAM broadens IR:6 emitter platform

    ams OSRAM broadens IR:6 emitter platform

    ams OSRAM has broadened its higher-efficiency infrared emitter technology platform. IR:6 devices cover 850nm, 920nm, and 940nm applications across sensing, biometrics, medical equipment, and machine vision.