Table 9.2.
Privacy measures for an IoT device and an IoT system.

The IoT Devices or the IoT System is accompanied by a specification of the type of data of which it allows the processing.

The IoT Devices or the IoT System is accompanied by a specification of the data flows from/to the outside.

The IoT Devices or the IoT System allows to define and modify the retention times for the various types of data that it stores.

The IoT Devices or the IoT System makes it possible to record the source of the data it stores (e.g., data supplied directly by the person concerned, data extracted from databases…)

The IoT Devices or the IoT System stores only the data necessary for its operation (e.g., it does not store unnecessary data).

If the process of verifying the accuracy of the data entered by the user identifies incorrect or suspicious data, the IoT Devices or the IoT System sends an alert to the competent function or reports it to an administrator (to allow the competent function to be informed).

The IoT Devices or the IoT System retains the date of the last update of each record.

The IoT Devices or the IoT System allows an administrator to “mark” data as restricted (e.g., providing flags in the database that identify the associated field as restricted).

Where applicable, the IoT Devices or the IoT System prevents the processing of restricted data fields (the restricted data field must not be read, modified, deleted, transmitted, displayed, etc. until it is unlocked by the platform administrator. Neither another user nor IoT Devices or the IoT System should be able to do this).

The IoT Devices or the IoT System shall enable the Data Controllers to aggregate in a comprehensible way all the data that it retains in relation to an interested party, allowing the party the ability to modify and visualize it.

The IoT Devices or the IoT System shall enable the Data Controller to record aggregated data in one or more common format files (.csv, .xlsx, .xls, .txt, etc.).

The IoT Devices or the IoT System shall enable the Data Controller to transfer aggregated data relating to a Data Subject in an interoperable format (e.g., XML, CSV, JSON).

The IoT Devices or the IoT System allows to export the aggregated data related to a Data Subject in an interoperable format (e.g., XML, CSV, JSON), flanking them with useful metadata in order to identify them correctly.

If the IoT Devices or the IoT System collects data on minors, it requires the consent of the parental guardians to be entered and given to the Data Controller.

Where applicable, if the IoT Devices or the IoT System collects data on minors, the consent of the parental guardians shall require an express opt in consent.

If the IoT Devices or the IoT System generates scores relating to a Data Subject (e.g., thirdparty data resulting from automatic processing) and the Data Subject did not give his or her consent to automated processing, the IoT Devices or the IoT System makes it

possible that the decision having legal effects on the Data Subject comes from an operator and not from an automated process.

Where applicable, the IoT Devices or the IoT System works in accordance with the consent given by the Data Subjects (e.g., it informs the operators about the consent given and does not make certain types of data available for certain processing operations if their consent was not been given).

Where applicable, the IoT Devices or the IoT System keeps a record of the consent lent or denied, each with its own timestamp.

Where applicable, the IoT Devices or the IoT System shall keep a record of the requests by the Data Subjects to exercise their rights.

The IoT Devices or the IoT System does not feed databases and/or does not transfer personal data to servers not allocated within the European Union in the absence of assessment of adequacy of the country in which the data are transferred and explicit consent requested and provided by the Data Subject/IoT Devices or the IoT System user.

If the IoT Devices or the IoT System is public, the Data Controller shall communicate and ease access to privacy policies in order to allow the Data Subject to review them at any time.

or Create an Account

Close Modal
Close Modal