The UK’s Information Commissioner’s Office (ICO) has published new guidance for manufacturers and developers of smart products to encourage the prioritisation of data protection in their designs.
The privacy watchdog said that the draft guidance will provide regulatory certainty to the IoT industry, outlining clear expectations for firms to comply with data protection law, as well as the responsible use of people’s personal information.
Builds on the ICO’s online tracking strategy for 2025, the guidelines cover areas such as how to ask for informed consent, how to provide transparent privacy information and what tools need to be available for people to exercise their rights over their data.
As well as helping developers stay on the right side of the law to operate fairly and responsibly, the guidance aims to give consumers meaningful choice and confidence in how their information is used.
With many IoT devices relying on the capture of special category information, including data relating to health, biometrics and location, the ICO advice makes it clear that tech manufacturers must meet privacy requirements under UK GDPR rules.
“People rightly have a greater expectation of privacy in their own homes so they must be able to trust that smart products are using their personal information responsibly and only in ways they would expect,” said Stephen Almond, executive director for regulatory risk at the ICO.
“This is not just about compliance – it’s about building a fair and transparent online world where people are given meaningful control over how their data is used.”
Citing the need for more clarity on the current rules, the ICO pointed to an investigation by consumer group Which? late last year, that found evidence that many smart products were able to collect excessive data from users, often without being transparent.
Recommended reading
- Glasgow and Edinburgh Councils Face ICO Reprimand
- ICO Apologises Over Data Protection Response Times
- ICO Publishes New AI and Biometric Tech Strategy
Which? found that certain IoT products were asking for ‘risky’ data, such as permission to record audio on a user’s phone, for no functional reason, with some products’ smart features refusing to work if this was not provided.
“By clarifying our expectations, we can empower organisations to plan and invest in the use of information responsibly,” continued Almond.
“We want to help organisations get it right from the start – but we are closely monitoring compliance and ready to act where we believe corners are being cut or personal information is being collected recklessly.”





