Tuesday

22nd May 2018

Column / Brussels Bytes

EU e-privacy proposal risks breaking 'Internet of Things'

  • The 'Internet of Things' is linking traditional online devices - such as computers and smartphones - to everyday items such as fridges, thermostats and music systems. (Photo: Marcus JH Brown/Flickr)

The 'Internet of Things' - smart devices that transmit data over a network - offer myriad benefits to European society, from helping people keep track of their fitness and providing drivers with live traffic information, to monitoring air quality and automating homes and factories.

But the forthcoming ePrivacy Regulation (ePR) could throw sand in the gears of such progress by unnecessarily regulating Internet of Things (IoT) devices.

Thank you for reading EUobserver!

Subscribe now for a 30 day free trial.

  1. €150 per year
  2. or €15 per month
  3. Cancel anytime

EUobserver is an independent, not-for-profit news organization that publishes daily news reports, analysis, and investigations from Brussels and the EU member states. We are an indispensable news source for anyone who wants to know what is going on in the EU.

We are mainly funded by advertising and subscription revenues. As advertising revenues are falling fast, we depend on subscription revenues to support our journalism.

For group, corporate or student subscriptions, please contact us. See also our full Terms of Use.

If you already have an account click here to login.

  • Items within your own household could 'talk' to each other - in the way that email connected the world (Photo: internetfestival.it)

To fix the problem, EU policymakers need to clarify that the ePR should not apply to most IoT devices.

In contrast to the General Data Protection Regulation (GDPR), which imposes strict limits on how companies can use personal data in general, the ePR proposes even stricter rules to protect the secrecy of electronic communications, like emails and voice calls.

The ePR would prohibit all data processing not necessary to provide a service and require explicit user consent in all cases, while the GDPR is more flexible.

Smartwatches and baby monitors

The European Commission's latest draft of the ePR stresses that it applies to machine-to-machine (M2M) transmissions, which would include all the data flowing between IoT devices, but the proposal makes no distinction between M2M transmissions that contain human communications, like smartwatches and baby monitors, and those that do not, like internet-connected air and water quality sensors.

For example, the ePR proposal could require drivers using live traffic information services to consent to data processing each time their car enters the range of a new sensor network and tries to exchange data with road sensors.

This is not practical.

Drivers cannot safely study a privacy agreement and truthfully confirm having read, understood, and agreed while navigating traffic.

The GDPR, on the other hand, would allow pre-existing contracts with the driver as a substitute for direct consent, and even that would only be necessary if the transmission carries personal data.

Not feasible

Clearly not all M2M transmissions involve interpersonal communications, and treating them as if they do would render many services that rely on this data inconvenient at best, and unfeasible at worst.

The GDPR already provides adequate protection for the privacy of personal information transmitted by IoT devices, while devices that transmit neither personal information nor private communications between people, like air quality monitors, need not be subject to either law.

The heart of the problem is that the ePR does not clearly specify which types of M2M transmissions the regulation would apply to.

Before the ePR becomes law, EU policymakers should clarify the regulation so that it only covers services that enable communications between people.

Indeed, there is a proposal before the Council of the European Union to exclude M2M services from the ePR, except where they enable "interpersonal and interactive communication."

Such a change would mean the ePR protects communications that rely on M2M transmissions, like voice conversations, while M2M services that carry personal data but are not for communications between people, like fitness tracking, would fall under the general provisions of the GDPR.

Transmissions that contain neither communications between people nor personal data need not be subject to any privacy rules at all.

EU policymakers have already created major problems for Europe's digital economy with the GDPR, which imposes several unnecessary restrictions—particularly on the use of artificial intelligence—that will undermine technological innovation in Europe, often without increasing consumer protection.

By adding even tighter restrictions, the ePR is likely to further limit EU digital innovation.

But unlike the GDPR, the ePR is not yet finalised, and policymakers can still easily change it. The scope of the ePR is needlessly broad, and policymakers should narrow it down while they still have the opportunity.

Nick Wallace is a Brussels-based senior policy analyst at the Centre for Data Innovation. His Brussels Bytes column deals with the digital single market and data-related policy issues in the European Union

Column / Brussels Bytes

ECJ should rule against Austrian online censorship lawsuit

EU judges have an opportunity to make clear that no member state can decide what the rest of the world reads online, now that Austria's Supreme Court has referred the Glawischnig case to the European Court of Justice.

Column / Brussels Bytes

Some EU regulators still don't get internet economics

New EU data protection rules threaten the European digital economy, but recent actions by some national regulators remind us why EU-wide rules cannot come soon enough.

Are EU data watchdogs staffed for GDPR?

The success of the new general data protection regulation (GDPR) will depend on whether data protection authorities enforce the new rules - which, in turn, will be at least partly determined by how many people they employ.

Opinion

Cybersecurity and defence for the future of Europe

Cybersecurity is a core element of Europe's strategy to become a global leader in digital technologies and a secure place for its citizens, write EU commissioner Jyrki Katainen and expert Jarno Limnell.

New EU fines will apply to 'old' data breaches

On 25 May, a new general data protection regulation will apply. Data breaches that happened before that date, but were covered up, can be fined under the new regulation.

Stakeholders' Highlights

  1. Nordic Council of MinistersOECD Report: Gender Equality Boosts GDP Growth in Nordic Region
  2. Centre Maurits Coppieters“Peace and reconciliation is a process that takes decades” Dr. Anthony Soares on #Brexit and Northern Ireland
  3. Mission of China to the EUMEPs Positive on China’s New Measures of Opening Up
  4. Macedonian Human Rights MovementOld White Men are Destroying Macedonia by Romanticizing Greece
  5. Counter BalanceControversial EIB-Backed Project Under Fire at European Parliament
  6. Nordic Council of MinistersIncome Inequality Increasing in Nordic Countries
  7. European Jewish CongressEU Leaders to Cease Contact with Mahmoud Abbas Until He Apologizes for Antisemitic Comments
  8. International Partnership for Human RightsAnnual Report celebrates organization’s tenth anniversary
  9. Nordic Council of MinistersNordic Cooperation Needed on Green Exports and Funding
  10. Mission of China to the EUPremier Li Confirms China Will Continue to Open Up
  11. European Jewish CongressCalls on Brussels University to Revoke Decision to Honour Ken Loach
  12. Sustainable Energy Week 2018"Lead the Clean Energy Transition"- Register and Join Us in Brussels from 5 to 7 May

Latest News

  1. Are EU data watchdogs staffed for GDPR?
  2. EU pessimistic on permanent US trade exemption
  3. US asks EU to go after Russian and African villains
  4. Facebook threatened with removal from EU-US data pact
  5. Defence firms 'reap benefits' of their advice to EU
  6. Athens mayor wants direct access to EU migration fund
  7. Nordics could be first carbon-negative region in world
  8. Zuckerberg and Trump top the EU's agenda This WEEK

Stakeholders' Highlights

  1. EU Green Week 2018Green Cities for a Greener Future. Join the Debate in Brussels from 22 to 24 May
  2. Nordic Council of Ministers12 Recommendations for Nordic Leadership on Climate and Environment
  3. Macedonian Human Rights MovementOxford Professor Calls for an End to the Anti-Macedonian Name Negotiations
  4. ACCAPeople Who Speak-Up Should Feel Safe to Do So
  5. Mission of China to the EUProgress on China-EU Cooperation
  6. Nordic Council of MinistersWorld's Energy Ministers to Meet in Oresund in May to Discuss Green Energy
  7. ILGA EuropeParabéns! Portugal Votes to Respect the Rights of Trans and Intersex People
  8. Mission of China to the EUJobs, Energy, Steel: Government Work Report Sets China's Targets
  9. European Jewish CongressKantor Center Annual Report on Antisemitism Worldwide - The Year the Mask Came Off
  10. UNICEFCalls for the Protection of Children in the Gaza Strip
  11. Mission of China to the EUForeign Minister Wang Yi Highlights Importance of China-EU Relations
  12. Nordic Council of MinistersImmigration and Integration in the Nordic Region - Getting the Facts Straight