[Home](/)/[Resources](/resources)/UK GDPR for Connected Products

UKPrivacyRegulation guide

# UK GDPR and Connected Products — Privacy by Design

UK GDPR (retained under the Data Protection Act 2018) applies to any connected hardware product that collects, processes, or transmits personal data about UK users. From user activity tracking to location data and biometrics, IoT and connected products are some of the highest-risk data processing environments the ICO examines. Privacy by design is not optional — it is a statutory obligation under Article 25.

Copy Link[Share on WhatsApp](https://wa.me/?text=https%3A%2F%2Fkrono-labs.com%2Fguides%2Fuk-gdpr-connected-products)

At a glance

Legislation

UK GDPR / DPA 2018

Regulator

ICO

Key article

Article 25 (Privacy by Design)

Max penalty

£17.5M or 4% global turnover

Territorial scope

Extraterritorial

## When UK GDPR applies to your connected product

Most connected hardware manufacturers underestimate their exposure. The threshold for UK GDPR applicability is low — any product that generates, captures, or relays data that can be linked to an individual engages the regulation. Four scenarios are consistently relevant to hardware product teams.

### Device collects personal data

Location coordinates, biometric identifiers, health and wellness metrics, behavioural usage patterns, voice recordings, and image data all constitute personal data under UK GDPR Article 4(1). If the device generates or stores any of these, UK GDPR applies.

### Device transmits data to servers

Any transmission of personal data from the device to a cloud backend, analytics platform, or third-party service is a processing activity. The manufacturer is typically the controller; cloud providers are processors requiring a Data Processing Agreement (DPA).

### App or platform processes user data

Companion apps, web dashboards, and management platforms that process data derived from device use are within scope. Mobile app analytics, crash reporting SDKs, and push notification services are common areas of non-compliance.

### UK users in scope regardless of manufacturer location

Article 3 of UK GDPR applies extraterritorially. Any manufacturer offering products to UK users or monitoring their behaviour is subject to UK GDPR, even if the company has no UK establishment. A UK Representative may be required.

**Lawful basis:** Controllers must identify a lawful basis before processing. For connected products, the most common bases are consent (explicit, freely given, specific, informed, and unambiguous — must be withdrawable), legitimate interests (requires a balancing test; the ICO scrutinises this closely for IoT), and contract (processing necessary to deliver the service the user signed up for). Special category data — health metrics, biometrics, precise location patterns — requires a separate condition under Article 9.

## Article 25 Privacy by Design obligations

Article 25 UK GDPR makes privacy by design a legal requirement, not a best practice. Controllers must implement appropriate technical and organisational measures at the time of designing the processing system and at the time of the processing itself. For hardware, this means privacy controls must be specified in product requirements, implemented in hardware and firmware, and tested before release — not bolted on after a regulator inquiry.

01

Data minimisation at the hardware design stage — collect only what is strictly necessary for the stated purpose, enforced at sensor and firmware level.

02

Purpose limitation in firmware and app — data collected for one function must not be repurposed without fresh lawful basis or user consent.

03

Access controls and authentication — devices must enforce strong authentication to prevent unauthorised access to personal data streams.

04

Encryption in transit and at rest — personal data must be protected with appropriate cryptographic controls throughout its lifecycle on and off the device.

05

User control and deletion mechanisms — users must be able to access, correct, and erase their data; deletion must propagate to device storage, cloud, and third-party processors.

06

Retention limits enforced in firmware — automated deletion or anonymisation schedules should be built into device logic, not left as a manual process.

07

Security as a design requirement — overlaps with PSTI Act obligations; security controls must be documented in the technical file and kept current through the product lifecycle.

## DPIA requirements for connected products

A Data Protection Impact Assessment is a structured risk analysis process required by Article 35 UK GDPR before commencing high-risk processing. For connected hardware, the question is rarely whether a DPIA is needed — it almost always is — but whether it has been done properly and kept current as firmware and features evolve.

### When a DPIA is mandatory

Under Article 35 UK GDPR, a DPIA is required for systematic and extensive profiling, large-scale processing of special category data (health, biometric, location), or use of new technologies. The ICO's list of processing types requiring a DPIA includes smart devices with continuous monitoring capability.

### What a DPIA must cover

Description of processing operations and purposes; necessity and proportionality assessment; risk identification (to rights and freedoms of data subjects); risk mitigation measures; and residual risk sign-off by the Data Protection Officer or senior management.

### ICO prior consultation triggers

Where residual risk remains high after mitigation, the controller must consult the ICO before commencing processing. The ICO has 8 weeks (extendable to 14 weeks) to respond. Proceeding without consultation where required is itself an infringement.

### DPIA template structure for hardware

Hardware DPIAs should include: data flow diagrams showing on-device, in-transit, and at-rest processing; firmware version control showing privacy controls; third-party SDK inventory with DPAs; retention schedules; and security architecture summary cross-referenced to PSTI technical requirements.

## ICO enforcement priorities for IoT

The ICO has been increasingly active in the connected product space. Enforcement actions and investigations reveal the ICO's focus areas: tracking and profiling without adequate consent, products targeting children, and health data processed without appropriate safeguards. Understanding past enforcement helps hardware teams identify where scrutiny is likely.

### ICO enforcement against smart TV and streaming device tracking

The ICO has investigated automatic content recognition (ACR) and behavioural profiling by smart TV manufacturers. Key issues: inadequate consent mechanisms, lack of granular opt-out, and opaque data sharing with advertising networks.

### Children's smart devices and the Age Appropriate Design Code

The ICO's Children's Code (UK GDPR Article 25 + s.123 DPA 2018) applies to connected products likely to be accessed by under-18s. Requirements include: high privacy defaults, no nudge techniques to weaken privacy settings, no geolocation tracking without prominent notice, and data minimisation by default.

### Health wearables and special category data

Health and fitness wearables processing biometric or health data engage Article 9 UK GDPR. Explicit consent is typically required as the lawful basis for special category data. Processing for research purposes requires additional safeguards under Schedule 1 DPA 2018.

## Frequently asked questions

### Does UK GDPR apply if our company is outside the UK?

Yes. UK GDPR Article 3 applies to any controller or processor outside the UK that offers goods or services to UK data subjects, or monitors their behaviour. Manufacturers selling connected products to UK consumers are subject to UK GDPR regardless of where the company is incorporated. A UK Representative must be designated unless the processing is occasional, low-risk, and does not involve large-scale special category data.

### What constitutes personal data for a connected hardware product?

Personal data is any information relating to an identified or identifiable natural person. For connected products this includes: precise and approximate location data, IP addresses assigned to the device, biometric data from sensors (fingerprint, heart rate, face), usage behaviour that can be linked to a user account, device identifiers (MAC address, serial number) where linked to a person, and voice or image recordings. Truly anonymised aggregated data falls outside scope but anonymisation must be robust and irreversible.

### When is a DPIA mandatory for a connected product?

A DPIA is mandatory under UK GDPR Article 35 when processing is likely to result in high risk to individuals. For connected products, mandatory triggers include: systematic monitoring of individuals in a public or private space, large-scale processing of special category data (health, biometric), processing that uses new technologies where the impact is uncertain, and any processing type on the ICO's published list of processing operations requiring a DPIA. If your product continuously collects location or health data, a DPIA is almost certainly required.

### How does the UK Children's Code affect connected products that minors might use?

The ICO Age Appropriate Design Code (Children's Code) applies to information society services likely to be accessed by children under 18, which includes connected consumer products with digital interfaces. Key obligations include: geolocation services must be off by default; profiling for non-essential purposes must be off by default; nudge techniques that encourage children to share more data or weaken privacy settings are prohibited; and parental controls must be implemented proportionately. Non-compliance can result in enforcement action under UK GDPR as well as specific DPA 2018 provisions.

**Disclaimer:** This page is an educational resource only and does not constitute legal advice. UK GDPR compliance requirements depend on the specific nature of your product, processing activities, and business structure. Consult qualified legal counsel and review ICO guidance for your particular circumstances.

🇬🇧 UK roadmap for your product

Every standard, document, and test that applies — free, no account required.

See your free roadmap[

Want an expert to take your product through 🇬🇧 UK compliance for you?

One consultant from Krono's compliance team takes your product from requirements to legal sale, with a fixed quote before any work starts.

See compliance services](/services)

Learn this properly

In-depth course that teaches the full process, not just this one answer.

[Start the course — $149](/courses/09-ukca-marking-for-electronics-products)[Prefer to read? Get the book — $24.99](/books/09-ukca-marking-for-electronics-products)

Related guides

*   [UK PSTI Security RequirementsComplete guide to UK PSTI Act: security requirements for connectable products, compliance obligations, statement of compliance,…](/guides/uk-psti-security)
*   [UK NIS RegulationsThe UK NIS Regulations 2018 create supply chain obligations that affect hardware and IoT product suppliers to regulated sectors.](/guides/uk-nis-regulations)
*   [India DPDP Act for HardwareHow India's Digital Personal Data Protection Act 2023 applies to connected hardware — consent architecture, data fiduciary obli…](/guides/india-dpdp-act-hardware)
*   [UK AI Product RegulationComplete guide to UK AI regulation for product manufacturers: current UK AI governance framework, AI Safety Institute, interact…](/guides/uk-ai-product-regulation)
*   [UK Online Safety Act for Connected DevicesHow the Online Safety Act 2023 reaches hardware companies whose products ship with companion apps or cloud services: regulated service classification, illegal content duties, age assurance, and where it stops and PSTI begins.](/guides/uk-online-safety-act-connected-devices)