Sector wise readiness
Automotive and IoT: telemetry is a record of a life
- Is device telemetry personal data under DPDP?
- Usually yes. Telemetry from a connected car is a record of everywhere the driver went, how fast, and when they braked hard. From a wearable it is a heart rate history, and from a smart speaker it is a home.
- Who this affects
- Car makers, wearable makers, smart home and connected device businesses.
- What to do about it
- Set collection limits at design time. Always on sensors collect far more than the function needs, because nobody set a limit.
A misconception I keep seeing when car makers, wearables and smart home companies read DPDP checklists: "we sell hardware, the data is just telemetry."
Telemetry from a connected car is a record of everywhere the driver went, how fast, and when they braked hard. From a wearable, it is a heart rate history. From a smart speaker, it is a home.
The auditor's red flag here is exactly this: always on sensors collect far more than the function needs. A device that could stream everything usually does, because nobody set a limit at design time.
A sector map is a superset, not a launch checklist.
What applies from the start, whatever your size
- ✅ Notice
- ✅ Consent and easy withdrawal
- ✅ Security safeguards
- ✅ Rights handling
- ✅ Grievance mechanism
- ✅ Processor contracts
- ✅ Breach response
What connected devices carry from day one
- ✅ A basis and minimisation for device data. Telematics, location and sensor data need a clear basis, and you should collect what the function needs, not everything the sensor can produce.
- ✅ Device to cloud security. Encrypt the link, control access, and secure your over the air updates. An insecure update channel is a route into every device you ever sold.
- ✅ Cross border telemetry. Global device clouds move data offshore by default. Map it and be ready to restrict it.
- ✅ Separate consent for secondary use. Sharing driving data with an insurer, or running your own analytics on device data, is a new purpose. It needs its own consent, not the one the user gave to make the device work.
What may not apply yet
- ❌ SDF obligations. Large connected device fleets are plausible candidates to assess, but Significant Data Fiduciary status comes only on Government notification, not from units shipped.
- ❌ A mandatory Data Protection Officer, annual DPIAs and independent audits. These attach to SDF status once notified.
The better question
The better question is not "is sensor data really personal data?"
It is "if we printed one week of one device's data, would the owner be comfortable reading it?"
Law creates obligations. Scale and risk influence implementation. But minimisation and device security are design decisions. They apply from your first unit, and they are far cheaper before launch than after.
If you build connected products, does your device collect what the function needs, or what the sensor can reach?