Skip to main content
  • Sections
  • Search

Center for Strategic & International Studies

User menu

  • Subscribe
  • Sign In

   Ranked #1 Think Tank in U.S. by Global Go To Think Tank Index

Topics

  • Climate Change
  • Cybersecurity and Technology
    • Cybersecurity
    • Data Governance
    • Intelligence, Surveillance, and Privacy
    • Military Technology
    • Space
    • Technology and Innovation
  • Defense and Security
    • Counterterrorism and Homeland Security
    • Defense Budget
    • Defense Industry, Acquisition, and Innovation
    • Defense Strategy and Capabilities
    • Geopolitics and International Security
    • Long-Term Futures
    • Missile Defense
    • Space
    • Weapons of Mass Destruction Proliferation
  • Economics
    • Asian Economics
    • Global Economic Governance
    • Trade and International Business
  • Energy and Sustainability
    • Energy, Climate Change, and Environmental Impacts
    • Energy and Geopolitics
    • Energy Innovation
    • Energy Markets, Trends, and Outlooks
  • Global Health
    • Family Planning, Maternal and Child Health, and Immunizations
    • Multilateral Institutions
    • Health and Security
    • Infectious Disease
  • Human Rights
    • Civil Society
    • Transitional Justice
    • Human Security
  • International Development
    • Food and Agriculture
    • Governance and Rule of Law
    • Humanitarian Assistance
    • Private Sector Development
    • U.S. Development Policy

Regions

  • Africa
    • North Africa
    • Sub-Saharan Africa
  • Americas
    • Caribbean
    • North America
    • South America
  • Arctic
  • Asia
    • Afghanistan
    • Australia, New Zealand & Pacific
    • China
    • India
    • Japan
    • Korea
    • Pakistan
    • Southeast Asia
  • Europe
    • European Union
    • NATO
    • Post-Soviet Europe
    • Turkey
  • Middle East
    • The Gulf
    • Egypt and the Levant
    • North Africa
  • Russia and Eurasia
    • The South Caucasus
    • Central Asia
    • Post-Soviet Europe
    • Russia

Sections menu

  • Programs
  • Experts
  • Events
  • Analysis
    • Blogs
    • Books
    • Commentary
    • Congressional Testimony
    • Critical Questions
    • Interactive Reports
    • Journals
    • Newsletter
    • Reports
    • Transcript
  • Podcasts
  • iDeas Lab
  • Transcripts
  • Web Projects

Main menu

  • About Us
  • Support CSIS
    • Securing Our Future
Photo: Adobe Stock
Blog Post - Technology Policy Blog
Share
  • LinkedIn
  • Facebook
  • Twitter
  • Email
  • Printfriendly.com

Privacy, Security, and the Internet of Things

January 30, 2015

According to the Federal Trade Commission (FTC), the Internet of Things (IoT) is currently composed of 25 billion connected devices around the world and the number will double to 50 billion within the next five years.  These devices collect vast amounts of information on industrial and business processes and human health, behavior, and preferences that can be leveraged to improve delivery of products and services, health, and safety. 

IoT will bring significant societal benefits; but without guidance, it could also bring undesired side effects.  To date, the security and privacy of IoT are largely achieved through market preferences and industry self-regulation.  But governments are increasing scrutinizing the privacy and security risks associated with the Internet of Things.

EditRamirez.jpg

On Tuesday, the Federal Trade Commission (FTC) issued a staff report on the Internet of Things, urging companies to adopt data security best practices, minimize the collection and retention of consumer data, and to provide notice and choice to users.  Recognizing the enormous potential for innovation in IoT, the report stated that IoT-specific legislation could stifle innovation at this stage and would therefore be premature.  Instead, the FTC provocatively advocated for new, broad-based legislation that would expand the FTC’s enforcement authority to regulate companies broadly for consumer privacy, as well as the functionality of the devices and services they produce. 

Critics of the report say that the FTC is rushing to conclusions about how to secure IoT devices, particularly on the issues of data minimization and the need for legislation.  They are likely overreacting.

The report highlighted issues that the FTC plans to monitor.  It does not expand the FTC’s enforcement authority.  Nudging companies to adopt improved security best practices through non-regulatory means is a good thing, and it is much needed.  The report was also carefully scoped to include consumer-facing IoT devices, and makes clear that business-to-business and machine-to-machine devices are outside the scope of the report. 

Technology permeates every aspect of modern life.  As users become more tech-savvy, they will demand more control and transparency in regard to how their personal data is collected, stored, and used.  User demand for a consent-based model that provides notice to consumers of how data is used and lets individuals opt out is inevitable.  Companies entering the IoT space should practice privacy-by-design in their product development processes.   

The call for legislation is a statement of support for the White House’s legislative proposal on data security and breach notification released two weeks ago.  Those worried about sweeping regulation should be comforted by the fact that the current Republican-controlled Congress is unlikely to take up legislation that would significantly expand government mandates.

At the end of the day, the U.S. approach to addressing privacy and security risks associated with IoT is still considerably more measured than that of the European Union, which has signaled intent to designate all data produced by IoT devices as protected under the EU Data Protection Directive.

Written By
Denise E. Zheng
Senior Associate (Non-resident), Strategic Technologies Program
Media Queries

Contact H. Andrew Schwartz
Chief Communications Officer
Tel: 202.775.3242

Contact Caleb Diamond
Media Relations Manager and Editorial Associate
Tel: 202.775.3173

More from this blog

Blog Post
The Evolving Role of Artificial Intelligence and Machine Learning in US Politics
In Technology Policy Blog
December 21, 2020
Blog Post
No One is Immune: The Spread of Q-anon Through Social Media and the Pandemic
In Technology Policy Blog
December 17, 2020
Blog Post
Assessing the Impact of U.S.-China Technology Competition and Decoupling: Focusing on 5G
In Technology Policy Blog
December 16, 2020
Blog Post
Covid-19 and the Trajectory of US Venture Capital and Technology Innovation
In Technology Policy Blog
December 3, 2020
Blog Post
Managing U.S.-China Technology Competition and Decoupling
In Technology Policy Blog
November 24, 2020
Blog Post
Applications of Synthetic Aperture Radar Satellites to Environmental Monitoring
In Technology Policy Blog
November 9, 2020
Blog Post
The Goldilocks Porridge Problem with Section 230
By Zhanna Malekos Smith
In Technology Policy Blog
November 3, 2020
Blog Post
Notes from a CSIS Virtual Event: Innovation in the Intelligence Community
In Technology Policy Blog
October 20, 2020

Related Content

On Demand Event
China's Power: Up for Debate
December 4, 2019
Newsletter
RESOLVED: Japan Could Lead Global Efforts on Data Governance
June 27, 2019
Journal
New Perspectives in Foreign Policy Issue 18
By Caleb Diamond, Dana Kim, Eilish Zembilci
October 1, 2019
On Demand Event
A Conversation with Norwegian Deputy Foreign Minister Audun
October 22, 2019
Report
Ties that Bind: Family, Tribe, Nation, and the Rise of Arab Individualism
By Jon B. Alterman
December 2, 2019
Book
Faith in the Balance
October 28, 2019
On Demand Event
Foreign Aid and International Affairs Spending: A Conversation with Chairwoman Nita Lowey (D-NY) and Ranking Member Kay Granger (R-TX)
October 22, 2019
Report
On the Rise: Europe’s Competition Policy Challenges to Technology Companies
By Kati Suominen
October 26, 2020
Footer menu
  • Topics
  • Regions
  • Programs
  • Experts
  • Events
  • Analysis
  • Web Projects
  • Podcasts
  • iDeas Lab
  • Transcripts
  • About Us
  • Support Us
Contact CSIS
Email CSIS
Tel: 202.887.0200
Fax: 202.775.3199
Visit CSIS Headquarters
1616 Rhode Island Avenue, NW
Washington, DC 20036
Media Queries

Contact H. Andrew Schwartz
Chief Communications Officer
Tel: 202.775.3242

Contact Caleb Diamond
Media Relations Manager and Editorial Associate
Tel: 202.775.3173

Daily Updates

Sign up to receive The Evening, a daily brief on the news, events, and people shaping the world of international affairs.

Subscribe to CSIS Newsletters

Follow CSIS
  • Facebook
  • Twitter
  • LinkedIn
  • YouTube
  • Instagram

All content © 2020. All rights reserved.

Legal menu
  • Credits
  • Privacy Policy
  • Reprint Permissions