CIO Applications Europe
About UsConferencePartner With Us
Close
  • Applications
      • Business Intelligence & Analytics
      • Call Center Solutions
      • CRM & Customer Experience
      • Data Center
      • Digital Transformation
      • E-Invoicing
      • Intelligent ERP & Automation
      • Risk Management & Compliance
      • Unified Communications (UCaaS)
  • Industries
      • Automotive & Mobility
      • Construction & Infrastructure
      • Financial Services
      • Healthcare
      • Retail & E-commerce
      • Telecom & Media
      • Travel and Hospitality Tech
  • Technologies
      • Cloud
      • Cybersecurity & Resilience
      • Data Engineering & Analytics
      • Generative and Agentic AI
      • IoT & Edge Computing
      • Robotics
  • Platforms
      • AWS
      • IBM
      • Microsoft
      • Salesforce
      • SAP
      • ServiceNow
  • Leadership Perspectives
  • Innovation Insights
  • Research
  • News
  • CXO Awards
    • Europe
      • US
  • Topics

  • Menu
      • Business Intelligence & Analytics
      • Cloud
      • Digital Transformation
      • Generative and Agentic AI
      • Microsoft
      • Risk Management & Compliance
      • Travel and Hospitality Tech
      • Unified Communications (UCaaS)
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Generative and Agentic AI
  • Digital Transformation
  • Business Intelligence & Analytics
  • Cloud
Topics
  • Topics

  • Business Intelligence & Analytics
  • Cloud
  • Digital Transformation
  • Generative and Agentic AI
  • Microsoft
  • Risk Management & Compliance
  • Travel and Hospitality Tech
  • Unified Communications (UCaaS)
  • Home
  • IoT

A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by the Construction Tech Review Advisory Board.

Barclays

Nicole Sandler, Vice President (VP) Fintech and Regtech

IoT a moving regulatory landscape

The Internet of Things (IoT) is now a reality, enabling connected devices to interact with each other and to collect and share data on an unprecedented scale. Some use cases have already proven themselves, such as in insurance, where telematics monitor driver behaviour. Alongside enabling the full automation of the vast majority of payments, IoT-generated data may boost innovation in banking, as well as allowing for more accurate risk management.

As with many new technologies, it is important to consider the regulatory and legal challenges that arise from adoption of the IoT and the new regulatory frameworks that are being employed, particularly in an era where data is key. The General Data Protection Regulation (GDPR) and ePrivacy Regulation are two notable frameworks. It is anticipated that new business models will develop as a result of the development of the IoT and regulatory frameworks may be subject to change and evolution.

IoT and data privacy

In a number of cases, IoT products collect data on their users and their interests and behaviours, all of which are of great value to businesses. From a legal perspective, most of this data will be classified as personal data and is therefore subject to protections both in terms of data protection and data security.

In May 2018 the GDPR comes into force. The aims of the new GDPR are to harmonise the current data protection laws in place across the EU Member States, to make companies take the issue of data protection more seriously, and to strengthen an individual’s rights over their data. Whilst not all IoT use cases are about personal data, some are, and therefore GDPR will need to be taken into account, not least because there are substantial fines for non-compliance or data breaches (up to the higher of 4 per cent of annual worldwide turnover and EUR20 million). Moreover, it is worth highlighting that this regulation has extra-territorial scope, and therefore also applies to businesses based outside the EU that offer goods and services (even if they are for free) to consumers, or that monitor individuals in the EU.

In addition to the GDPR, another framework that specifically mentions the IoT is the ePrivacy regulation which focuses on all electronic communications.

Whilst the text is not yet finalised and the date of enforcement is still unclear, the future ePrivacy rules could end up eclipsing the GDPR where IoT is concerned, as a result of its wide significant scope of application which could potentially cover all data related to connected devices. Akin to the GDPR, this regulation also looks to be armed with equally large fines and extra-territorial application.

Too early to regulate?

Regulators have been considering whether to regulate IoT technologies for several years already. They have so far shied away from proposing concrete new regulatory approaches to the IoT, opting instead for recommendations of principle, in particular stressing the need for developers to adhere by the practice of privacy and security by design.

Furthermore, policy-makers’ focus is largely on the promotion of open standards for IoT communication protocols to avoid fragmentation and to foster interoperability for IoT technologies to reach their potential. However, as the technology matures, it is apparent that they pose new threats that existing data and cyber-security regulation may not address. This notably includes the need for clarification on the allocation of responsibility for security breaches or liability for damages resulting from a fault in a connected device.

It is imperative that the industry, policy-makers and regulators work together to mitigate the risks. There are various ways for firms and businesses to engage with both regulators and policy-makers. A common approach is to respond to discussion papers (DPs) and consultation papers (CPs) or to attend roundtables. Over the past couple of years there has been an increase in roundtables, DPs and CPs from international regulators, policy-makers and supranationals (including ESMA, IOSCO, the ECB and the European Commission), and domestic regulators and policymakers (including the FCA). Other key approaches include attending working groups, public hearings, bilateral meetings, conferences and through forums/tools such as the FCA’s sandbox - a safe space for businesses to test innovative products, services, business models and delivery mechanisms in the real market, with real consumers. These forms of engagement allow the industry to educate each other and understand the problems and pain-points in order to collaboratively understand how these should be approached and solved. As technology continues to help drive business models, the industry needs to continue engaging.

IoT complexity magnifies cyber security risk

With the explosion of devices and sensors, cybersecurity takes on a whole new dimension, not just for financial institutions, but also for their customers. Whilst the IoT provides new ways for businesses to create value, at the same time data sharing and connectivity offers new opportunities for information to be jeopardized. For instance, a key issue with low-priced IoT devices which are connected directly into the public internet is that they have a low security threshold and are unlikely to have regular security patches. This has been exploited by the Mirai botnet which targets vulnerable devices. While to date Mirai infected bots’ attacks have been most prevalent in Europe and the US, Mirai infected bots are a global phenomenon. In 2016 security researchers determined that over a half a million IoT devices located in 164 jurisdictions were vulnerable to Mirai. Due to the compound effect of the numerous devices it would be beneficial if devices connected to the internet should have a regulatory requirement to meet a certain threshold of both initial security standards and ongoing bug fixes.

According to a report by Gartner there will be over 20 billion connected devices by 2020, all of which represent a portal to the network which can be hacked or compromised. Therefore, the promotion of security by design is essential to guaranteeing end-to-end security across the whole financial services chain.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
The Leadership Perspectives forum brings together voices shaping construction technology and innovation. Participation is by invitation only. It features leaders who are not merely observing technological change, but actively contributing to it through digital transformation and execution-driven insights.
EDITOR'S CHOICE
  • Willis Towers Watson

    Legal & General

    Building Technology Foundations That Last

    Mark Hall, Group Chief Technology Officer

  • Willis Towers Watson

    Adp Uk

    "Shift left" Defect Discovery using Agile and DevOps

    Keith Watson, Director Of Devops

  • Willis Towers Watson

    Motor Oil

    Trust, Security Strategy and the AI-Driven Threat Landscape

    Syngelakis J. Christos, Group Data Protection Officer

  • Willis Towers Watson

    Swiss Re [SWX: SREN]

    A Future of Enhanced Human Work

    Sergio Chelli, IT Procurement Manager at Swiss Re [SWX: SREN]

Weekly Brief

loading

I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

×
#

CIO Applications Europe Weekly Brief

Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from CIO Applications Europe

Subscribe

loading

THANK YOU FOR SUBSCRIBING

CIO Applications Europe
Follow on LinkedIn

About

  • Home
  • About Us
  • Partner With Us

Stay Connected

  • Subscribe
  • Newsletter
  • Sitemap

Contact Us

  • editor@cioapplicationseurope.com
  • sales@cioapplicationseurope.com
  • marketing@cioapplicationseurope.com

Legal

  • Editorial Policy
  • Privacy Policy
  • Terms of Use

© 2026 CIO Applications Europe. All rights reserved. Headquarteblue in Fort Lauderdale, FL, USA.

This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://iot.cioapplicationseurope.com/leadership-perspective/iot-a-moving-regulatory-landscape-nid-132.html