Who is responsible for data processing in smart homes? Reconsidering joint controllership and the household exemption

Jiahong Chen, Lilian Edwards, Lachlan Urquhart, Derek McAuley · International Data Privacy Law · 2020

The growing industrial and research interest in protecting privacy and fighting cyberattacks for smart homes has sparked various innovations in security- and privacy-enhancing technologies (S/PETs) powered by edge computing. The complex technical set-up has however raised a whole series of legal issues surrounding the regulation of smart home with data protection law. To determine how responsibility and accountability should be fairly assumed by stakeholders, there is a pressing need to first clarify the roles of these parties within the existing data protection legal framework. This article focuses on two legal concepts under the General Data Protection Regulation (GDPR) as the mechanisms to (dis)assign responsibilities to various categories of entities in a domestic Internet of Things (IoT) context: joint controllership and the household exemption. A close examination of the relevant provisions and case-law shows a widening notion of joint controllership and a narrowing scope for the household exemption. While this interpretative approach may prevent evasion of accountability in specific cases, it may lead to the unintended consequence of imposing disproportionate compliance burdens on developers, contributors, and users of smart home safety technologies. By discouraging users to adopt S/PETs, data protection law may likely lead to a lower level of privacy and security protection. The differential responsibilities among joint controllers as envisaged in case-law may reconcile the tensions to some degree, but certain limitations remain. The regulatory dilemma in this regard highlights some underlying assumptions of data protection law that are no longer valid with regard to a smart home, and thus calls for further conceptual and empirical studies on fair reassignment of responsibility and accountability in a domestic IoT setting. Smart home Internet of Things (IoT) devices are notoriously badly secured. Commercial practices geared towards usability see devices shipped with default passwords, but users rarely change these. This has led to cases of IP connected cameras being remotely accessible via search engine Shodan, enabling babies to be monitored sleeping.1 Similarly, poorly secured devices can be more vulnerable to remote access attacks, implicating them in botnets. We have seen this in the case of the Mirai,2 Persirai3 and Reaper4 botnets.5 Concurrently, there are growing concerns about the personal data-driven economy resulting from new compliance requirements and high fines under the General Data Protection Regulation (GDPR).6 A key issue is the dominant cloud-based big data analytics infrastructure dominating IoT product and service design. It enables creation of cheaper devices with data collected locally, analysed remotely, and the service provided locally again.7 These IoT privacy and security concerns have sparked a growing research agenda in creating local data storage and analysis infrastructures, where data analytics is brought to the data, as opposed to centralizing the data. This provides users more control over who accesses their data, why, for how long, and so forth. From a regulatory perspective, the European Data Protection Supervisor (EDPS) has extolled the virtues of such personal information management systems (PIMS) sitting at the edge of the network,8 as has a recent Royal Society report.9 Development and adoption of security- and privacy-enhancing technologies (S/PETs) are not just priorities on the EU’s Digital Single Market Strategy,10 but indeed encouraged or by the the of these technologies on a legal with regulatory provided for and users of such technologies and imposing compliance burdens on We however have concerns over the of data protection law on in a domestic IoT how responsibility and accountability are to various of under the legal framework. The notion of joint controllers and the household are of as as the mechanisms to the parties to data protection requirements are To the of joint controllership and the household for domestic IoT with edge this article at two research The by the and how data protection can be data by personal data and analysed on a local to users to from the of their data their data by how it enables as in of the by mechanisms for but smart home by for security management at the edge of the This is by the of devices on the and is data are to or this may with remote access or The and of and on the and analysis of data may to be personal or and a of who may or may not be as data controllers or data The of legal in IoT has in the and further such surrounding such systems and and and may be these pressing in and about how responsibilities are and who the a for a has the smart home with such should be as a data can are from the on the of a household about the such as of the and as be these may to the fair of data protection responsibility and accountability among a of for smart homes with to the of personal data the home, but it such technologies joint the of this article the joint controllers and the household have in the to protection to data to this by creating the of such as and who is for of data protection the first is to the data or the accountability of the data is the for compliance of data protection While categories of such as data or be of data a in data protection are the burdens on data The has the of data as under the Data Protection is or legal or or with the and of the of personal It the has a of new provisions on there is no to that the case-law by the of of the or the by the the European Data Protection at the of the are no longer where are to the new it be to how the scope of data and the notion of joint controllership have by the and the further on how the is likely to to cases a of smart home technical and be in the of this various by a on where joint controllership from legal case-law has the by where controllers are by technical or the of controllership with regard to a need to two key a data of a data or just a two or more entities joint controllers controllers for these are among the by the on the concepts of and are of legal in on the data controllership the of the responsibilities for compliance with data protection and on the joint controllership are under the to for responsibilities and be for the of data The first the data and data is of and to protecting personal data in a domestic IoT not of the cloud-based approach in the of IoT to the about the of as data as this issue it of the of this article and should be a for The is more relevant to the of this concerns the for a of entities to joint The from the of the that is and may a of The joint controllers may close for and of a or a more or or a the of entities not them joint can be controllers for their of the data it is that the the a of with joint and This is likely to be the case the parties have to personal The and the that the as joint controllership on a legal and of and can be the controllers not the legal as a data it control under the the of such to the as of the or the of of as as their is a controllership by legal approach is in a that joint controllership is the parties in a and their responsibilities the data the in the recent on the concepts of and joint controllership focuses on where the parties determine the and of the It should be that the analysis is under Regulation of personal data by the the in and the two it in the of data protection towards the notion of joint controllership under the To the interpretative approach by European has on the in the data in their legal It is that data controllers can be by of legal such to the data of should be and the not control over the the joint responsibilities are a that should in by as as the of data the the the to the of data in the the by the as to a data by a search engine that and as the that personal data, the the of in the of information on the It has to the that a in the of data in that it the accessible to a search on the of the data to users who not have the on data are for the first the has that the and the of data protection law a of data to and protection of data as be has by the in While the has not with the issue of joint controllers in this about how joint controllership may from technical To a to from the or the not not control over the of data, the that that for of to that determine the of that with this not of the While in a this to that it is for a to a joint with by not certain technical The joint controllers are in where the that the of a is a joint with It is that of a on by creating such a the to on the or of a It is that the on the of personal by the in with the are to be and the categories of personal data is to be of by to the of the personal data of to While the of the a and this not a in the the on how the of to personal data from it and the has to as controllership by technical a case the further the scope to controllership by The to the should be as a joint with who personal data in the on the that the is and encouraged by that the of on how data are and for to a joint It is that the it that the and of data not of or from the is it relevant the has access to the personal data in This a scope of joint controllers who not have to on the of data the the further how joint controllership may of the of a legal the parties or the of access to the personal data by of the to on joint controllership with but in a a on that the to with and thus certain information accessible by the The has in how the and are by and the the as the to have on the to by of the that it as a for the and by of the personal data of to that By such that the to with the the has on the by the personal data is the and are to have the of the is the the of and for the that it can data for is the for the to joint in not the of the to for and thus not a the it is the technical on a technical that to access to the personal data in From to there has and of the not of the joint and is the from the case-law that this approach is to a high level of data protection to data a notion of joint controllership may entities more and may prevent them from from their data protection this may or compliance on certain for the and adoption of edge such as and as be to certain of data protection in the responsibilities among are not of smart home the of the or the or of certain widening scope of joint controllership that may within the of a joint as are the in technical how smart home data are collected and for be to that under certain technical where such not have access to the personal data, may be as the has in cases that it is a has access or not to the data it to This of how data be such controllers of as be the has or control over the personal data. are the for the users of these who may in a dilemma where of such systems in their smart homes in the of privacy or for their their or the but being as a joint From a technical of there is a smart home that enables data and a on a that data smart in the of joint controllers may in cases some protection to data but this may at the some on the adoption of these technologies. While the and the to have the fair of responsibilities in the case of joint be further not be further on who should be for in a a more analysis of the of it is to some mechanisms that may to the of joint the the household be in it is that a as a data or it not that the of data on of the a of from being the household be relevant to the of smart home security technologies. provides Regulation not to the of personal by a in the of a personal or household further the of personal or household with the of no to a or A of are in the and the of or and within the of such with a in the as and the of of the new may to have the scope by and it should be that the may a scope that of the the of or household in the of these specific and to the more on the a more should be and from further the of smart home it is that the of the devices or of the may from this exemption. there is a or of their that the of personal of these or are not but is by the exemption. It be a are or responsibilities have in this is is that can the of the by the household exemption. A more may be by to the of the but this be to the of such technologies the household of the not of the this the in this on the users of S/PETs, the can be from data The on be a for this as it concerns the of home security not a smart in this specific The to the of a on home but a under the household exemption. the it is the that such as that at issue in the a and is from the of the the data in that it be as is a or to and by of the that such may and the of or may the of the has not further it a the is towards the of a it is that the has a approach to the scope of the exemption. the has in of a of the in the of relevant cases it has for the has the two in cases that the of the household access by of and to a the of the this the to the of in a smart home the to the of data is to the of the and their the case of there is no in IoT setting. While the of the of these technologies may be for protecting the of or adoption of such on the technical the in or in the users connected to the the domestic or not a for the household the is that the of may the of protecting it the of the household and to mechanisms within the legal such as the by the such as the protection of the and of and this it not to a smart devices for domestic The that such technologies of personal data from the or of personal data to the domestic the of the household exemption. The of the shows the for users of these technologies to from the exemption. The of the household that data within the scope of personal or household not be to by the first this or a of data protection at home as this to a and the not that are not it to household as access of data from the household that the of the home not be and indeed be to the this the as to such in the first The to of the household can be in to the Data provides that the and requirements for data not to data by or for personal the this on the that is not to of of personal data that in the in or and as as to the the of in a household exemption. the new it is provided that not to data by in the of personal or household A has in the This at the of on data by in their for to the of their The of data within the the a a of or a is in and on a personal or a of the the of the a of the to by for and personal of privacy are to the data are for as is the case with a personal the in such it be disproportionate to to with data protection data access to the data, just their personal are in more in the provided in the not to the within the of the of a to such as personal be While to the in the this has a data protection law to personal is not just for protecting the data but for the such as it them to at the of the data To from the of to the of a household but can be Data protection law should not to personal or household it be as it to the data as the privacy are in these and as it to the two it has how the scope of joint controllership has widening the scope of the household has narrowing as the two concepts have by the for of smart to a to the security and privacy of their homes may a high of being a joint and the protection by the household exemption. controllership and the household as two legal are the the a of entities are for the data the in a that the personal data from controllership the in are personal or The further that the to but not to the entities for such with regard to the in the of on for the and may be from the of the but the service the household is a that to from the compliance this the notion of joint controllership and the household are in by the responsibilities for some of data and thus imposing them on some these two concepts the a is a data and for the household be with the responsibilities as a of a of have no responsibility at The responsibilities of joint as may not be but joint controllership may lead to a of burdens that are not to the of To the that joint controllership and the household determine who should and who should not be for data as a legal to This a underlying privacy and data protection privacy law focuses more on the of personal and data protection law the accountability of of personal as of the is such as and so of a data protection is thus to determine the to the responsibilities are various By the household for data protection law has in the responsibilities from personal data for personal are to be to a lower level of accountability in a with and or personal of within the The joint controllership and the household are in the a assumptions that be valid for a home but not for a smart it is assumed that personal or domestic are within the of a The of for within home and thus has on the responsibilities can be and or to a of the case of the be the parties for the of the not the issues of these two the two may in a the no the as be in the of this these two assumptions not in IoT should be that the provided by of be from the of data protection law the of the on in these as and a for personal for should not in the the to access the this not that the information in such is of in or by law. This is by the that certain can be as or and thus within such should be from the two provided by in two of and not to the and as two of of can be within the within the these two the that a high level of that the information within such the or is the not the and thus have or the the of should and thus to a lower level of accountability is is a of the of management under the of homes and in cases have more as are and to the privacy is a approach should be is the to management by the of IoT technologies. The of a smart home are more as smart devices are information about is the home to the remote the of a smart home may be by or on the more IoT technologies to is as of a home, the and have from the This is the case in the to this on and such as or on the of the a smart home security for the of new be brought or close to the by or a domestic to of such a may more of the or certain cases, the and storage of information be but it is not as as a and have concerns over the safety of such The of devices may be by is the The may for to a from the a a a smart home, it is no longer the their their their connected of the be or the more need to on the of the of a the and are no longer by a but by a of with of to the of the home, and thus of To such a smart home may be seen as a This towards the need for further research on and in a smart home with but from a legal of the that a can be the domestic and a legal the in joint controllership and the household have the of for a of the roles of the parties it to a complex it not fair to the of in The of in this article as a case in technologies on the of a of who have roles to and thus have level of control over the of the We to to the of control by a of The of the for have control as determine the of data and the the but have no access to the the have control as determine data are collected and the the of or have interpretative control as determine how data or data can be the users have control as determine or are a this approach further and The level of and various of that accountability is not just in but in a The control by the users them not to the the of their the control by the them not to the control by the them not to data in of the are in for of are the in and in of control and the for The by joint controllership and the household to have to such a complex The of responsibilities as envisaged by the and the be in the this issue to some but certain remain. this the a that is relevant but provides that of the and should be encouraged to the to data protection with regard to the of the to that controllers and are to their data protection It some on the roles that the parties are to in the of for smart it these are not as data controllers at that can be as in some as are but not the case be for a to the of the data the case of for smart the to some are not data controllers to the not determine the of the but a technical to the it not that not have control over how data are It not that it be fair to the of data on to and in should and how such responsibilities should be legal it more of or The for the of a smart home with such have a certain level of control over the of data for that be but not or to the to the should to need to to the that the the household have it fair to the data on it to so the it to so the for the and their The may not be more in a of control over data and responsibilities among these be a of of that the scope of joint controllership and the scope of the household not disproportionate on certain of of the that joint controllers should a determine their responsibilities for compliance with the under this Regulation by of this is by the the of the the as as the have some to such a The has indeed the need to is and for data and where the various joint controllers and of in While the has not the of joint and and joint controllers for from the data has that in cases various controllers be and thus for the of personal data at and to This has by the in that of joint responsibility not responsibility of the various in the of personal and that may be at of that of personal data and to so that the level of responsibility of of them be with regard to the relevant of the This approach is by the in and it is indeed and to the of controllers their roles in the whole of the and of data the approach by the by the and by the is to a of the is on the that joint controllers have or can to on how the responsibilities should be among as data controllers are to so under the of analysis in the on joint controllership has that the of controllership not a legal the and can from technical or it is that such can and should be in the of this be the and the have the of joint controllers as a of data or and thus the of should be This the of data protection responsibilities as a of in or in for the of data controllers and data from a law The joint and for can be by and with the the controllers who can in data protection law concerns not but the for of personal data and the personal data The are among in and as a of degree, not be for in the of control joint controllers in to adopt is a not the as or the default approach of joint and is in data protection responsibilities it how to reconcile to be a the to determine the responsibilities among joint and the that data can be of the joint in the joint controllers to the roles and of the joint controllers the data This can be as joint controllers to of them to be for certain of data as as this and with the data the data not be by such a and may to their of the some of these may be by the data may be some of the joint of the to such on a of protection of the data or the and of The security and privacy interest of the for may be by the of the data these a on fair of and may creating further among The of legal on these may the and adoption of smart home technologies that privacy and security for IoT of data protection responsibilities the of joint controllership and the household and of the parties is and should be to is to categories of in the domestic IoT in to their in the data protection it is of the to the on and the need to further and more the of smart home IoT how data protection law should users in a domestic the burdens of domestic data controllers by them of the data protection This is not the case The of cases this article have how domestic IoT has some of the underlying assumptions of data protection and has legal as to who should the responsibility among a of connected to the smart home edge as as how accountability can be in a and This the issue of how data protection law should smart The scope of joint controllership and the scope of the household as are to a high of and to data have to for their as this the interpretative approach may certain in smart homes and thus of edge such as and this may in a lower of as as for smart home We that this issue law of the research is to the control of various by in smart IoT should be to to the have in accountability with further is for a of the among with and various as as of to fair reassignment of responsibility and accountability in a domestic IoT these and and the of IoT systems or and the creation of the regulatory to This by the and

Read the paper · More papers on PaperTik