What is the Internet of Things (IOT)
Probably The Internet of Things is an expression familiar only to a small, somewhat niche group of people. IoT is simply a connected object that can make our lives easier or safer. Think about your smart TV, robot vacuum cleaners or voice assistant.We have IoT in practically all areas of our daily life from the “connected home” or domotics, to the leisure sector up to the health sector where information technology has strongly entered the field in the last years improving the life expectancy of patients but also the everyday life of ordinary people.
How does it work?
IoT plays a critical role in the current digital economy, enabling billions of connected devices to exchange data and powering artificial intelligence systems in many fields…
Smartphones too play an important role in IoT as many IoT devices can be controlled by an application on a smartphone.
IoT devices are everyday objects with sensors and small computers that collect data and either process it locally with simple rules or send it elsewhere for more complex analysis.
In this article, we will focus on one particular category of IoT, namely IoMTs (Internet of Medical Things) or healthcare IoT, how it relates to the EU General Data Protection Regulation (GDPR) as well as other privacy regulations.
IoMTs are all those devices and applications connected that enable machine-to-machine communication. We can consider them as a branch of IoT.
Examples of IoMT is remote patient monitoring and virtual visits of people with chronic or long-term conditions, tracking of patients’ medication orders, location of hospitalized patients in hospitals, etc.
In the field of patient care, a connected medical device should only be embraced with extreme prudence due to potentially safety vulnerabilities and risks to patient safety.
In this context, it’s important to understand how EU legislation protects personal data collected by those IoT devices.
GDPR implication
IoMTs raise concerns for compliance with the principles related to the processing of personal data (Art. 5 of the GDPR). These principles are: lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation and integrity and confidentiality. These principles must be evaluated considering the responsibility of the Data protection by design and by default (Art. 25) and the Security of processing (Art. 32). The primary tool to evaluate such concerns is certainly the Data Protection Impact Assessment (DPIA).
It is clear that a risk management assessment is a crucial tool to identify and assess the risks associated to the use of IoT devices. Manage and mitigate (or even eliminate) these risks is one of the primary goals of the DPIA, to ensure the protection of the fundamental rights and freedoms of individuals which for the regulation is more important than creating or protecting value.
In light of privacy concerns mentioned above, and in relation to the characteristics of IoMT elements that enable applications and services to aggregate and manage data at every level of data generation, it is strongly recommended to carefully assess the risks to data subjects and conduct a DPIA that covers all the stages of the personal data lifecycle with a focus on the purpose of processing and the risk of re-identification of data subjects.
Data encryption is an essential safeguard for medical devices. As the transferred data flows containing patient information are encrypted, and transferred privately, the possibility of access by a hacker is rendered much more challenging. Vulnerable smart medical devices are present in the systems of 89% of healthcare organizations.
The interaction between GDPR and IoT becomes more complicated when considering the role qualification of the parties involved in a specific processing activity, especially that of the Data Controller and the Data Processor.
For example, as per Working Party 29’s opinion on IoT (8/2014),
- A device manufacturer that develops the operating system or defines the main features of the software will be considered as a Data Controller.
- A third-party app developer will be considered as a Data Controller when creating interfaces that enable data subjects to have access to their data when it is held by the device manufacturer.
What about special categories of personal data?
IoT applications may, accidentally or not, directly or indirectly process special categories of data (e.g. smart wearables, capable of inferring the health or well-being of the data subject). For this use (process), explicit consent under Article 9(2) of the GDPR must be considered.
Other EU Regulations and Directives Affecting Medical IoT
As a support to the European regulation on data protection concerns (GDPR), we have to consider the Medical Device Regulation (MDR) or the In Vitro Diagnostic Medical Device Regulation (IVDR) issued by the European Parliament concerning medical devices.
Under the MDR and IVDR, IoT devices must be classified according to their intended use as defined in Article 2. Manufacturers are responsible for determining whether their IoT device qualifies as a medical device or accessory. This classification determines the regulatory pathway (self-declaration for Class I, Notified Body assessment for higher classes) and directly impacts the type of personal health data that will be processed, requiring the manufacturer to implement appropriate GDPR compliance measures, including conducting a DPIA when necessary.
In addition to regulations specifically targeting medical devices, several new EU regulations and directives impacting IoT have entered into force or will soon apply. These include:
- The Data Act (Regulation (EU) 2023/2854), which governs access to and sharing of data generated by connected products and related services, directly impacting IoT ecosystems;
- The AI Act (Regulation (EU) 2024/1689), which introduces a risk-based framework for AI systems, including those embedded in IoT devices;
- The NIS 2 Directive (Directive (EU) 2022/2555), which enhances cybersecurity requirements for entities in critical sectors, including healthcare, making it highly relevant for medical IoT.
These instruments expand the regulatory landscape beyond the Medical Devices Regulation (EU) 2017/745 by addressing data governance, AI risks, and cybersecurity, all increasingly essential for connected medical technologies.