Privacy and Data Protection Challenges in IoT Data and Metadata Processing
摘要
This chapter casts light on three normative challenges in terms of fundamental rights, in particular, the right to privacy and the right to the protection of personal data (Arts. 7 and 8 of the EU Charter of Fundamental Rights), brought about by the structural data and metadata sharing of the ubiquitous IoT. The first legal challenge hinges on how structural IoT data and metadata processing challenges the two different regimes of the ePrivacy Directive and the GDPR, in particular, taking into account (i) the lawfulness of the processing; (ii) lack of transparency and information asymmetry; (iii) information security risks. The second legal challenge casts light on the relationship between various cryptographic technical tools e.g., but not limited to, encryption, and the traditional legal disciplines of privacy and data protection against the background of IoT data and metadata processing. Notwithstanding the lightweight—in the case of resource-constrained devices—or ‘strong’ encryption protocols that may be adopted to secure (IoT) device communication, serious privacy concerns might nevertheless arise. Encrypted traffic analysis, or metadata analysis, which corresponds to the third legal challenge, is presented taking into account, in particular, hidden impacts on IoT users’ privacy and security.