DPDP 3.1.3: DPDP and Internet of Things (IoT) – Case Study 3 – Lakshmi’s Smart Home and the Data That Left the House

The Scenario

Lakshmi is a homemaker in Bengaluru. Her family uses a suite of smart home devices — a connected doorbell with a camera, a voice-activated home assistant, smart lighting controlled by an app, and a connected refrigerator that tracks grocery inventory. All devices were purchased from different manufacturers, each with its own app and privacy policy.

Over time, Lakshmi realised that advertisements on her phone were displaying products she had discussed verbally at home and items she had added to her refrigerator’s shopping list. She had never consciously consented to any of this data leaving her home and being used for targeted advertising. She also had no single point of contact to understand what data was being collected, by whom, or how to stop it.

When she attempted to delete her data from one manufacturer’s platform, she received a response that her data had been shared with “technology partners” and could not be fully recalled.

The DPDP Act Position

Lakshmi’s situation illustrates the most complex IoT-DPDP compliance scenario: the multi-vendor smart home, where data collected by one device travels through multiple Data Fiduciaries and Data Processors, none of whom have a co-ordinated compliance architecture.

First — Consent fragmentation failure. Each device manufacturer that collects personal data within Lakshmi’s home is a Data Fiduciary. Each must independently satisfy Section 5 (notice) and Section 6(1) (specific, informed, free consent). A bundled privacy policy buried in a device setup wizard does not constitute the clear, plain-language, itemised consent notice required by Rule 3 of the DPDP Rules. Moreover, oral conversations captured by a voice assistant constitute personal data under Section 2(t) of the Act — any data about an individual who is identifiable by or in relation to such data. Capturing and processing these without specific, affirmative consent is unlawful.

Second — Data sharing with technology partners as undisclosed processing. When a Data Fiduciary shares personal data with a third-party technology partner for advertising targeting, that third party is either a Data Processor or a separate Data Fiduciary. Under Section 8(2), if it is a Data Processor, the original Data Fiduciary must ensure it processes data only for the specified purpose. If the specified purpose was “device functionality” and the actual use is “advertising targeting,” the sharing is unlawful — regardless of what the fine print says.

Third — Structural inability to respond to erasure requests. Section 12(3) of the DPDP Act requires the Data Fiduciary to erase personal data on request. When the Data Fiduciary has already shared data with technology partners — who are now using it independently — the original Data Fiduciary cannot honour this obligation without binding downstream agreements that require cascading deletion. The absence of such agreements is a compliance failure at the architecture stage, not a technical impossibility.

Fourth — Children’s data risk. If Lakshmi’s home includes minor children who interact with voice assistants or other smart devices, Section 9 of the DPDP Act applies. Processing personal data of a child requires verifiable parental consent. A voice assistant that captures a child’s voice — identifiable personal data — without verifiable parental consent is in direct violation. The penalty for breach of Section 9 obligations extends to ₹150 crore under the Schedule to the Act.

The IS Audit Perspective

IS Audit 3.0 by ICAI is explicit: IoT privacy risk arises because objects within the IoT collect and aggregate fragments of data that relate to their service, and that individually innocuous data points combine to reveal sensitive attributes. Lakshmi’s scenario is the textbook illustration of this risk at the consumer level.

The Puttaswamy judgment (2018) directly anticipated this concern, observing that IoT and data mining processes together can create new knowledge about individuals — something even the individuals themselves did not possess. The court noted that this is an age of “ubiquitous dataveillance,” where users of wearable devices and smart home technology generate vast data about lifestyles, choices, and preferences without conceiving of themselves as having volunteered that data. Indian law now governs that data.

The Compliance Fix

Smart home device manufacturers and platform operators selling to Indian consumers must:

→ Provide a separate, device-specific consent notice in clear and plain language — not a buried privacy policy — before any data collection begins. Rule 3 of the DPDP Rules applies to every device sold in India that collects personal data. → Identify and disclose every “technology partner” as a named Data Processor or co-Data Fiduciary in the consent notice, along with a specific description of what data they receive and for what purpose. → Build cascading deletion mechanisms so that an erasure request to the primary Data Fiduciary propagates to all downstream Data Processors. → Implement verifiable parental consent mechanisms under Section 9 before any smart home device capable of collecting children’s data is activated in a household. → Apply transport-level encryption across all device-to-cloud data flows — IS Audit 3.0 (Section 6.5.6) identifies the lack of transport encryption as a primary IoT risk.

Lakshmi’s home was smart. Its manufacturers were not compliant.


The Central Compliance Question for IoT Deployments

The IoT-DPDP compliance challenge is, at its core, a consent architecture problem. IoT devices are designed to collect continuously, silently, and at scale. The DPDP Act requires consent to be specific, informed, and granular. These two imperatives pull in opposite directions — and organisations that do not resolve this tension before deployment will face it as an enforcement problem after 13 May 2027.

There are five questions every organisation must answer before deploying IoT systems that collect personal data:

One. Have we issued a Rule 3-compliant notice — itemised, plain-language, and device-specific — for every category of personal data our IoT system collects?

Two. Is each downstream use of that data — analytics, scoring, advertising, pricing, performance management — identified as a specified purpose at the time of initial consent?

Three. Does every vendor, cloud platform, and analytics partner in our IoT data chain have a written Data Processor contract under Section 8(2) limiting them to the specified purpose?

Four. Have we built cascading deletion mechanisms so that a Section 12(3) erasure request can be honoured across the full data chain?

Five. If children may interact with our IoT devices, do we have a verifiable parental consent mechanism that meets the Section 9 standard?

IS Audit 3.0 by ICAI sets the governance standard clearly: IoT governance must address the lifecycle of IoT devices, the data managed by the IoT solution, and IoT applications in the organisation’s IT landscape. The DPDP Act makes this governance framework legally mandatory, not merely a best practice.


What Responsible IoT and DPDP Compliance Looks Like

The DPDP Act does not prohibit IoT. It requires that every IoT deployment be designed so that Data Principal rights — consent, purpose limitation, erasure, and correction — can be meaningfully exercised.

Devices will continue to collect data. Networks will continue to transmit it. Platforms will continue to analyse it. None of that is prohibited. However, every step in that chain — from sensor to server to insight — must be governed by a consent framework that the person at the centre of it all understood and agreed to, in plain language, before collection began.

The Puttaswamy judgment (2018) described this era as one of ubiquitous dataveillance. IoT is the infrastructure of that dataveillance. The DPDP Act is the law that governs it. Together, they mean one thing for Indian organisations: design your IoT systems for privacy first, not compliance as an afterthought.

The compliance deadline is 13 May 2027. Every IoT device collecting personal data in India today is already in scope.


Sources: IS Audit 3.0, ICAI | DPDP Act 2023| DPDP Rules 2025 | Puttaswamy v Union of India (2018)


Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors: This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.1.3: DPDP and Internet of Things (IoT) – Case Study 3 – Lakshmi’s Smart Home and the Data That Left the House

DPDP 3.1.2: DPDP and Internet of Things (IoT) – Case Study 2 –  Suresh and the Smart Office That Never Stopped Watching

The Scenario

Suresh is a mid-level manager at a logistics company in Chennai. His employer had implemented an IoT-enabled smart office system — access badges tracked movement across the building, smart cameras monitored workstations, occupancy sensors logged time at desk, and a connected printer recorded who printed what and when.

All of this data flowed into a workplace analytics platform that generated individual productivity scores. Suresh was placed on a performance improvement plan based partly on his occupancy metrics — he had spent less time at his desk during a period when he was, in fact, attending client meetings in the conference rooms.

He was never told that his movement and occupancy data were being collected and used for performance evaluation. He had signed a general IT usage policy when he joined — three years before this system was installed.

The DPDP Act Position

This scenario raises three compliance failures.

First — Absence of lawful consent for a new processing purpose. Section 6(1) of the DPDP Act requires consent for each specified purpose. A general IT usage policy signed three years earlier does not constitute valid consent for IoT-based occupancy tracking and performance scoring. The purposes are different, the data categories are different, and the consequences to the employee are materially different.

Section 5(1) of the Act requires that every request for consent be accompanied or preceded by a notice informing the Data Principal of the personal data to be processed and the purpose. No such notice was given when the IoT system was deployed. Consequently, all processing of Suresh’s location and occupancy data for performance evaluation was unlawful.

Second — Use of incomplete data to make decisions affecting the Data Principal. Section 8(3) requires that when personal data is likely to be used to make a decision that affects the Data Principal, the Data Fiduciary must ensure the completeness, accuracy, and consistency of that data. Suresh’s occupancy data was accurate — he was not at his desk — but it was incomplete, because the system had no mechanism to capture the reason. An employee attending client meetings generates the same occupancy reading as one who is absent without reason. Using this data for performance decisions without ensuring completeness is a direct violation of Section 8(3).

Third — Breach of proportionality under the Puttaswamy doctrine. The Supreme Court’s judgment in Puttaswamy v Union of India (2018) established that any encroachment on informational privacy must satisfy the proportionality test: there must be a lawful basis, a legitimate aim, and the measure must be proportionate to that aim. Continuous occupancy monitoring of every employee for the purpose of productivity scoring is disproportionate to any legitimate workplace management aim — particularly when other, less invasive means of performance assessment are readily available.

The IS Audit 3.0 Perspective

IS Audit 3.0 by ICAI identifies insufficient authentication and authorisation, insecure web interfaces, and lack of transport-level encryption as key IoT risks. In Suresh’s case, the workplace IoT system aggregated movement data with no individual access controls, no audit trail for the analytics platform, and no individual visibility into what data was being collected about each employee.

IS Audit 3.0 (Governance and Controls) is direct: IoT governance must define the lifecycle of IoT data, cover the changes to IT governance for distributed IoT architecture, and ensure that the principles for managing that architecture deliver on the stated business goals. A workplace analytics platform that generates employment consequences without a lawful consent framework is not a managed system — it is an uncontrolled compliance liability.

The Compliance Fix

Employers deploying workplace IoT systems must:

→ Issue a fresh, specific consent notice — separate from general IT policies — for each new IoT deployment that collects employee personal data. → Conduct a Data Protection Impact Assessment (DPIA) under Section 10 of the DPDP Act before deploying any system that collects employee movement, biometric, or occupancy data at scale. → Ensure that any data used to make employment decisions is complete, not merely accurate — which means building context-capture mechanisms alongside sensors. → Apply proportionality: if the legitimate aim is productivity management, the least invasive means of achieving that aim should be used. Continuous movement tracking is rarely the least invasive option. → Give employees visibility into what data is being collected about them, and provide a mechanism to raise corrections under Section 12(2) of the DPDP Act.

Suresh’s employer automated its surveillance. However, it did not automate its compliance.

Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors:
This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.1.2: DPDP and Internet of Things (IoT) – Case Study 2 –  Suresh and the Smart Office That Never Stopped Watching

DPDP 3.1.1: DPDP and Internet of Things (IoT) – Case Study 1 –  When Every Device Becomes a Witness

INTRODUCTION

IoT and DPDP compliance represent one of the most underestimated challenges in India’s data protection landscape today.

Your fitness band knows your resting heart rate. Your smart meter knows when you wake up. Your office access badge knows exactly where you were at 9:14 am. Individually, each of these data points seems harmless. Together, however, they compose a surveillance portrait of extraordinary detail — one that its subject never agreed to provide and may not even know exists.

This is precisely the privacy risk that IS Audit 3.0 (ICAI Module 6, Section 6.5.6) identifies when it notes that IoT devices collect and aggregate fragments of data that, in combination, can reveal religion, health information, lifestyle choices, and other sensitive personal attributes — even when no single data point appears sensitive in isolation.

The Internet of Things is defined in IS Audit 3.0 (Module 6, Section 6.5.1) as a system of interrelated computing devices, mechanical and digital machines, objects, animals, or people that are provided with unique identifiers and the ability to transfer data over a network without requiring human-to-human or human-to-computer interaction. In simple terms, devices collect, send, and act on data — largely without human involvement at the point of collection.

That last phrase is the compliance problem. The DPDP Act, 2023 is built on the premise of informed, specific, and free consent. IoT is built on the premise of seamless, continuous, and frictionless data collection. These two architectures sit in fundamental tension — and that tension has a deadline: 13 May 2027.

Three Case Study bring this tension to life.


Case Study 1 — Rohini’s Wearable and the Insurance Company That Knew Too Much

The Scenario

Rohini is a 41-year-old schoolteacher in Pune. She purchased a health insurance policy from a mid-sized insurer. As part of a wellness incentive programme, the insurer offered her a discount in exchange for syncing her fitness wearable to their app. Rohini agreed, expecting only her step count to be shared.

Over eighteen months, the wearable transmitted her heart rate variability, sleep patterns, stress indicators, menstrual cycle data, and location history to the insurer’s cloud platform. The insurer’s algorithm then recalculated her risk profile — and at renewal, her premium increased substantially. No one told Rohini that these data points were being collected, how they were being used, or that they would influence her premium.

The DPDP Act Position

Rohini’s situation discloses at least three distinct violations.

First — Consent specificity failure under Section 6(1). The DPDP Act requires consent to be free, specific, informed, unconditional, and unambiguous. It must be limited to personal data that is necessary for the specified purpose. Rohini consented to sharing her step count for a wellness discount. She did not consent to the sharing of menstrual cycle data, stress indicators, or sleep patterns. Any processing beyond the specified purpose is unlawful.

Rule 3 of the DPDP Rules, 2025 reinforces this directly. A Data Fiduciary must give notice in clear and plain language, with an itemised description of personal data to be collected and a specific description of the purpose. A general reference to “health data” does not satisfy this standard. Each category of IoT data being collected must be identified separately in the consent notice.

Second — Purpose limitation failure under Section 8(1). The purpose for which Rohini’s data was processed — premium recalculation — was never disclosed as a specified purpose at the time of consent. Consequently, processing her data for that purpose is unlawful under the Act, regardless of what the policy fine print may say.

Third — Sensitive personal data processing without adequate basis. Menstrual cycle data and health metrics constitute personal health information. While the DPDP Act does not yet have a separate “sensitive personal data” category in the manner of some foreign frameworks, Section 8(5) requires the Data Fiduciary to implement reasonable security safeguards. Moreover, when data is used to make a decision that affects the Data Principal, Section 8(3) requires the Data Fiduciary to ensure completeness, accuracy, and consistency of that data. An algorithmic premium revision based on wearable data must meet this standard.

The IS Audit 3.0 Perspective

IS Audit 3.0 (Module 6, Section 6.5.6) specifically identifies privacy concerns in healthcare IoT as a primary risk, observing that devices in this domain collect at least one piece of personal information and that the aggregation of IoT data fragments can reveal health information that was never explicitly disclosed. This aggregation risk is precisely what happened to Rohini.

Furthermore, IS Audit 3.0 (Section 6.5.7) identifies governance of IoT data as requiring a clear reference architecture, defined governance processes, and lifecycle management of the data managed by the IoT solution — none of which the insurer had implemented.

The Compliance Fix

Insurers and any organisation using wearable or health IoT data must:

→ Issue a separate, itemised consent notice for each data category collected by the device — not a single bundled consent covering “health data.” → Clearly specify every downstream use — including risk assessment, pricing, and underwriting decisions — as a stated purpose at the time of initial consent. → Ensure that data collected via wearable integration is not used for purposes beyond what was disclosed, unless fresh consent is obtained for the new purpose. → Implement data minimisation controls at the IoT gateway level, so that only the specific data categories covered by consent are transmitted to the cloud platform.

Rohini’s insurer collected far more than it disclosed. The DPDP Act calls that a violation — not a feature.

Rohini’s insurer had a wellness programme. It did not have a consent programme. Under the DPDP Act, that distinction matters enormously. The compliance deadline is 13 May 2027.

Disclaimer

The contents of this post are intended for general awareness and informational purposes only. They do not constitute legal opinion, professional advice, consultancy, statutory interpretation, or a recommendation to act in any particular manner.

The Digital Personal Data Protection Act, 2023, related rules, notifications, regulatory guidance and judicial interpretations may evolve from time to time. The applicability of the law may also vary depending on the facts, sector, nature of data processing, organisational role, contractual terms and compliance framework.

Readers should not rely solely on this post for making legal, business, HR, technology, data-processing or compliance decisions. Specific advice from a qualified legal, privacy, cybersecurity, governance or compliance professional should be obtained before acting on any matter discussed.

The author / publisher shall not be responsible for any loss, liability, claim, penalty or consequence arising from reliance on the contents of this post without independent professional advice.


Authors:
This article has been co-authored by CA. Sunil Elayadath and CA. Karthik Narayanan S, Partners of Karthik & Sunil, together with Mr. Dhanesh P. K., Designated Partner, DSK Sustainability Tech.

DPDP 3.1.1: DPDP and Internet of Things (IoT) – Case Study 1 –  When Every Device Becomes a Witness