--- layout: default title: "A Review of the Policy Debate around Big Data and Internet of Things" description: "An August 2015 CIS blog post by Elonnai Hickok reviewing how regulators and experts across jurisdictions, including the US FTC, the Article 29 Working Party, the European Commission, and the European Data Protection Supervisor, are responding to Big Data and the Internet of Things from a policy perspective." authors: ["Elonnai Hickok"] categories: [Elonnai Hickok] date: 2015-08-17 source: "Centre for Internet and Society" permalink: /elonnai/review-of-policy-debate-around-big-data-and-internet-of-things/ created: 2026-09-20 homepage_featured: true --- **"A Review of the Policy Debate around Big Data and Internet of Things"** is a blog post written by [Elonnai Hickok](/elonnai/), published by the [Centre for Internet and Society](/cis/) on 17 August 2015. It reviews how regulators and experts across jurisdictions, including the US Federal Trade Commission, the Article 29 Data Protection Working Party, the European Commission, and the European Data Protection Supervisor, are reacting to Big Data and the Internet of Things (IoT) from a policy perspective. ## Contents 1. [Article Details](#article-details) 2. [Full Text](#full-text) 3. [Context and Background](#context-and-background) 4. [External Link](#external-link) ## Article Details
This blog post seeks to review and understand how regulators and experts across jurisdictions are reacting to Big Data and Internet of Things (IoT) from a policy perspective.
The Internet of Things is a term that refers to networked objects and systems that can connect to the internet and can transmit and receive data. Characteristics of IoT include the gathering of information through sensors, the automation of functions, and analysis of collected data.[1] For IoT devices, because of the velocity at which data is generated, the volume of data that is generated, and the variety of data generated by different sources,[2] IoT devices can be understood as generating Big Data and/or relying on Big Data analytics. In this way IoT devices and Big Data are intrinsically interconnected.
Big Data paradigms are being adopted across countries, governments, and business sectors because of the potential insights and change that it can bring. From improving an organization's business model, facilitating urban development, allowing for targeted and individualized services, and enabling the prediction of certain events or actions, the application of Big Data has been recognized as having the potential to bring about dramatic and large scale changes.
At the same time, experts have identified risks to the individual that can be associated with the generation, analysis, and use of Big Data. In May 2014, the White House of the United States completed a ninety day study of how big data will change everyday life. The Report highlights the potential of Big Data as well as identifying a number of concerns associated with Big Data. For example: the selling of personal data, identification or re-identification of individuals, profiling of individuals, creation and exacerbation of information asymmetries, unfair, discriminating, biased, and incorrect decisions based on Big Data analytics, and lack of or misinformed user consent.[3] Errors in Big Data analytics that experts have identified include statistical fallacies, human bias, translation errors, and data errors.[4] Experts have also discussed fundamental changes that Big Data can bring about. For example, Danah Boyd and Kate Crawford, in the article "Critical Questions for Big Data: Provocations for a cultural, technological, and scholarly phenomenon," propose that Big Data can change the definition of knowledge and shape the reality it measures.[5] Similarly, a BCS/Oxford Internet Institute conference report titled "The Societal Impact of the Internet of Things" points out that often users of Big Data assume that information and conclusions based on digital data is reliable and in turn replace other forms of information with digital data.[6]
Concerns that have been voiced by the Article 29 Working Party and others specifically about IoT devices have included insufficient security features built into devices such as encryption, the reliance of the devices on wireless communications, data loss from infection by malware or hacking, unauthorized access and use of personal data, function creep resulting from multiple IoT devices being used together, and unlawful surveillance.[7]
The regulation of Big Data and IoT is currently being debated in contexts such as the US and the EU. Academics, civil society, and regulators are exploring questions around the adequacy of present regulation and overseeing frameworks to address changes brought about by Big Data, and if not, what forms of or changes in regulation are needed? For example, Kate Crawford and Jason Schultz, in the article "Big Data and Due Process: Towards a Framework to Redress Predictive Privacy Harms," stress the importance of bringing in "data due process rights," i.e. ensuring fairness in the analytics of Big Data and how personal information is used.[8] While Solon Barocas and Andrew Selbst, in the article "Big Data's Disparate Impact," explore if present anti-discrimination legislation and jurisprudence in the US is adequate to protect against discrimination arising from Big Data practices, specifically data mining.[9]
In the context of data protection, various government bodies, including the Article 29 Data Protection Working Party set up under Directive 95/46/EC of the European Parliament, the Council of Europe, the European Commission, and the Federal Trade Commission, as well as experts and academics in the field, have called out at least ten different data protection principles and concepts that Big Data impacts:
In a report titled "Internet of Things: Privacy & Security in a Connected World" by the Federal Trade Commission in the United States, it was noted that though IoT changes the application and understanding of certain privacy principles, it does not necessarily make them obsolete.[20] Indeed, many possible solutions that have been suggested to address the challenges posed by IoT and Big Data are technical interventions at the device level rather than fundamental policy changes. For example, it has been proposed that IoT devices can be programmed to:
Such solutions place the designers and manufacturers of IoT devices in a critical role. Yet some, such as Kate Crawford and Jason Schultz, are not entirely optimistic about the possibility of effective technological solutions, noting in the context of automated decision making that it is difficult to build in privacy protections as it is unclear when an algorithm will predict personal information about an individual.[29]
Experts have also suggested that more emphasis should be placed on the principles and practices of:
Others have recommended that certain privacy principles need to be adapted to the Big Data/IoT context. For example, the Article 29 Working Party has clarified that in the context of IoT, consent mechanisms need to include the types of data collected, the frequency of data collection, as well as conditions for data collection.[30] While the Federal Trade Commission has warned that adopting a pure "use" based model has its limitations, as it requires a clear (and potentially changing) definition of what use is acceptable and what use is not acceptable, and it does not address concerns around the collection of sensitive personal information.[31] In addition to the above, the European Commission has stressed that the right of deletion, the right to be forgotten, and data portability also need to be foundations of IoT systems and devices.[32]
To the question of whether current regulatory frameworks are adequate and additional legislation is needed, the FTC has recommended that though specific IoT legislation may not be necessary, a horizontal privacy legislation would be useful, as sectoral legislation does not always account for the use, sharing, and reuse of data across sectors. The FTC also highlighted the usefulness of privacy impact assessments and self-regulatory steps to ensure privacy.[33] The European Commission, on the other hand, has concluded that to ensure enforcement of any standard or protocol, hard legal instruments are necessary.[34]
As mentioned earlier, Kate Crawford and Jason Schultz have argued that privacy regulation needs to move away from principles on collection, specific use, disclosure, notice etc. and focus on elements of due process around the use of Big Data, as they say, "procedural data due process." Such due process should be based on values instead of defined procedures and should include at the minimum notice, hearing before an independent arbitrator, and the right to review. Crawford and Schultz more broadly note that there are conceptual differences between privacy law and big data that pose serious challenges, i.e. privacy law is based on causality while big data is a tool of correlation. This difference raises questions about how effective regulation that identifies certain types of information and then seeks to control the use, collection, and disclosure of such information will be in the context of Big Data, something that is varied and dynamic. According to Crawford and Schultz, many regulatory frameworks will struggle with this difference, including the FTC's Fair Information Privacy Principles and EU regulation including the EU's right to be forgotten.[35]
The European Data Protection Supervisor, on the other hand, looks at Big Data as spanning the policy areas of data protection, competition, and consumer protection, particularly in the context of "free" services. The Supervisor argues that these three areas need to come together to develop ways in which the challenges of Big Data can be addressed. For example, remedy could take the form of data portability, ensuring users the ability to move their data to other service providers, empowering individuals and promoting competitive market structures, or adopting a "compare and forget" approach to data retention of customer data. The Supervisor also stresses the need to promote and treat privacy as a competitive advantage, thus placing importance on consumer choice, consent, and transparency.[36]
The European Data Protection reform has been under discussion and it is predicted to be enacted by the end of 2015. The reform will apply across European States and all companies operating in Europe. The reform proposes heavier penalties for data breaches, and seeks to provide users with more control of their data.[37] Additionally, Europe is considering bringing digital platforms under the Network and Information Security Directive, thus treating companies like Google and Facebook as well as cloud providers and service providers as a critical sector. Such a move would require companies to adopt stronger security practices and report breaches to authorities.[38]
A review of the different opinions and reactions from experts and policy makers demonstrates the ways in which Big Data and IoT are changing traditional forms of protection that governments and societies have developed to protect personal data as it increases in value and importance. While some policy makers believe that big data needs strong legislative regulation and others believe that softer forms of regulation such as self or co-regulation are more appropriate, what is clear is that Big Data is either creating a regulatory dilemma, with policy makers searching for ways to control the unpredictable nature of big data through policy and technology through the merging of policy areas, the honing of existing policy mechanisms, or the broadening of existing policy mechanisms, while others are ignoring the change that Big Data brings with it and are forging ahead with its use.
Answering the "how do we regulate Big Data" question requires re-conceptualization of data ownership and realities. Governments need to first recognize the criticality of their data and the data of their citizens/residents, as well as the contribution to a country's economy and security that this data plays. With the technologies available now, and in the pipeline, data can be used or misused in ways that will have vast repercussions for individuals, society, and a nation. All data, but especially data directly or indirectly related to citizens and residents of a country, needs to be looked upon as owned by the citizens and the nation. In this way, data should be seen as a part of critical national infrastructure of a nation, and accorded the security, protections, and legal backing thereof to prevent the misuse of the resource by the private or public sectors, local or foreign governments. This could allow for local data warehousing and bring physical and access security of data warehouses on par with other critical national infrastructure. Recognizing data as a critical resource answers in part the concern that experts have raised, that Big Data practices make it impossible for data to be categorized as personal and thus afforded specified forms of protection due to the unpredictable nature of big data. Instead, all data is now recognized as critical.
In addition to being able to generate personal data from anonymized or non-identifiable data, big data also challenges traditional divisions of public vs. private data. Indeed, Big Data analytics can take many public data points and derive a private conclusion. The use of Big Data analytics on public data also raises questions of consent. For example, though a license plate is public information, should a company be allowed to harvest license plate numbers, combine this with location, and sell this information to different interested actors? This is currently happening in the United States.[39] Lastly, Big Data raises questions of ownership. A solution to the uncertainty of public vs. private data and associated consent and ownership could be the creation of a National Data Archive with such data. The archive could function with representation from the government, public and private companies, and civil society on the board. In such a framework, for example, companies like Airtel would provide mobile services, but the CDRs and customer data collected by the company would belong to the National Data Archive and be available to Airtel and all other companies within a certain scope for use. This "open data" approach could enable innovation through the use of data but within the ambit of national security and concerns of citizens, a framework that could instil trust in consumers and citizens. Only when backed with strong security requirements, enforcement mechanisms and a proactive, responsive and responsible framework can governments begin to think about ways in which Big Data can be harnessed.