Showing posts with label Internet of Things. Show all posts
Showing posts with label Internet of Things. Show all posts

Tuesday, 28 March 2017

Hacking the playroom: How can children be safe and protected in the digital world?

This year, the digital world will reach a significant milestone – Almost 50% of the world’s estimated 7.4 billion population will be online. And, according to research by UNICEF Innocenti, one-third of these will be children.

So what are the particular risks or harms that children face in an increasingly connected world? In this blog, children’s online rights expert Dr Rachel O’Connell will examine the issues  through the perspective of recent reports about connected toys. She will then consider the new European Union data protection rules, which come into force in 2018 and how these and other developments might help to provide more security, privacy and safety.



Toys that talk and listen
As connected and smart toys are being utilised by companies as marketing tools, advertising, product placement and sponsoring are increasing. For example, Cayla “the world’s first interactive doll” came in for criticism, when she was found to have in-built audio tools designed to market foods high in sugar or fat to children. You can see the video here from BEUC the European Consumer’s organisation.

Cayla was also in trouble for failing to protect children’s data and privacy. The blue-tooth enabled doll comes with a microphone to capture children’s speech which can then be analysed using a third party app.  So concerned was Germany's network watchdog by what they deemed the unlawful surveillance capability of the doll that they urged parents to destroy her:

Any toy capable of transmitting signals and surreptitiously recording audio or video without detection is unlawful. The danger, the agency claims, is that anything a child or someone else says in the vicinity of the doll can be transmitted without parents' knowledge. Also, lack of network security could allow the toy to be turned into a listening device, the agency suggests.

To be clear…
The company that produced the Cayla doll would have had numerous contractual relationships between a range of third parties, which include data processors, app platforms, marketing technology and advertising platforms, data management platforms, data analytics, and speech recognition software.

While blanket permission for these businesses to process a child’s data will have been given, when a parent clicks ‘I Agree’ to the Terms of Service and Privacy Policy, the limits to this approach to informed consent have been well documented

Rights of the child
As well as advertising and security, regulators are concerned by violations of the legal protection of children’s rights afforded under the UN Convention of the rights of the child , including Article 16:  

·         No child shall be subjected to arbitrary or unlawful interference with his or her privacy, family, or correspondence, nor to unlawful attacks on his or her honour and reputation.
·         The child has the right to the protection of the law against such interference or attacks.

However, as the UK Information Commissioner's Office (ICO) highlighted, under existing data protection legislation there was ‘little that could be done to prevent unscrupulous third parties from harvesting a child’s data and using it for inappropriate purposes’[1].

The new General Data Protection Regulation (GDPR), which comes into force in May 2018 stipulates why children’s rights merit specific protection with regards to their personal data:

“Children may be less aware of the risks, consequences and safeguards concerned and their rights in relation to the processing of personal data. Such specific protection should, in particular, apply to the use of personal data of children for the purposes of marketing or creating personality or user profiles and the collection of personal data with regard to children when using services offered directly to a child.”

Article 8 of GDPR also states that where a child is below the age of 16 years, processing of their personal data is only lawful if consent is given or authorised by the holder of parental responsibility over the child. Member states can choose to lower the age at which parental permission is required to 13 years of age, but no lower.

The GDPR specifically states that separate consent will be needed for different processing operations – this means that in the future it will not only be a requirement to inform consumers of who the data processors are and obtain consent, they must also enable consumers to withdraw this permission at any point.

Privacy by design
 A key principle underpinning  GDPR is that businesses will need to adhere to the principle of Privacy by Design, which requires privacy and data protection compliance during the product or service design stage, instead of bolting them onto the end. These rules will have a reach far beyond the EU as any business processing EU citizens’ data will have to abide by them.

New rules, new tools
What is beginning to emerge, driven primarily by regulation, is a raft of technical standards which detail how businesses can develop Privacy Enhancing Technologies (PETs) that provide consumers with greater control over their personal data. For example

·         The PAS 1296 Age Checking code of practice is due for publication by the British Standards Institution next month, provides guidance for businesses mandated to check the age-related eligibility of consumers and to obtain verified parental consent before processing children’s data.
·         Kantara’s consent receipt specification enables consumers, to communicate and manage the personal data they have shared.

·         User-Managed Access protocol (UMA) is an access management protocol standard, which will enable end users to better protect their data no matter which platform they are on.

The global consumer movement has a duty to advocate for the adoption of best-practice tools and ensure that existing and new digital services are built with consumer protection in mind. Educating consumers about the choices they have available to them will also help pave the way for a digital world that is safer and more secure for people of all ages.





Monday, 13 March 2017

Consumers and the Internet of Things: one connection too many?

Liz Coll, Head of Digital Advocacy at Consumers International, takes a look at recent trends in the global uptake of connected devices and considers what these trends can tell us about consumer attitudes towards the Internet of Things.  



Last year our report on ‘Connection and Protection in the digital age’ explored the impact of the rapidly expanding trend of the Internet of Things (IoT) – with more and more everyday objects connecting to the internet. As with any ‘next big thing’ topic, the figures looked astounding with some commentators predicting 50 billion IoT devices to be connected by 2020.

New reports in 2017 have not been quite so bold with their predictions. According to analyst firm Gartner, the total number of IoT devices deployed by 2020 is more likely to be just over 20 billion. As with any forecast about the future of the digital economy, there are no certainties – but this drop feels significant. Could it be that consumer attitudes and concerns about connected devices are, at least partly, behind these more reserved predictions in 2017?

Our 2016 report suggested that security concerns and the invasive nature of connected technology would potentially hold back consumer engagement in this next deeper, more personal phase of digital technology. The focus of our work with G20 governments to help ‘Build a Digital World Consumers can Trust’ makes the case that unless consumers can trust digital technology, they won’t readily accept it into their everyday lives.  Getting trust right is therefore a key part of creating a vibrant demand side for the market.

So does it look like this is the case for the consumer market for IoT devices? A report released by Deloitte in 2016 points to an uneven uptake of consumer IoT devices in more developed economies. Connected entertainment devices such as games consoles and smart TVs have maintained a steady growth but sales of Fitbit devices failed to meet expectations.

Some research indicates that this limited take off is because of a failure to meet people’s needs, both in terms of pricing and also the difficulty of use and maintenance. As shown in the MEF Global Consumer Survey from April 2016, the levels of privacy and security were also problematic for consumers, with 62% and 52% of those surveyed reporting these as the biggest concerns, respectively.

Another example of the noticeable consumer resistance to connected devices has been the move by some Fitbit users to turn off the smart elements of their devices off only months after purchasing the products. With novelty seemingly wearing off so quickly, does this mean that penetration of IoT devices won’t happen as all those excited articles predicted?

In reality, it is hard to prove or predict that people won’t buy internet of things products because of a lack of trust. As privacy and technology expert Gilad Rosner somewhat ominously predicted that business momentum will mean that “The Internet of Things will happily march along with lousy privacy and security, and we will be the poorer for it”. 

Connected technology seems to be one of those things that creeps into products – an alarm clock on a smart phone that suddenly wants to become a ‘sleep tool’ to help you enjoy a restful night. An insurance provider that offers a subsidised fitness trackers, for as long as you keep active.

But with high profile internet of things problems such as the #Toyfail and the development of devices such as fertility trackers collecting and analysing sensitive information about one of the most private aspects of people’s lives, perhaps people will start to demand technology that is not just helpful but safe, ethical and human-centered.

How can consumer organisations play a leading role by working with businesses to ensure that connected devices can be safer, less invasive and prioritise consumer interests? Our member Consumer Reports’ new digital standard initiative is an excellent example of how the global consumer movement can evaluate and test the safety of digital products and services, empowering consumers to make informed choices about whether they want to invest in IoT devices. This week, Maria Rerecich of Consumer Reports will speak at an SXSW event that considers how a consumer organisation can include privacy, security, and data practices in its testing protocols.

As consumer organisations continue to monitor ongoing developments in the connected world, it’s vital that the global consumer movement advocates for businesses to build security and privacy in at the design stage. It’s not just the right thing to do but could be a smart business move as consumers look for products they’re sure they can trust  – for your child’s next birthday would you buy a smart toy classed as ‘espionage equipment’?

We are co-hosting the G20 Consumer Summit in Berlin on WCRD this week which will provide an excellent opportunity to engage in a dialogue with governments, business leaders and key stakeholders about the most pressing concerns that consumers face and how to work together to create a better digital world.


Friday, 9 December 2016

Internet-connected toys: A #ToyFail with global implications


Amanda Long, Director General at Consumers International, discusses the failure of My Friend Cayla and i-Que dolls to protect consumer privacy and considers what this means for consumers globally. 



The way in which consumers are interacting with the digital world is constantly evolving. With more than 3 billion people now connected to the internet worldwide, there is a growing opportunity for everyday objects to be synced with the web. By 2020, it is forecasted that the number of connected devices will reach 50.1 billion and children’s toys are no exception to this trend.

In the wake of the Norwegian Consumer Council’s #ToyFail report, Consumers International and several of our Members have condemned the miserable failure of My Friend Cayla and i-Que toys to protect consumer data, security and privacy. Not only are these toys dangerously easy for others to gain access to, they are also able to record everything the child says and transfer the recordings to a company that can sell the information on the third parties. 

This irresponsible lapse in consumer protection raises a number of important questions. How has this failure impacted on consumers across the world? What can it tell us about the current gaps between rapid digital innovation and the policies in place to protect consumer privacy and data? How can the global consumer movement use its collective voice to call for change? 

By looking at the manufacturing and distribution network of these toys, it is easy to see that the reach of this issue has no borders. Genesis Toys, the company that produces and develops both the Cayla and i-Que dolls, are based in Los Angeles, California. The products are then manufactured in Hong Kong before being distributed to retailers in the U.S, South Africa, the Middle East, Australia and Scandinavia. British toy company Vivid also distribute the toys to markets in Europe, including the UK, France and Germany. The companion app for the toys is developed by ToyQuest, who have offices across the globe and are partnered with a wide range of licensors including Disney, Nickelodeon and DreamWorks. 

The international reach of these companies is hugely significant. The availability of the toys in a wide range of markets maximises the number of consumers affected by the breaches in security and privacy. The capacity of national consumer protection policies in each market will also differ from country to country, leaving some consumers more exposed than others. 

Digital innovation is undoubtedly a key driver of progress and has the potential to create many opportunities for consumers. The benefits should not, however, come at the expense of the rights of individuals. Consumers must feel that they can use their products safely and securely without concerns that their thoughts, opinions and feelings will be passed on to the highest bidder. Trust should be at the forefront of every relationship between digital providers and consumers. In this case, it would seem that the trust of parents and children using the toys has been undermined. 

It is also essential that companies adopt a design-philosophy that puts safety, privacy and security at the top of their priority list when developing new products. As the speed with which the creation of new technologies and devices accelerates, manufacturers and governments must make sure that their safeguarding of consumer interests keeps up the pace. 

As this story continues to develop, we must ensure that the collective voice of consumers across the globe is heard. Working together with our Members, Consumers International has acted quickly to brief and share engagement tools with consumer organisations in affected markets outside of Europe, enabling them to liaise with the relevant national authorities and media outlets. Regardless of where consumers are based in the world, we are calling for the manufacturers to:

  • Not collect more data than necessary for the functionality of the service
  • Prevent these kind of issues resurfacing by adopting a design-philosophy of privacy and security by design.
  • Make these toys safer by increasing security features in how devices are paired, to stop unauthorised people from connecting to the toy.
  • Stop all direct marketing to children through to apps

By following these guidelines and prioritising consumer protection, digital providers can begin to move towards a world in which consumers can fully benefit from advances in technology without the fear of their rights being eroded.

Sources
- #Toyfail: An analysis of consumer and privacy issues in three internet-connected toys, Norweigan Consumer Council
- Here’s How Many Internet Users There Are, TIME
- IoT: number of connected devices worldwide from 2012 to 2020, Statista

Tuesday, 4 October 2016

How can consumers make meaningful choices in the digital world?

This week, Amanda Long, Director General of Consumers International spoke at EDPS-BEUC conference on Big Data: Individual Rights and Smart Enforcement [1]in Brussels which brought together issues of competition, consumer protection and data protection.  You can read Amanda’s full speech here. Below is an extract.
Questions of size, power, competition and choice have never been so important to our understanding of consumer protection and empowerment in the digital world.  The reach of so many big internet companies is remarkable: one in two global internet users visit Amazon on a monthly basis[2].  Google has a 71% share of the search market globally, rising to 90% in the European Union[3]. WhatsApp is the top messaging app in 109 countries, or 56% of the world.[4]

Consumers are feeling the direct impact that such large players have on their individual choices: from privacy tools disappearing from app stores[5], or WhatsApp users seeing the service bought out by Facebook, followed by changes to the terms of data sharing [6],  to the impenetrable terms and conditions which people must agree to in order to access digital services[7].  These digital services that quickly link up friends, music, events and travel are convenient and can be great fun but can also feel a bit like a lobster pot - easy to get into but very tricky to get out of.

Many multinational platforms and digital companies have become indispensable to contemporary life, offering high quality, convenient digital interactions. The data monetisation model behind some, where people ‘exchange’ information about themselves for the service with no upfront financial cost, makes for a tantalising offer.   They are the default by which consumers experience and interact with digital - the gateway to the internet if you like: we don’t search, we Google, we don’t make videocalls, we Skype.

The dominance of a small number of firms is significant because people’s choice over whether to engage or not in the digital world is becoming increasingly limited.[8]  If a few large companies effectively become gateways to all the internet has to offer, then we have to ask questions about how their size and dominance impact consumer choice, power and protection?

In the European Union, the prospects of keeping markets competitive and consumers protected are closely tied. It is suggested that competition itself can offer a protection of sorts by creating markets where companies compete for customers on the basis of value, quality and strong consumer credentials. In reality, without a range of options, and without an easy way to move between these options, it is difficult for consumers to sever ties if they are unsatisfied with a particular service. As a result, it becomes very hard to gauge whether people are happy or unhappy with services and the way companies operate. Classic ideas of competition and consumer protection are therefore stretched. 

Looking ahead to the next phase of digital consumption; the internet of things, heavy reliance on a small number of large companies could become even more important.  As well as raising privacy and security issues, the internet of things marks a major change in how we think about consumption, purchase and ownership. This is mostly because of so-called ‘hybrid’ products [9]– where physical products are owned by the customer, yet the presence of software means the device is subject to contract terms and conditions, which could put unexpected limitations on its use or make exiting a contract difficult.

Large established players already marking out territory in the internet of things will have to gather and connect data to as many objects and people as possible to make their connected services thrive. The more data points connected, the more potentially valuable the insights, so drawing in and retaining as many customers as possible will be top of companies’ agenda.  Exercising choice could get harder for consumers, as they lean towards contracting with one company as an easy way of bringing together multiple services. In practice, switching provider by exiting contracts will be time consuming or inconvenient.  Add to this the difficulties in transferring data between suppliers and lock in seems more and more inevitable.
These limitations on choosing between providers are really important for the digital age.  If competition can no longer effectively deliver consumer protection through providing choice, then we need to approach things differently.   In fact there is the real opportunity to forge a positive consumer agenda for the digital age that addresses areas of consumer concern and offers real choice over how to participate.  A complex, integral and dominating set of relationships should not put us off arguing for a fairer and more accountable digital system for consumers.
For example:
-          Data portability and system interoperability – to enable easy transfer between different services, keep different options open, and keep the value of data close to consumer control
-          Smarter use of information, and more transparency on how decisions based on data are made, not just what data is collected.  
-          Innovations that aid consumer understanding and build consumer trust and confidence such as personal data intermediaries. 

The genie is out of the bottle.  Widespread digital technology is here.  There is real potential for consumers to benefit but also a flip side presenting widespread negative consumer outcomes.  It is up to us to work together to ensure that the practices and delivery of large digital companies stand up to the scrutiny and expectations of the people whose lives are so entwined with them.




Friday, 5 August 2016

CI work on mobile banking standard ISO 12812

Robin Simpson and Sadie Homer, Senior Policy Advisors at Consumers International report on their work preparing the new international standard on mobile banking.
  
Back in January 2012, the International Organization for Standardization (ISO) asked for experts to join the working group preparing a new international standard on Mobile Banking/Payments, in particular asking CI if we could represent the consumer stakeholder group, providing expertise, particularly in the field of consumer protection.

Four years later our efforts have borne fruit in the form of  ISO 12812 Core banking – mobile financial services. It takes the form of an international standard on the general framework for these services (Part 1) and is supported by four technical specifications on specific sectors of the business (parts 2-5 see below).

Achieving an ISO standard was not a smooth passage, two rounds of voting by national standards bodies were needed to gain approval. The second only succeeding on the basis that papers 2-5 do not have full international standard status. Nevertheless, CI felt able to support the final standard but it was not an easy process. Consumer experts encountered resistance to some basic consumer protection issues being included at times, even when they were optional (and bearing in mind that international standards are voluntary).

Ably assisted by experts from our members we fought for limits on how much consumers would be liable for, in the case of unauthorised or fraudulent use of their payment systems. We secured greater transparency in remittances sent between countries and we gained important safeguards on logging transactions and receipts, with electronic logs being kept available. One specific issue that was not considered until our intervention was the treatment of dormant assets, in particular in the event of the death of an account holder.  This is a major issue where consumers do not have an individualised mobile phone contracts, such as in much of Africa.

How worth-while are such exercises? After all, standards are not legally binding, they are voluntarily adopted by companies and cannot be enforced in court. CI expended scarce resources travelling to Paris, Chicago, Boston, also taking part in many teleconferences, and drafting in great detail.  These factors are important considerations. But without our participation the consumer voice would not have been heard at all. The alternative, legislation and binding regulation, can only be applied at national level one country at a time, and legislation may be even slower to develop than standards, if at all. 

Even if it will require another review for our conditions to be fully met, the applicability of this standards is potentially global. And in many countries, the standards adopted today can form the basis of regulation tomorrow. Standards can also be used by consumer organisations as a sound basis to compare businesses and to support those that offer best practice terms to consumers. They can also be used to hold transnational companies to account to provide an equal level of service to all consumers, in all countries they are doing business.

Papers 2-5 will be reviewed in two years’ time and CI would also support a review of ISO 12812, given the speed of development in this sector. At that point we hope to be able to strengthen the standard further and make the case for all parts to be given full International Standard status. The mobile payment and banking sector is fast evolving, and so the standards that keep consumers safe must also move with it. 


You can read more about the Standards here

Tuesday, 5 July 2016

Defining Consumer Protection in the Digital Age

Robin Simpson, Consumers International's (CI) Senior Policy Adviser, recently represented CI at the OECD Ministerial Meeting on The digital economy innovation, growth and social prosperity which took place in Cancun, Mexico. He spoke at the Civil Society Forum convened by the OECD Civil Society information Society Advisory Council (CSISAC) and in the main agenda panel discussion on Consumer Trust and Market Growth, chaired by the French Secretary of State for the Digital Economy Mme Axelle Lemaire. Here are his impressions.

This event was big in both senses, hundreds of delegates and a substantial agenda of great importance to consumers. Such events are infrequent, the previous one was was in Seoul in 2008 a long gap given the speed with which developments take place in this technology driven area. The OECD has a very active work programme in which we are implicated through our membership of the Committee on Consumer Policy on which I have represented CI for 10 years. It is fair to say we have a critical stance on policies adopted (see below) but equally fair to note that they encourage our input. 

I start at the end. Like many such conferences it concluded with a grand declaration almost entirely pre-cooked. National delegations undertook to: 
  1. Support the free flow of information,
  2.   Stimulate digital innovation and creativity,
  3.  Increase broadband connectivity and …., protect consumers,
  4.  Embrace the opportunities arising from emerging technologies and applications such as the Internet of Things,
  5. Promote digital security risk management and the protection of privacy at the highest level of leadership
  6. Stimulate and help reduce impediments to e-commerce within and across borders
  7.  Take advantage of the opportunities arising from online platforms
  8. Spur the employment opportunities created by the digital economy
  9. Strive for all people to have the skills needed to participate in the digital economy and society

How can we possibly not like such a list of virtuous objectives? In the panel discussion chaired by Mme Lemaire, I described how the success of third party platforms has been underpinned by their acceptance of limited liability for consumers in the event of breaches of security and other ancillary supports such as dispute resolution. And I argued for the development of universal international standards for data protection and privacy. All of this is compatible with the above

But, as so often, what is most interesting about conference declarations is not so much what they include as what they do not include. Or the force with which major principles are stated…or not. CSISAC pointed out that privacy is insufficiently addressed by the declaration. Point 1 talks of ‘respecting applicable frameworks’ for privacy, point 5 seeks to  ‘promote…the protection of privacy at the highest level of leadership’. But privacy is a human right as recognised by the UN declaration on Human Rights of 1948 and the International Covenant on Civil and Political Rights 1966 and needs to be stated as such. CSISAC also made the link between such rights and the Internet of Things (IoT).

But the declaration, in mentioning the IoT, sets down no markers in that regard, including only the usual qualifier ‘appropriateness’ when considering the need for regulatory frameworks. ‘Appropriate regulation’ is frequently a euphemism for reduction of regulation, a danger in a sector which is in our view dangerously exposed  to corporate abuse as is demonstrated by our recent publication: The Internet of Things and the challenges for consumer protectionWe make the point there that Intellectual property law is in danger of eclipsing consumer protection law in the digital area particularly in the IoT because software is governed by copyright law, which envisages use of products being licensed rather than the products being purchased. Licensees have far fewer protections as consumers compared with outright purchasers.

In the closing paragraphs of the statement, the national delegations ‘further declare’ that they will: ‘help preserve the fundamental openness of the Internet while concomitantly meeting certain public policy objectives, such as the protection of privacy, security, children online and intellectual property, as well as the reinforcement of trust in the Internet;’. Intellectual property is, we argue, over-protected in as much as consumers may find their computers rendered non-functional by technical protection measures in the event of their having transgressed, usually unwittingly, copyright elements within contracts of licence. Such technical measures are triggered by algorithms, not by agents of service providers and as such, escape judicial controls regarding the extent to which they are justifiable or proportionate. And in that respect, the statement as indeed the panel discussion on the Internet of Things, remained silent. 

Despite the technological razamatazz which characterised much of the conference, the discussion has not kept pace with the excessive technical measures taken against consumers that have been out there in the market place for over a decade now.



Tuesday, 17 May 2016

Does the Internet of Things mean we’ll never be left to our own devices?

Liz Coll, Digital Policy Expert, introduces and outlines consumer concerns around the Internet of Things in light of Consumers International's latest report.



Nest’s announcement last month that it would no longer support Revolv’s smart home controller may not have topped many consumer’s concerns, but it clearly demonstrates the kinds of detriment that look set to arise from the Internet of Things

Revolv (acquired by Google’s Nest in 2014) let people connect and control all of the smart switches, security devices, sensors, and heating in their home. This week it will be switched off, so the hardware will no longer function. The Revolv customer (and ‘lifetime’ subscription holder) who first drew attention to this in a blog, sums up the impact of its closure on him: 

 “My house will stop working. My landscape lighting will stop turning on and off, my security lights will stop reacting to motion, and my home made vacation burglar deterrent will stop working. This is a conscious intentional decision by Google/Nest.”

Consumers who bought the product with a lifetime subscription were left wondering whether they would have any rights to refunds, or replacements or what would happen with its data? Since the user outcry, there been a change of heart, and now refunds will be issued for the hub purchase price. 

But is pulling the plug on owned devices a one off, an inconvenient by-product of fast moving technology, or could this be a worrying indication of a potential future for the Internet of Things? We may see a future where device functionality is more and more dependent on remote decisions with little input from owners, and where large companies definition of a product ‘lifetime’ prevails. 

The future’s here

With estimates that, already, 25 billion devices are connected to the Internet of Things – a figure that’s set to double by 2020 -  connected devices now outnumber people by nearly  4 to 1. 

No longer a futuristic concept, the Internet of Things is becoming embedded in everyday life - along with some patterns that may cause alarm for consumers. It’s not just about devices and appliances at the luxury end of the market (such as talking fridges), Consumer International’s (CI) latest research with Members in Kenya, the Philippines and Nigeria discovered that smart systems and products are connecting and collecting data on users and services across all walks of life, including healthcare and public transportation.  

Of course, consumers could stand to benefit in many ways, as more devices across more sectors share usage information and learning. Think of the convenience of a smart car whose tyre sensors detect the precise time at which you need a replacement; the peace of mind of a smart home security system, or items tagged with location sensors; the ease of using a connected transit system across a busy city; or an energy home system that learns and adjusts to your preferences and habits.



The erosion of ownership

So far the capacity of these devices to collect detailed, time sensitive and often personal data and share it with other devices or remote hubs has been the subject of much attention and discussion about privacy. Security is also a huge concern, with much larger surface area meaning increased vulnerability.  

But the implications go much further than this and could, as in the case of Revolv’s smart home kit, suggest a world where the normal expectations of what we can do, and for how long, with things we have purchased are turned on their head.  

Our new report calls this the ‘erosion of ownership’ which could come about as tangible objects take on digital properties by way of the software embedded into them. We expect to see more hybrid products emerging where the part of the product containing software is licenced via contract while the device itself is owned. In such cases, will operation of the device be subject to contract terms which can put unexpected limitations on how the product is used - or in Revolv’s case, if it can actually be used at all? There are even fears that we may start to see the type of remote automated contract enforcement recognisable from digital rights management, where technical blocks are put on to limit particular uses and prevent unauthorised use, repair or plug-ins.

Upholding rights for the future

How easy will it be for consumers to understand or uphold their rights, or attempt to uphold them given such complex lines of responsibility? Or where there is confusion over exactly what a consumer can or can’t do with a product they have purchased? 

We know laws find it hard to keep up with technological developments, and that as products and companies cut across not only sectors but national jurisdictions, that regulation and enforcement of consumer rights is challenging. Additionally, we cannot rely on competition to provide for checks and balances as a small number of companies dominate, and provider lock- in is already evident in the infancy of the Internet of Things.  

To make sure that we really can be left to our own devices if we prefer, consumer protection and concepts of proportionality, fair use and fair processes, must be put at the centre of discussions on the Internet of Things development and delivery. 

What’s more, to move beyond protection and into a scenario where consumers can gain insight and convenience from connected devices on their own terms, services and products should be designed with consumer trust and controls built in, with easy ways to hold companies who overstep the mark to account.