ICO sounds alarm over wearable tech privacy issues
Data protection body warns wearable tech users and device makers to be wary of falling foul of privacy regulations

The Information Commissioner's Office (ICO) is calling on wearable tech users to ensure data collected by their devices is processed in line with the UK's data protection laws.
This week alone has seen details emerge about new smartwatch technology from LG and Android, as well as the UK release of Google Glass to developers and beta testers, as the wearable tech trend continues to gain momentum.
If you are using a wearable technology for your own use then you are unlikely to be breaching the Act.
In the midst of this, the ICO has published a blog post, reminding users of the technology to be wary of the privacy implications of using it, and the laws surrounding the sharing of data created by wearable devices.
Andrew Paterson, the data protection watchdog's senior technology officer, said it is imperative the way wearable tech devices collect, process and share information is in line with the requirements of the UK Data Protection Act.
"If you are using a wearable technology for your own use then you are unlikely to be breaching the Act. This is because the Act includes an exemption for the collection of personal information for domestic purposes," Paterson explained.
For instance, if someone wears a devices that tracks health data that remains on the device, or is only viewable from a private computer, that is fine in the eyes of the Data Protection Act.
"But, if you were to one day decide that you'd like to start using this information for other purposes outside of your personal use, for example to support a local campaign or to start a business, then this exemption would no longer apply," he added.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Further complications may also emerge if the health tracking device above shares details of the jogging routes people have taken or publishes details of users' performance online to compare with others.
This type of data must be processed in line with the Data Protection Act, warns Paterson.
"This includes making sure that people are being informed about how their details are being collected and used, only collecting information that is relevant, adequate and not excessive and ensuring that any information that needs to be collected is kept securely and deleted once it is no longer required," he explained.
And it's not just the Data Protection Act wearable tech users and device makers risk falling foul of, as the CCTV Code of Practice also comes into play for tools that capture pictures and videos.
"The rise of wearable technology brings exciting new possibilities and is set to become widespread in the years ahead," he added.
"But organisations must not lose sight of the fact that wearables must still operate in compliance with the law and consumers' personal information must be looked after," Paterson concluded.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd
-
AI recruitment tools are still a privacy nightmare – here's how the ICO plans to crack down on misuse
News The ICO has issued guidance for recruiters and AI developers after finding that many are mishandling data
By Emma Woollacott
-
“You must do better”: Information Commissioner John Edwards calls on firms to beef up support for data breach victims
News Companies need to treat victims with swift, practical action, according to the ICO
By Emma Woollacott
-
LinkedIn backtracks on AI training rules after user backlash
News UK-based LinkedIn users will now get the same protections as those elsewhere in Europe
By Emma Woollacott
-
UK's data protection watchdog deepens cooperation with National Crime Agency
News The two bodies want to improve the support given to organizations experiencing cyber attacks and ransomware recovery
By Emma Woollacott
-
ICO slams Electoral Commission over security failures
News The Electoral Commission has been reprimanded for poor security practices, including a failure to install security updates and weak password policies
By Emma Woollacott
-
Disgruntled ex-employees are using ‘weaponized’ data subject access requests to pester firms
News Some disgruntled staff are using DSARs as a means to pressure former employers into a financial settlement
By Emma Woollacott
-
ICO reprimands Coventry school over repeated data protection failures
News The ICO said the academy trust failed to follow previous guidance, which caused a serious data breach
By Emma Woollacott
-
ICO dishes out fine to HelloFresh for marketing spam campaign
News HelloFresh failed to offer proper opt-outs, the ICO said, and customers weren’t warned their data would be used for months after they cancelled
By Emma Woollacott