Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Internet of Things Framework introduced by the Online Trust Alliance for our connected world

By Kathryn Rattigan on August 20, 2015
Email this postTweet this postLike this postShare this post on LinkedIn

On August 11, 2015, the Online Trust Alliance (OTA) released an Internet of Things (IoT) Trust Framework (the Framework), which presents guidelines for IoT manufacturers, developers, and retailers. The Framework was designed by a group of multi-stakeholders formed in January 2015, including ADT, AVG Technologies, Microsoft, Symantec, TRUSTe, Verisign, and over 100 other IoT experts. Craig Spiezle, Executive Director and President of OTA, said, “The rapid growth of the Internet of Things has accelerated the release of connected products, yet important capability gaps in privacy and security design remain as these devices become more and more a part of everyday life.” The Framework addresses only two key categories of IoT devices: home automation devices and consumer health and fitness wearables.

Specifically, some of the Framework’s highlights are:

  • Privacy Policies: “The privacy policy must be readily available to review prior to product purchase, download or activation and be easily discoverable to the user. Such policies must disclose the consequences of declining to opt-in or opt-out of policies, including the impact to usage of key product features or functionality.”
  • Limit Disclosures: “Any default personal data sharing must be limited to third parties/service providers who agree to confidentiality and to limit usage for specified purposes.”
  • Encrypt: “Personally identifiable data must be encrypted or hashed at rest (storage) and in motion using best practices including connectivity to mobile devices, applications and the cloud utilizing Wi-Fi, Bluetooth and other communication methods.”
  • Test: “Manufacturers must conduct penetration testing for devices, applications and services.”
  • Mitigate: “Manufacturers must publish and provide timely mechanisms for users to contact the company regarding issues including but not limited to the loss of the device, device malfunction, account compromise, etc.”

For the list of guidelines, click here.

Public comments on the Framework are due to the OTA by September 14, 2015. The OTA is also developing tools and methodologies that will formalize the Framework and ultimately lead to a voluntary Code of Conduct and certification program for IoT manufacturers, developers and retailers.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.

Read more about Kathryn RattiganEmail
Show more Show less
  • Posted in:
    Technology and AI
  • Blog:
    Data Privacy + Cybersecurity Insider
  • Organization:
    Robinson & Cole LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo