A Privacy Engineering Framework for the Internet of Things Antonio Kung1, Frank Kargl2, Santiago Suppan3, Jorge Cuellar4, Henrich C. Pöhls5, Adam Kapovits6, Nicolas Notario7, Yod Samuel Martin8 1 Trialog, Paris, France
[email protected] 2 Ulm University, Ulm, Germany
[email protected] 3,4 Siemens, Munich, Germany 3
[email protected] 4
[email protected] 5 University of Passau, Passau, Germany
[email protected] 6 Eurescom, Heidelberg, Germany
[email protected] 7 Atos, Madrid, Spain
[email protected] 8 Universidad Politécnica de Madrid, Madrid, Spain
[email protected] Abstract. This paper describes a privacy engineering framework for the Internet of Things (IoT). It shows how existing work and research on IoT privacy and on privacy engineering can be integrated into a set of foundational concepts that will help practice privacy engineering in the IoT. These concepts include privacy engineering objectives, privacy protection properties, privacy engineering principles, elicitation of requirements for privacy and design of associated features. The resulting framework makes the key difference between privacy engineering for IoT systems targeting data controllers, data processors and associated integrators, and privacy engineering for IoT subsystems, targeting suppliers. Keywords: Privacy-by-design, Internet of things, IoT system, IoT subsystem, Integrator, Supplier. 1 Introduction 1.1 The Internet of Things The Internet of Things (IoT) refers to smart devices, sensors, and actuators that are embedded in the physical world, connected to each other and to further computing resources, allowing applications and intelligent services to understand, track, and control almost anything in the physical world through standard communication networks.