Source · Select Committees · Culture, Media and Sport Committee

Recommendation 12

12 Accepted Paragraph: 102

Work with OPSS to promote data protection and security guidelines for IoT devices.

Conclusion
As the guidelines set out in the 2018 Code of Practice for Consumer IoT Security imply, cybersecurity and data protection are mutually reinforcing. Without cybersecurity, data cannot be meaningfully protected, while data protection can manage the risk and impact of cyberattack. The Information Commissioner’s Office, either bilaterally or through the Digital Regulation Co-operation Forum, which helps co-ordinate regulation of digital platforms and services, should work with the Office for Product Safety and Standards as it promotes the guidelines pertaining to data protection and data security in the 2018 Code of Practice.
Government Response Summary
The government commits that the Information Commissioner’s Office (ICO) will work with the Office for Product Safety Standards (OPSS), bilaterally or via the Digital Regulation Co-operation Forum, to support industry and ensure effective enforcement of new regulations.
Paragraph Reference: 102
Government Response Accepted
HM Government Accepted
We accept this recommendation. The Information Commissioner’s Office will work with the Office for Product Safety Standards, either bilaterally or through the Digital Regulation Co-operation Forum, to help support one another’s work, to most effectively support industry, and to ensure that enforcement of the new regulations is effective. This includes both manufacturers covered by the PSTI Act, regulated by the OPSS, and organisations who deploy technology as data controllers, covered by data protection law and regulated by the ICO.