- Defines simple device erasure, associated-service removal, user instructions, and deletion confirmation expectations.
"delete user data"
A practical guide to the consumer IoT personal-data provisions in ETSI EN 303 645 clauses 5.8, 5.10, 5.11, and 6.
This helps scope technical controls and evidence. ETSI EN 303 645 can support privacy work, but it is not a substitute for a separate legal assessment.
Structured answer sets in this page tree.
Cited legal and guidance references.
Start with a product-specific inventory of , telemetry, sensors, purposes, recipients, retention, and deletion paths. Then apply clauses 5.8, 5.10, 5.11, and 6 with their stated legal force. EN 303 645 supplies technical data-protection provisions; it does not decide lawful basis, controller or processor roles, statutory retention, data-subject rights, or compliance with privacy law.
Start with the actual provision set. Clause 5.8 addresses confidentiality for moving between the device and services, stronger treatment for sensitive personal data exchanged with associated services, and accessible documentation of external sensing capabilities such as optical or acoustic sensors.
Clause 5.10 applies when telemetry is collected and recommends examining it, including log data, for security anomalies. Clause 5.11 covers user-data erasure from the device, personal-data removal from associated services, deletion instructions, and confirmation. Clause 6 adds processing transparency; consent, withdrawal, and consent records where consent is the basis; telemetry minimization and transparency; purpose-based data minimization and deletion; early aggregation with limited retention; and anonymization.
For clause 5.8, do not stop at a generic statement that traffic is encrypted. The useful evidence is a route-by-route map that shows which personal-data category uses which secure communication mechanism, what security guarantees it provides, and which cryptographic details are implemented.
TS 103 701 assesses whether secure communication mechanisms referenced by personal-data entries provide confidentiality for the relevant use case, whether the mechanism is appropriate for the technology, operating environment, risk, and usage, and whether the implemented cryptographic settings match the IXIT documentation.
Telemetry has two separate sets of provisions. Clause 5.10 recommends security-anomaly examination if telemetry is collected. Clause 6 requires transparency about what telemetry is collected, how it is used, by whom, and for what purposes, and recommends limiting personal-data processing in telemetry to what is necessary for the intended functionality.
The practical evidence should distinguish telemetry used for security examination from telemetry collected for other product purposes. TS 103 701 uses IXIT 24-TelData for telemetry description, purpose, security examination, and linked personal-data categories, and IXIT 2-UserInfo for the consumer-facing telemetry documentation.
Use the ETSI provisions and TS 103 701 evidence model to map personal-data flows, telemetry, consent, deletion, minimization, aggregation, anonymization, and user documentation before assessment.
Turn personal-data, telemetry, consent, and deletion requirements into assigned evidence requests.
Resolve narrow questions about provision scope, IXIT fields, and evidence expectations before implementation.
Review product scope, data flows, deletion paths, and assessment evidence with Sorena.
Clause 5.11 requires simple functionality for erasing user data from the device and recommends simple functionality for removing from associated services. It also recommends clear instructions for deleting and, where possible, erasing personal data from the device and associated services, and clear confirmation that personal data has been deleted and, where possible, erased from devices and associated services.
The deletion review should cover more than a factory reset button. EN 303 645 notes that factory reset may be inappropriate in shared-use situations where one user needs to remove their own without disrupting the owner or future users.
Provision 6-6 is mandatory where the device processes . It limits data stored or processed on the device, or made available to an associated service, to what is necessary for a purpose identified under Provision 6-1 and requires deletion when the data is no longer necessary for any identified purpose.
Provisions 6-7 and 6-8 are recommendations. Where collection or on-device processing exists solely to compute an aggregate, 6-7 calls for the minimum input needed, aggregation as early as possible, and minimized retention of both inputs and the aggregate. Provision 6-8 recommends anonymization technologies to protect privacy during collection, processing, and storage.
Review this checklist before publishing a claim, submitting evidence to an assessor, or using the page in procurement. Each item is based on the ETSI provisions or TS 103 701 evidence model and should be tied to a product version and assessment boundary.
"delete user data"
"personal data"
"valid way"
"telemetry data"
"Data protection provisions"
"Data anonymization technologies should be used to protect privacy during data collection, processing and storage."
"IXIT 21-PersData"
"Documentation of Telemetry Data"
"Security Examination"
"IXIT 25-DelFunc"
"confidentiality"