Artifact GuideGLOBALETSI EN 303 645

ETSI EN 303 645 Data Protection Provisions

A practical guide to the consumer IoT personal-data provisions in ETSI EN 303 645 clauses 5.8, 5.10, 5.11, and 6.

This helps scope technical controls and evidence. ETSI EN 303 645 can support privacy work, but it is not a substitute for a separate legal assessment.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
6

Structured answer sets in this page tree.

Primary sources
12

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Start with a product-specific inventory of , telemetry, sensors, purposes, recipients, retention, and deletion paths. Then apply clauses 5.8, 5.10, 5.11, and 6 with their stated legal force. EN 303 645 supplies technical data-protection provisions; it does not decide lawful basis, controller or processor roles, statutory retention, data-subject rights, or compliance with privacy law.

Section 1

What do the ETSI EN 303 645 data protection provisions cover?

Start with the actual provision set. Clause 5.8 addresses confidentiality for moving between the device and services, stronger treatment for sensitive personal data exchanged with associated services, and accessible documentation of external sensing capabilities such as optical or acoustic sensors.

Clause 5.10 applies when telemetry is collected and recommends examining it, including log data, for security anomalies. Clause 5.11 covers user-data erasure from the device, personal-data removal from associated services, deletion instructions, and confirmation. Clause 6 adds processing transparency; consent, withdrawal, and consent records where consent is the basis; telemetry minimization and transparency; purpose-based data minimization and deletion; early aggregation with limited retention; and anonymization.

  • List each category of processed by the device or associated service, including purpose, processor or authorized party, lifecycle, consent basis where used, and secure communication mechanism.
  • Identify sensitive by product context; ETSI gives examples such as home-security video, payment information, communication content, and timestamped location data.
  • Do not treat the word sensitive as a fixed EN 303 645 category list. The standard says the harm potential varies across products and use cases, so record why a particular disclosure could cause harm in this product context.
  • Document all obvious external sensing capabilities in a way ordinary users can access and understand, including inactive capabilities that could still be enabled by compromised firmware.
  • Treat GDPR references narrowly: EN 303 645 provides technical data-protection features and can support compliance work, but it does not determine the lawful basis, controller or processor roles, legal retention duties, or compliance with applicable privacy law.
Section 2

How should personal data in transit be protected?

For clause 5.8, do not stop at a generic statement that traffic is encrypted. The useful evidence is a route-by-route map that shows which personal-data category uses which secure communication mechanism, what security guarantees it provides, and which cryptographic details are implemented.

TS 103 701 assesses whether secure communication mechanisms referenced by personal-data entries provide confidentiality for the relevant use case, whether the mechanism is appropriate for the technology, operating environment, risk, and usage, and whether the implemented cryptographic settings match the IXIT documentation.

  • Create an IXIT-style personal-data table with description, purpose, authorized parties, lifecycle, processing activities, secure communication mechanisms, sensitivity, consent handling, and anonymization where applicable.
  • For sensitive sent between the device and an associated service, show the associated service relationship and the mechanism protecting confidentiality.
  • Keep cryptographic evidence specific: protocol, version, cipher suite or comparable details, communication partner, and whether confidentiality is accompanied by integrity or authenticity protection.
  • Add a functional check that the observed traffic protection matches the documented secure communication mechanism instead of relying only on architecture diagrams.
Section 3

What evidence is needed for telemetry and consumer transparency?

Telemetry has two separate sets of provisions. Clause 5.10 recommends security-anomaly examination if telemetry is collected. Clause 6 requires transparency about what telemetry is collected, how it is used, by whom, and for what purposes, and recommends limiting personal-data processing in telemetry to what is necessary for the intended functionality.

The practical evidence should distinguish telemetry used for security examination from telemetry collected for other product purposes. TS 103 701 uses IXIT 24-TelData for telemetry description, purpose, security examination, and linked personal-data categories, and IXIT 2-UserInfo for the consumer-facing telemetry documentation.

  • For each telemetry category, record the description, collection trigger, purpose, security examination if any, and any personal-data categories included.
  • Show why linked is necessary for the telemetry purpose; unsupported convenience collection should be treated as a gap.
  • Make consumer documentation match the telemetry inventory, including what is collected, how it is used, who uses it, and the purposes.
  • Do not claim every telemetry feed supports security monitoring; if no security examination is performed for a feed, state that clearly in the evidence model.
Section 4

How should user data deletion be designed and tested?

Clause 5.11 requires simple functionality for erasing user data from the device and recommends simple functionality for removing from associated services. It also recommends clear instructions for deleting and, where possible, erasing personal data from the device and associated services, and clear confirmation that personal data has been deleted and, where possible, erased from devices and associated services.

The deletion review should cover more than a factory reset button. EN 303 645 notes that factory reset may be inappropriate in shared-use situations where one user needs to remove their own without disrupting the owner or future users.

  • Define deletion functionality by target type: user data on the device, on associated services, user configuration, and user-related cryptographic material such as passwords or keys.
  • For each deletion flow, document initiation steps, user interaction, confirmation message, and the data categories it covers.
  • Test typical data creation, execute each deletion function, and verify whether the corresponding data still exists on the device or associated service.
  • Include backup copies and linked applications in the deletion analysis. EN 303 645 says consumers who request complete deletion also expect retrospective deletion of backups, while applicable law and system design determine the supported process.
  • Where multiple users are supported, verify that a user without elevated privileges cannot delete another user's data.
Section 5

What changed in the V3.1.3 purpose, aggregation, and anonymization provisions?

Provision 6-6 is mandatory where the device processes . It limits data stored or processed on the device, or made available to an associated service, to what is necessary for a purpose identified under Provision 6-1 and requires deletion when the data is no longer necessary for any identified purpose.

Provisions 6-7 and 6-8 are recommendations. Where collection or on-device processing exists solely to compute an aggregate, 6-7 calls for the minimum input needed, aggregation as early as possible, and minimized retention of both inputs and the aggregate. Provision 6-8 recommends anonymization technologies to protect privacy during collection, processing, and storage.

  • For each personal-data category, record the stated purpose, the fields needed for it, the retention rule, and the deletion trigger.
  • For aggregation-only processing, document why each input is needed, where aggregation occurs, and how long raw inputs and aggregate results remain.
  • For anonymization, identify the method and verify that the implemented processing matches the IXIT description; do not label pseudonymous or merely de-identified data anonymous without case-specific support.
  • Keep these EN provisions separate from legal retention or deletion decisions that depend on applicable law and the product's facts.
Section 6

Release checklist for ETSI EN 303 645 data protection evidence

Review this checklist before publishing a claim, submitting evidence to an assessor, or using the page in procurement. Each item is based on the ETSI provisions or TS 103 701 evidence model and should be tied to a product version and assessment boundary.

  • Personal-data inventory: every data category has purpose, authorized parties, lifecycle, processing activities, secure communication mechanisms, consent handling where used, sensitivity classification, aggregation status, and anonymization method where used.
  • Sensor transparency: user-facing documentation lists external sensing capabilities and explains them in accessible language.
  • Telemetry register: every telemetry category has purpose, security-examination status, linked , and matching consumer-facing documentation.
  • Consent evidence: when consent is the basis for processing, the flow shows a free, obvious, explicit opt-in choice, withdrawal at any time, and storage of consent information.
  • Legal-basis boundary: do not demand an EN 303 645 consent flow for processing that does not rely on consent; document the privacy-law basis separately and apply provisions 6-2, 6-3A, and 6-3B only where consent is the basis.
  • Deletion evidence: device and associated-service deletion functions are documented, executable by users with limited technical knowledge, cover the intended data categories, and provide clear confirmation.
  • Purpose and retention evidence: data fields are limited to their identified purposes, deletion triggers are testable, and aggregation-only flows minimize inputs and retention.
  • Claim hygiene: avoid saying EN 303 645 proves GDPR compliance; instead, state which ETSI technical provisions are addressed and leave legal conclusions to the applicable privacy-law review.
Primary sources

References and citations

etsi.org
Referenced sections
  • Defines simple device erasure, associated-service removal, user instructions, and deletion confirmation expectations.
"delete user data"
etsi.org
Referenced sections
  • Defines the personal-data confidentiality provisions and the requirement to document external sensing capabilities.
"personal data"
etsi.org
Referenced sections
  • Defines consumer information, valid consent, withdrawal, telemetry minimisation, and telemetry information provisions.
"valid way"
etsi.org
Referenced sections
  • Defines mandatory purpose-based data minimization and deletion in 6-6, the aggregation recommendation in 6-7, and the anonymization recommendation in 6-8.
"Data anonymization technologies should be used to protect privacy during data collection, processing and storage."
etsi.org
Referenced sections
  • Maps the three provisions to IXIT 21-PersData fields for purpose, lifecycle, processing activities, aggregation, and anonymization, with conceptual and functional checks.
Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 telemetry: what should consumer IoT teams evidence?
ETSI EN 303 645 telemetry guidance for consumer IoT teams: security anomaly examination, IXIT 24-TelData evidence, personal-data minimization, and consumer telemetry disclosures.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.