Artifact GuideGLOBALETSI EN 303 645

ETSI EN 303 645 Telemetry evidence for consumer IoT products

A focused answer on how ETSI EN 303 645 treats collected telemetry data, security anomaly examination, and user-facing telemetry information.

Based on ETSI EN 303 645 V3.1.3 and ETSI TS 103 701 V2.1.1. Telemetry collection is optional; the provisions apply when the product collects it.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
7

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

ETSI EN 303 645 V3.1.3 does not require a product to collect . If the IoT product does collect it, provision 5.10-1 recommends examining it for . If telemetry contains , separate provisions address necessity and the information given to consumers.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What does ETSI EN 303 645 say about telemetry?

EN 303 645 defines as data from a device that can help the manufacturer identify issues or information related to device usage. Provision 5.10-1 is a recommendation that applies when telemetry is collected from the IoT product, including usage and measurement data. It does not require telemetry collection.

The standard gives practical examples of the kind of security signal it expects teams to look for: deviations from normal device behaviour, such as an abnormal increase in failed login attempts, or across multiple devices showing that updates are failing because software update authenticity checks are invalid.

  • Start by listing the actually collected by the device and associated services, not by writing a generic monitoring statement.
  • For each category, document whether it is used for security anomaly examination or only for another purpose such as performance or stability analysis.
  • Keep the claim conditional: EN 303 645 does not require every product to collect , but collected telemetry should be examined for .
Citations
Question 2

What evidence should support a telemetry claim?

TS 103 701 turns the provision into IXIT 24-TelData evidence. The completed IXIT lists telemetry collected by the device and associated services, with an identifier, description, purpose, security examination, and references to any processed in the telemetry data.

For provision 5.10-1, the Test Laboratory checks whether IXIT 24-TelData describes at least one examination for and whether the description is suitable for that examination. A TelData inventory is not enough by itself; the assessment needs the relationship between the signal and the stated anomaly check.

  • Use a TelData entry for each category actually collected, such as crash logs, update-failure signals, failed-login indicators, or usage measurements.
  • For used in security monitoring, describe how anomalies are examined and whether the examination is performed by the device or by an associated service.
  • If a category is not used for security examination, say so plainly instead of implying that every telemetry feed is security telemetry.
  • For a reviewable evidence record, connect each stated examination to its signal, expected baseline or rule, responsible team or service, review or execution cadence, retained result, and handoff into vulnerability or incident handling when the check finds a potential issue.
  • Reassess the TelData inventory and notices when a sensor, event field, identifier, collection purpose, recipient, associated service, anomaly rule, retention practice, or product software version changes.
Citations
Question 3

How should telemetry personal data and consumer information be handled?

EN 303 645 clause 6 is the relevant place to narrow privacy-facing statements. It says the document addresses personal-data protection from a strictly technical perspective, so teams should avoid broad legal-compliance claims unless they have separate legal source support.

For collected , provision 6-4 recommends limiting personal-data processing to what is necessary for the intended functionality identified under provision 6-5. Provision 6-5 requires information for consumers on what telemetry is collected, how it is used, by whom, and for what purposes. These are distinct from the security-anomaly recommendation in 5.10-1.

  • Map any in to IXIT 21-PersData and keep only the data needed for the stated telemetry purpose.
  • Make the consumer-facing notice accessible and consistent with the IXIT 2-UserInfo documentation of telemetry data.
  • When publishing product claims, say that the ETSI evidence supports technical data-protection provisions; do not claim GDPR compliance from EN 303 645 alone.
Citations
Primary sources

References and citations

etsi.org
Referenced sections
  • Primary ETSI source for telemetry definition, provision 5.10-1, clause 6 telemetry data-protection provisions, and examples of security anomalies.
"If telemetry data is collected from consumer IoT products"
etsi.org
Referenced sections
  • Primary ETSI source for provision 5.10-1 on examining collected telemetry for security anomalies.
"If telemetry data is collected from consumer IoT products"
etsi.org
Referenced sections
  • Assessment source for the telemetry pro forma fields and the provision 5.10-1 mapping to telemetry description and security-examination evidence.
"The completed IXIT lists all telemetry data collected by the DUT and its associated services."
etsi.org
Referenced sections
  • Assessment source for checking that at least one security examination is provided in IXIT 24-TelData and that the telemetry description fits the examination.
"The purpose of this test case is the conceptual assessment of the security anomaly examination."
etsi.org
Referenced sections
  • Assessment source for checking telemetry personal-data necessity and consumer information about telemetry processing.
"the information about processing telemetry data can be obtained as described"
Related guides

Explore more topics

ETSI EN 303 645 Applicability and Scope
Decide whether a connected product is in scope of ETSI EN 303 645, define the consumer IoT evidence boundary, and document N/A justifications for assessment.
ETSI EN 303 645 compliance: ICS, IXIT, evidence
Plan ETSI EN 303 645 compliance evidence for consumer IoT products with scope, ICS, IXIT, TS 103 701 assessment steps, verdict risks, and cited controls.
ETSI EN 303 645 consumer IoT products: what is in scope?
Decide whether a device and its associated services are in scope of ETSI EN 303 645 V3.1.3 and document the DUT, ICS, IXIT, and assessment boundary.
ETSI EN 303 645 Current Version Tracker
Track ETSI EN 303 645 version evidence, ETSI deliverable status checks, TS 103 701 assessment alignment, and change triggers for consumer IoT security work.
ETSI EN 303 645 CVD Workflow for IoT Vulnerability Reports
Cited workflow for ETSI EN 303 645 vulnerability disclosure: public policy contents, reporting contact, acknowledgement and status timelines, timely action, and TS 103 701 evidence.
ETSI EN 303 645 Data Protection Provisions
Guide to ETSI EN 303 645 data protection provisions for consumer IoT, including security, consent, telemetry, deletion, minimization, aggregation, and anonymization.
ETSI EN 303 645 default passwords: what must consumer IoT teams do?
ETSI EN 303 645 default password guidance for consumer IoT: unique or user-defined passwords, pre-installed password generation, change mechanisms, brute-force controls, and TS 103 701 evidence.
ETSI EN 303 645 FAQ: Consumer IoT Security Questions
Practical answers to common ETSI EN 303 645 questions on consumer IoT scope, associated services, passwords, updates, vulnerability disclosure, telemetry, deletion, and assessment evidence.
ETSI EN 303 645 ICS and IXIT Evidence Template
Build a cited ICS and IXIT evidence template for ETSI EN 303 645 consumer IoT assessments, with clear separation between EN provisions and TS 103 701 test information.
ETSI EN 303 645 implementation checklist
This ETSI EN 303 645 implementation checklist helps scope a consumer IoT product, record Annex B support statuses, map IXIT evidence, and avoid weak conformance claims.
ETSI EN 303 645 Implementation Evidence Guide
Build ETSI EN 303 645 implementation evidence from Annex B support/detail records, TS 103 701 ICS and IXIT inputs, test verdicts, and scoped external evidence.
ETSI EN 303 645 IoT Applicability Workflow
Decide whether ETSI EN 303 645 applies to a consumer IoT product, what associated services belong in scope, and how to record justified non-applicability.
ETSI EN 303 645 personal data deletion FAQ for consumer IoT
What ETSI EN 303 645 says about deleting user data and personal data from consumer IoT devices, associated services, apps, and evidence records.
ETSI EN 303 645 requirements: consumer IoT provision map
Map ETSI EN 303 645 consumer IoT requirements to product scope, Annex B ICS entries, TS 103 701 evidence, and implementation owners.
ETSI EN 303 645 Secure Update Evidence Workflow
Build secure-update evidence for ETSI EN 303 645 using provision 5.3, Annex B support/detail records, and TS 103 701 ICS, IXIT, and test-plan inputs.
ETSI EN 303 645 Secure Update Workflow
Map ETSI EN 303 645 secure-update provisions into a practical workflow for consumer IoT update mechanisms, support-period disclosures, and TS 103 701 evidence.
ETSI EN 303 645 Secure Updates and Vulnerability Disclosure
Source-backed guide to ETSI EN 303 645 clauses 5.2 and 5.3 for consumer IoT vulnerability disclosure, security updates, support periods, and assessment evidence.
ETSI EN 303 645 support period: what must consumer IoT teams publish?
ETSI EN 303 645 support-period guidance for consumer IoT: defined security-update support periods, user-accessible publication, non-updateable-device replacement support, model designation, and TS 103 701 evidence.
ETSI EN 303 645 test evidence: what should consumer IoT teams keep?
ETSI EN 303 645 test evidence guidance for consumer IoT teams: ICS support claims, IXIT detail, TS 103 701 test plans, verdicts, and external evidence checks.
ETSI EN 303 645 vs EU CRA for Consumer IoT
Compare ETSI EN 303 645 consumer IoT evidence with the EU Cyber Resilience Act's scope, manufacturer duties, application dates, and conformity requirements.
ETSI EN 303 645 vs RED Cybersecurity Delegated Act
Compare ETSI EN 303 645 consumer IoT evidence with the RED cybersecurity requirements, EN 18031 standards, application date, and conformity routes.
ETSI EN 303 645 vs UK PSTI: Evidence Crosswalk
Compare ETSI EN 303 645 evidence with UK PSTI scope, three mandatory security requirements, statements of compliance, duties, and enforcement.
ETSI EN 303 645 vulnerability disclosure requirements for consumer IoT
What ETSI EN 303 645 requires for consumer IoT vulnerability disclosure policies, report handling, status updates, timely action, and TS 103 701 evidence.
ETSI TS 103 701 Test Evidence Workflow for EN 303 645
Build an ETSI TS 103 701 test evidence workflow for EN 303 645 consumer IoT assessments: DUT identification, ICS, IXIT, test plans, verdicts, and external evidence.
How should teams handle constrained devices under ETSI EN 303 645 for consumer IoT products?
How ETSI EN 303 645 V3.1.3 treats use-case resource constraints, non-updateable devices, N/A claims, authentication controls, and assessment evidence.