Media & press resource · Swiss non-profit stiftung
Privacy Position Paper: Factsheet
A press-ready summary of Privacy in the Smart Home, the foundation's position paper on data autonomy and legal protection for the connected home.
Headline positions
- Privacy is a human right
- Data autonomy must be mandatory
- Existing privacy laws fail the smart home
- Consumer privacy labeling is required
Overview: Drawing the line on surveillance capitalism
Published in October 2025 by the foundation's Policy & Principles Working Group, Privacy in the Smart Home is a blueprint for the ethical smart home. The paper addresses how connected devices – from cameras and presence sensors to appliances – collect vast quantities of personal data that can be combined with AI to draw intimate behavioral insights. The foundation calls on legislators and the wider tech industry to mandate data autonomy and protect consumers from cloud-based surveillance and data harvesting.
Technical demands
The foundation outlines specific operational standards required to safeguard smart home privacy:
- Local-first architecture: Smart home devices must store, process, and execute data locally without requiring internet connectivity or external systems wherever possible.
- Data ownership: Data produced inside a home legally belongs to the people who live there or purchased the device, not the hardware manufacturer or platform provider.
- Granular transparency: Clear disclosure must be provided whenever data or control signals leave a home's local area network, specifying what is shared, with whom, and why.
- Simple data deletion: Users must be provided with non-technical methods to permanently delete their personal data in a timely manner across both local hardware and third-party systems.
- End-to-end security: Mandated strong end-to-end encryption for data transmitted beyond the local area network, and encryption-by-default for stored data.
Policy & regulatory recommendations
The Open Home Foundation calls on regulators and industry bodies to establish strict legal protections:
- Local by default: Require third-party data sharing to be turned off out of the box, requiring explicit, opt-in consent accompanied by clear explanations.
- Consumer privacy labeling: Institute a standardized labeling system (similar to point-of-purchase privacy indicators) so consumers understand a device's privacy implications before buying.
- Regulation of side-channel access: Scrutinize loopholes in unencrypted local network protocols (such as UPnP and mDNS) that allow third-party devices on a network to discover sensors, media streams, or metadata without explicit user permission.
- Chain-of-transmission deletion: Enforce financial penalties for third-party vendors that fail to delete stored data or fail to forward deletion requests down the entire distribution chain.
Scope & ongoing research
The position paper defines clear boundaries for current policy declarations while laying the groundwork for future ethical studies:
- External boundary focus: This position paper specifically tackles privacy between the smart home and external entities (cloud providers, Big Tech, advertisers).
- Inter-household privacy: The foundation is actively conducting primary research into the complex challenges of privacy between co-habitants inside the home (e.g., domestic safety and non-consensual tracking) to inform future policy work.
Privacy in the Smart Home is the first publication in an ongoing policy series produced by the Policy & Principles Working Group. The foundation is actively preparing its next two position papers dedicated to its remaining core principles: Choice and Sustainability.