COMMENT: The Internet of Things (IoT) is all around us. It''s on our wrists, in our homes and, increasingly, present in a whole range of industries, including ports and shipping, writes HFW’s Felicity Burling.

IoT can give ports enhanced visibility and control over their businesses Photo: jeferrb/Pixabay/CC0

IoT can give ports enhanced visibility and control over their businesses Photo: jeferrb/Pixabay/CC0

It's easy to see why. This network of interconnected devices and applications can give organisations enhanced visibility and control over their businesses, across hugely complicated global supply chains.

IoT is fuelled by that most precious and volatile of modern resources – data. And lots of it.

The catch? Any data that can directly or indirectly identify a living person is 'personal data' and is afforded special protection. Under updated EU rules (the General Data Protection Regulation, or 'GDPR') any organisation that uses personal data has serious obligations to keep this data secure, and to respect the data and privacy rights of the individuals concerned. Fines for getting it wrong could be up to €20m, or 4% of an organisation's annual turnover (not profit).

In addition to monitoring such things as vessel movement, container temperature, traffic volumes or bridge strain, IoT devices can and do process a lot of this personal data. While many players in the ports and shipping industries do not deal with individual customers directly, they do gather and analyse data about their employees, potentially through IoT devices that can help track and measure such things as their location, work productivity and even their health.

If your business uses IoT devices in these or other ways, then there are three fundamental things that you need to keep in mind: lawful grounds of processing, transparency and security.

The GDPR does not always require the consent of individuals (but check relevant ePrivacy rules too, which might require consent). Consent is just one potential lawful ground for processing personal data. Organisations should consider all of the potential lawful grounds available, and then inform the individuals concerned. Is there a legitimate interest to collect the data, for example for health and safety purposes? Or is consent the only way to justify the processing? If using consent, remember that it must be specific, and as easy to withdraw as it is to give. This could create problems if you really need the data and the individual changes his or her mind. Anonymise data where possible to avoid such problems.

On transparency and accountability, individuals like employees must be informed, at the point of collection, how and why their personal data is being used, including information on their rights. IoT providers have been criticised for not explaining this to users.

Vulnerabilities uncovered

One of the biggest concerns about the rise of the use of IoT, big data and automation in the maritime industry is the potential vulnerability to cyber-attacks and data breaches. The breach of one component in a network (an IoT device) could act as a gateway to a larger pool of data.

The EU's Networks and Information Systems (NIS Directive) came into force on May 10, 2018. It focuses on the cyber security of nationally important infrastructure and ‘operators of essential services’ (OES), including players in the marine, road and air transport sectors. Understandable given the risks involved – see for example the cyber-attack on twenty ships in the Black Sea in 2017, whose GNSS tracking equipment was hit by a ‘spoofing’ hack. The next attack could be more sinister.

Maritime companies need to demonstrate that they have implemented ‘appropriate and proportionate’ cyber security measures. Again, the potential penalties for breach of the NIS Directive are vast: £17m or 4% of global turnover.

A cyber breach could result not just in the loss of valuable commercial data, and operational havoc, but also theft or widespread disclosure of personal information. This brings the GDPR, and its eye-watering financial penalties, into play once more. The industry is responding to this double threat with draft guidance, and rightly so.

So, before you connect all of your devices to the internet, remember: with the power of big data comes great responsibility.

Felicity Burling is an associate in HFW’s Regulatory/Data Protection team, based in the company’s London office.