IoT data ownership and access: Policies for shared spaces

In multi-tenant buildings and industrial zones, clearly defining IoT data ownership and access rules is critical to prevent operational disruptions and ensure regulatory compliance.

As the adoption of the Internet of Things (IoT) grows in commercial and industrial shared spaces, the question of who owns the generated data and how it should be used and accessed becomes paramount for operational efficiency, regulatory compliance, and trust among stakeholders. A lack of clear policies can lead to fragmented data, disputes, or security breaches, threatening operational stability.

Defining data ownership in complex IoT ecosystems

In the context of IoT systems within shared spaces, such as office complexes or industrial facilities, defining data ownership is a complex task. Raw information is not always considered property in many legal systems, yet data holds significant commercial value. Intellectual property rights may protect certain forms or formats of data.

The European Data Act (EU Data Act), which entered into force in January 2024 and becomes mandatory in September 2025, aims to democratize data access by obliging data holders to make data available in user-friendly formats while protecting trade secrets and intellectual property. This law focuses on data generated by sensors, operational efficiency metrics, and usage data, often originating from IoT and industrial systems. It grants users the right to access and share data they generate.

In multi-party environments, such as shared equipment in industrial settings or devices used by multiple tenants in residential buildings, the question arises of how access and sharing rules apply when several users may have rights or interests in the same data. Addressing these issues requires a clear delineation of roles and responsibilities among building owners, tenants, service providers, and integrators.

Classifying IoT data and access levels

To effectively manage IoT data in shared spaces, a data classification system is essential to define appropriate access levels for various stakeholders. Data can be divided into several key categories:

  • Personal data: Information relating to identified individuals, subject to privacy laws such as GDPR and national data protection legislation.
  • Operational and machine-generated data: Data produced as a result of business operations, equipment sensors, or automated systems. This category is rapidly growing with the proliferation of IoT devices.
  • Shared and confidential data: Organizations must distinguish between shared data (accessible to both parties for operational purposes) and confidential data (such as intellectual property or personal data), which require different levels of consent, security obligations, and usage restrictions.
  • Anonymized or pseudonymized data: Data that has been processed to remove or mask personal identifiers. This can reduce certain compliance obligations, but re-identification risks must be considered.

Role-Based Access Control (RBAC) mechanisms are a structured method of assigning privileges, crucial for IoT networks to mitigate unauthorized access risks. RBAC involves assigning roles to users and specific permissions (read, write, execute, configure) to those roles. For example, a system administrator might have full access, a tenant administrator full control over their environment, and a client user only read access to assigned resources.

Legal and regulatory aspects of data sharing

In Ukraine, the primary legislative act regulating personal data protection is Law of Ukraine No. 2297-VI “On Personal Data Protection” dated June 1, 2010 (the PDD Law). This law establishes general requirements and obligations for the collection, processing, and use of personal data. Significant amendments were introduced in 2012 and 2013. Additionally, on October 25, 2022, a new draft Law No. 8153 “On Personal Data Protection” was submitted to the Verkhovna Rada of Ukraine, aiming to harmonize Ukrainian legislation with GDPR and Convention 108+ standards.

The PDD Law requires personal data owners and controllers to ensure its protection against accidental loss, destruction, and unlawful processing. Personal data processing must be open and transparent, and processing means must align with its purpose. The consent of the personal data subject is a key condition for processing, especially for sensitive information.

GDPR (EU General Data Protection Regulation) also applies to IoT, particularly when processing any data that could be considered personal or related to identified individuals. GDPR compliance requires strong encryption measures and “privacy by design.” When developing IoT devices for GDPR compliance, it is necessary to consider legal bases for processing personal data, conduct Data Protection Impact Assessments (DPIA) for high-risk operations, and ensure data subjects' right to erasure.

In shared spaces, IoT devices often lack the ability to inform and obtain consent from every individual whose information is collected. This creates challenges for consent and transparency compliance.

Developing data access and management policies for stakeholders

Creating transparent and effective data management policies is critical for multi-user environments. These policies must consider the interests of all participants – building owners, tenants, service providers, and integrators. Key aspects include:

  • Data Processing Agreements (DPA) and Service Level Agreements (SLA): These documents must clearly define who is the data controller and processor, what data is collected, how it is used, stored, and transferred, and the parties' responsibilities for its protection.
  • Data minimization principle: Collecting only the data necessary for a specific purpose and storing it temporarily can significantly reduce risks of non-compliance and data breaches.
  • Transparency: Users must be informed about what data is collected, how it is used, and with whom it is shared.
  • Dispute resolution mechanisms: Agreements should provide clear procedures for resolving disagreements regarding data ownership or use.

Effective cybersecurity management in commercial real estate requires assessing current safeguards, continuous risk assessment, and verifying security effectiveness through monitoring, third-party validation, and incident response planning.

Technological solutions for implementing access policies

Technologies play a key role in ensuring the enforcement of defined data ownership and access policies. These include:

  • Granular access control: IoT platforms must support detailed access control mechanisms, such as RBAC, allowing specific permissions to be assigned based on user roles and their needs. This helps prevent unauthorized access to sensitive IoT data during transmission and storage.
  • Data anonymization and aggregation: Using anonymization and pseudonymization methods helps protect personal data while allowing aggregated information to be used for analysis and operational optimization, such as improving energy efficiency.
  • Access monitoring and auditing: Systems should log all attempts to access data and devices, providing auditing capabilities and detection of suspicious activity.
  • Network segmentation: Placing IoT devices on separate networks (e.g., guest Wi-Fi or a separate VLAN) from core corporate networks helps limit potential damage in case of an IoT device compromise.
  • Encryption: Using encryption for data in transit and at rest is a fundamental security measure.

Integrating IoT devices with access control systems, including smart locks, sensors, and cameras, creates a network of connected devices that collaborate to enhance security, automation, and energy efficiency.

Checklist for developing IoT data management policies in shared spaces

For successful deployment of IoT systems in multi-tenant buildings or shared industrial zones, infrastructure leaders and technical leads are recommended to use the following framework:

  • Identify all stakeholders and their roles (owners, tenants, service providers, integrators).
  • Classify data types (personal, operational, anonymous, aggregated).
  • Define the owner for each data type.
  • Develop an access matrix for each stakeholder (read, write, modify, delete).
  • Assess compliance with Ukrainian personal data protection legislation and GDPR.
  • Develop Data Processing Agreements (DPA) and Service Level Agreements (SLA).
  • Define mechanisms for resolving data disputes.
  • Select technological solutions for implementing and monitoring access policies (e.g., RBAC).
  • Plan for regular review and update of policies.

The AZIOT platform allows flexible configuration of access rights to data from IoT devices, ensuring centralized management and compliance with defined ownership and information usage policies in multi-user environments. By supporting protocols such as MQTT, Modbus, BACnet, KNX, Zigbee, Z-Wave, LoRaWAN, Matter, SCADA, and BMS, as well as edge processing, Unity Base, rules/scenarios, dashboards, auditing, and access control functionalities, AZIOT provides tools for implementing comprehensive data management strategies at the physical and device levels.

Developing clear IoT data ownership and access policies is not merely a legal formality but a strategic necessity for ensuring operational stability, trust, and innovation in shared physical environments. Investing in robust data governance frameworks and technological solutions will maximize the benefits of IoT while minimizing privacy and security risks.

Learn more about Intecracy and inbase.com.ua solutions for data management and automation.

Source list

  1. osborneclarke.comManaging legal risk from IoT systems in business premises | Osborne Clarke
  2. tributech.ioWhat the EU Data Act Means for IoT Data Compliance
  3. kempitlaw.comIoT, Data Access and Multi-User Scenarios Under the EU Data Act - Kemp IT Law
  4. michaelbest.com
  5. legalitgroup.comGDPR and Internet of Things (IoT)
  6. ijcnis.org
  7. ijisae.orgRole-Based Access Control for Enhanced Device Security and Privacy: An Applied Framework Building on Granular IoT Access Models | International Journal of Intelligent Systems and Applications in Engineering
  8. thingsboard.ioRoles | Docs | ThingsBoard