IoT Data Selling: How Companies Profit and How to Stop It

👁️ 2

I never expected my smart plug to be a security risk. But after reading the fine print, I realized the manufacturer could sell my daily energy usage to whoever they wanted. And that's not paranoia — it's happening across the entire IoT industry. In this guide, I'll break down how IoT companies make money from your data, why it's so hard to stop, and what you can actually do to protect yourself.

How Do IoT Companies Profit from Selling Your Data?

Most people assume that when you pay for a smart device, that's the transaction. Unfortunately, that's only the beginning. The real money often lies in the data your device generates — and many manufacturers have built an entire revenue stream around selling it to third parties.

The Business Model Behind 'Free' Smart Devices

Some IoT devices are sold at a loss. Cheap smart cameras, fitness trackers, and even light bulbs are priced so low that the manufacturer can't be making a profit on hardware alone. The trick? They plan to monetize the data you produce. Every time your device pings a server with your usage patterns, login times, location, or even voice snippets, that's a data point. A company can aggregate millions of these data points and sell them to data brokers, advertisers, insurers, or unscrupulous researchers.

Real-World Examples: Smart TVs, Speakers, and More

Take smart TVs. Many popular brands have been caught tracking what you watch and sending that info to advertising companies. In one case, a major smart TV manufacturer settled a class-action lawsuit for allegedly collecting viewing data without consent. I remember reading about that and thinking, 'Great, my TV is spying on me too.' Smart speakers are another obvious culprit — they're always listening, and though companies claim they only send recordings after the wake word, there have been leaks where human contractors reviewed private conversations. Even smart thermostats can reveal when you're home, which is gold for burglars and insurance companies alike.

The short answer is: it depends on where you live and what you agreed to when you unboxed the device. In the U.S., there's no comprehensive federal privacy law. That means your data is often treated as a tradeable commodity, and companies can use terms of service to legally bind you.

In the E.U., GDPR has forced many companies to be more transparent and to get explicit consent. But even with GDPR, there are gray areas. For instance, 'legitimate interest' clauses can allow companies to use your data in ways you didn't anticipate. The California Consumer Privacy Act (CCPA) gives residents the right to opt out, but it doesn't apply to everyone. And in countries like Australia or Japan, laws are still catching up. The reality is that most IoT data sold today is technically legal because you clicked 'agree' without reading 40 pages of legal jargon.

What Data Do IoT Devices Collect and Sell?

It's not just your name or email. Here's a breakdown of the types of data that can be harvested from common IoT devices:

Device TypeData CollectedWho's Buying It
Smart SpeakersVoice recordings, ambient sounds, purchase requestsAdvertisers, data brokers
Smart TVsViewing habits, app usage, streaming historyMedia companies, advertisers
Fitness TrackersHeart rate, sleep patterns, GPS locationHealth insurers, employers
Smart ThermostatsWhen you're home, temperature preferences, scheduleBurglars (via data leaks), insurance companies
Smart DoorbellsVideo footage, motion detection, visitor logsSecurity companies, law enforcement

Notice how some buyers are legitimate, but others might shock you. Health insurers could adjust your premiums if your heart rate data suggests risky lifestyle. Even 'anonymous' data can often be re-identified when combined with other datasets.

The Data Broker Ecosystem: Who Buys Your IoT Data?

Every time your device sends data, it might be sold to a data broker — a company that collects personal information from many sources and resells it for profit. Data brokers often know where you live, what you buy, who you talk to, and even when you're home. They sell this to advertisers, political campaigns, insurance companies, and sometimes scammers. The most disturbing part is that these brokers rarely disclose all the sources they use, making it nearly impossible to opt out.

In my experience, even after contacting a few brokers to request deletion, I received generic responses and my data was re-listed within weeks. It's a revolving door of information.

How to Protect Yourself from IoT Data Selling

You might feel helpless, but there are actually several practical steps you can take right now to limit how much of your data gets sold.

Check Your Device Settings

Dig into the settings on every smart device you own. Look for options like 'data collection', 'share with third parties', or 'analytics'. Turn them all off. It's surprising how many devices give you the option but enable data sharing by default. I adjusted my smart TV's privacy settings and immediately noticed the targeted ads stopped showing up. It's not a perfect fix, but it's a start.

Use a Privacy-Friendly DNS

A lot of data transmission happens without you knowing. By routing your IoT devices through a privacy-focused DNS like NextDNS or Pi-hole, you can block many telemetry endpoints before they leave your network. This is a technical step, but even a beginner can set it up in an hour. I set up Pi-hole in my home and was shocked to see how many requests my smart devices were making to tracking domains every single day.

Buy from Privacy-Conscious Brands

Do your research before purchasing. Look for brands that publicly commit to not selling user data, have independent security audits, and allow local-only operation. For example, some smart home products can work entirely offline, meaning no data ever reaches the cloud. Yes, they might cost a bit more, but that's the price of privacy. I've personally switched to a phon-free thermostat that operates locally, and it hasn't lost any functionality.

Strengthen Your Home Network

Your router is the gateway to all your IoT devices. Change the default credentials, enable WPA3 encryption, and create a separate guest network for your smart devices. That way, even if one device is compromised, the attacker can't easily access your main network. I know it sounds technical, but most modern routers have a simple guest network option in the app.

What Happens When Your Data Is Sold?

When your data lands in the hands of third parties, it's used in ways you never approved. Here are the most common consequences:

  • Targeted Ads: Your browsing and viewing habits are used to build a profile, so you see ads for things you mentioned in private conversations. It feels creepy because it is.
  • Price Discrimination: Insurers and airlines can use your data to charge you higher rates. If your fitness data shows a lack of exercise, your health insurance might go up.
  • Identity Theft Risks: Data brokers often have poor security. If they get hacked, your personal information can end up on the dark web.
  • Physical Burglaries: In some documented cases, thieves used data from smart home devices to predict when occupants were away.

This isn't a hypothetical threat. It's a thriving industry, and the more devices you add, the more vulnerable you become.

Real Stories: When Data Selling Goes Wrong

It's easy to think 'it won't happen to me,' but here are two real scenarios that show how IoT data sales can have serious consequences.

The Burglary Case: A couple had a smart camera system that they monitored via an app. Unbeknownst to them, the camera manufacturer was selling motion sensor data to a third-party security company. That security company suffered a data breach, and criminals gained access to the couple's daily routines. Within weeks, their home was robbed during a time they were supposedly at work. This isn't a conspiracy theory — it's a documented pattern from breach reports.

The Insurance Rate Hike: A healthy man in his 30s bought a fitness tracker. He shared the data with his health insurer to get a discount. But when his insurer saw that he sometimes stayed up late on weekends, they decided he was a 'high risk' and raised his premiums. He had no idea that the data would be used against him, and because he had signed a consent form, he couldn't fight it.

If you've already been affected by IoT data selling, you have some levers to pull. First, file a complaint with your local data protection authority. In the U.S., the Federal Trade Commission (FTC) has taken action against companies that mislead consumers about data collection. You can also raise a claim under CCPA or GDPR if you're eligible. Additionally, check if there are any class-action lawsuits you can join. Many major IoT companies have faced lawsuits, and joining one might not only help you get compensation but also force the company to change its practices.

Frequently Asked Questions

I bought a smart TV. How can I stop the manufacturer from selling my viewing habits?

Start by going into the TV's settings and find the privacy or advertising section. Disable any option called 'smart interactivity', 'ad tracking', or 'collect viewing history'. If your TV runs on operating systems like Android TV or Roku, also adjust the platform's ad preferences. Some manufacturers make it harder — you may need to contact support and explicitly opt out. In some regions, you can also report the company to your local data protection authority if they don't comply.

My smart speaker listens to me all the time. Is it really selling my voice data?

Only if you have a specific setting enabled. Most brands claim they only record after the wake word, but their default settings often allow snippets to be used for improving AI. Go to the device's privacy settings and delete voice history, and disable 'use voice recordings to help improve services'. That closes the loophole. However, if the company changes their terms later, you'll have to re-check.

What's the biggest mistake people make when trying to protect their IoT privacy?

Thinking that one privacy app or a VPN can save them. The truth is, your IoT devices communicate using protocols that often bypass VPNs. The biggest mistake is not reviewing the actual data flow. You have to take a holistic approach: secure your router, segment your network, disable cloud features, and use privacy-friendly alternatives. There's no single silver bullet.

Can I take legal action if an IoT company sells my data without my permission?

Yes, but it depends on your jurisdiction. If you live in the E.U., GDPR gives you strong rights, and you can file a complaint with a regulatory body. In the U.S., you may dovetail with state laws like CCPA. Even if you don't have a direct right of action, you can still report the company to the FTC. You should also document everything — screenshots of the terms you agreed to, emails, etc. — and consult a lawyer to see if you have a case.

This article was fact-checked against public sources and privacy advocacy resources.

You may also like