The Internet of Things – The Latest Frontier
33 min
Share

The Internet of Things – The Latest Frontier

An interview with John Heitmann and Jameson Dempsey

CLE Credit
AZ ›· General
0.5 cr
CA ›· General
0.5 cr
CT ›· General
0.5 cr
NY ›· Areas of Professional Practice
0.5 cr

The thermostat talks to the phone, the phone talks to the car, the car talks to the manufacturer, and none of them needs a human to type anything. Ten billion devices were already connected when this conversation was recorded, with hundreds of billions forecast, from pacemakers to tractors. What happens to privacy and security when the internet stops being something you use and becomes something you live inside?

In this TalksOnLaw interview, the first of two parts, Joel Cohen sits down with John Heitmann and Jameson Dempsey, then communications and privacy lawyers at Kelley Drye & Warren, to map the legal terrain of the Internet of Things as it was being settled. The conversation continues in Part 2.

From the Internet of People to the Internet of Everything

Dempsey defines the shift: for twenty years, data entered the internet from people at keyboards; the Internet of Things collects it passively, through sensors, without anyone deciding to share. Heitmann widens the lens beyond the smart home to factories, supply chains, smart cities, agriculture, and health — insulin pumps and pacemakers that are lifesaving when they work and life-threatening when they fail. Both frame the conversation not as alarm but as foresight: what risks can be seen coming, and what law already exists to meet them.

No Omnibus Law, Two Cops on the Beat

The United States, Dempsey explains, has no general privacy statute — only sector-specific laws for children, health, and financial data, and no constitutional right the courts have been willing to name. Into the gap step the FTC, under Section 5's ban on unfair and deceptive practices, and the FCC, under Section 201's ban on unjust and unreasonable ones. Deception means breaking a promise in your privacy policy; unfairness means doing nothing at all to secure the data. Heitmann identifies the categories regulators treat as sensitive — health, financial, geolocation, children — and Cohen tests the edges: the light bulb in a child's room, the baby monitor that may or may not store video, the Fitbit whose heart-rate data an employer or insurer would love to see, the car that remembers where it has been.

Privacy Policies Nobody Reads

Cohen presses on the agreement between company and consumer: a privacy policy so dense that a user gives up more than she understands. Both guests concede that only the lawyers who draft them read them, and describe the push toward layered, just-in-time disclosures — the push notification that an app wants your location — which begin as best practice and, once standard, become the baseline against which unfairness is measured. Heitmann's answer to Cohen's hypothetical about a pharmaceutical company that learns of his heart condition from his fitness tracker is that no major company would risk it: the "creepiness" test, brand damage, and a creative class-action bar are, he argues, as effective a deterrent as any statute.

Security by Layers

The segment closes on security — physical, administrative, and technical — and why it matters beyond the data. A hacked doorknob or car is a safety problem, not a privacy problem; the connected-home platforms that aggregate many streams become more attractive targets than any single light bulb; and human training is as much a part of security as encryption. Companies in this space, Heitmann says, have to embrace security the way the mobile industry already has: you are expected to know the threats and respond.

What to Know Now

The framework Heitmann and Dempsey describe has held, and most of what they anticipated arrived. The FTC has policed connected devices under Section 5 exactly as they predicted: against router maker D-Link (2017) for advertising security it did not provide, against Vizio (2017) for tracking viewing on smart televisions without consent, against Amazon's Ring (2023) for employee and hacker access to home cameras, and — in a case that fulfills Cohen's hypothetical about the car that remembers your speeding — against General Motors and OnStar (2025) for collecting and selling drivers' precise location and driving behavior to data brokers and insurers without consent, resulting in a five-year ban on such disclosures. Device-specific security law also emerged: California's SB-327 (effective 2020) requires reasonable security features on connected devices, the federal IoT Cybersecurity Improvement Act of 2020 sets standards for devices the government buys, and the FCC's U.S. Cyber Trust Mark, adopted in 2024, gives consumers a label for products meeting security baselines. The sectoral patchwork remains: Congress has not enacted an omnibus privacy law, but California's Consumer Privacy Act (2018) and its successor, along with roughly twenty state statutes since, now give most Americans rights to know, delete, and opt out of the sale of their data. The disclosure practices the guests describe as best practice — just-in-time notices, app permission prompts — are now required by platform rules and several state laws. And on the "highly sensitive" categories they identify, the Supreme Court in Carpenter v. United States (2018) recognized a Fourth Amendment interest in historical cell-site location data, the first constitutional foothold for the geolocation concerns raised here. Heitmann now practices at Nelson Mullins in Washington; Dempsey left private practice for Stanford's CodeX center and the legal-technology community.

About John Heitmann and Jameson Dempsey

“There are ten billion devices already connected to the Internet of Things and within ten years, people estimate it will be hundreds of billion.”

John Heitmann is a partner at Nelson Mullins Riley & Scarborough in Washington, D.C., where he leads a communications and technology practice ranked by Chambers USA, having moved his team from Kelley Drye & Warren in 2022. He counsels communications providers and technology companies on FCC regulation, privacy and data security, and consumer protection, and is a Certified Information Privacy Professional (CIPP/US). He has been recognized by Chambers USA, The Legal 500, and Best Lawyers in telecommunications and data privacy, and named a "Trailblazer" by the National Law Journal.

Jameson Dempsey is a technology attorney and community builder. After practicing in the communications and privacy groups at Kelley Drye & Warren, he became a residential fellow at CodeX, the Stanford Center for Legal Informatics, and serves as a global director of Legal Hackers, the worldwide movement fostering creative problem-solving at the intersection of law and technology. He has been recognized in The Legal 500 for data protection and privacy and received a Fastcase 50 award. He clerked for Magistrate Judge Roanne L. Mann of the Eastern District of New York and was Editor-in-Chief of the Brooklyn Law Review.