With General Data Protection Regulation (GDPR) coming into full enforceable effect in May 2018, two years after it was approved and adopted by the EU, regulators will have the power to fine companies up to €10m, or 2% of annual global revenue (whichever is greater), for failure to handle customers’ personal data in adherence with the regulations. This article explores why this legislation’s scope overshadows almost every aspect of IoT security. Whether it is health tracking,