GDPR Compliance for Manufacturers: A Practical Guide
In June 2026, the UK's Information Commissioner's Office announced a formal probe into how smart TV manufacturers use consumer data and published final guidance on IoT products, warning that most IoT data processing "is likely to result in a high risk." The same month, Italy's antitrust authority opened proceedings against Vorwerk over the shutdown of cloud services for Neato robot vacuums — a landmark case examining whether manufacturers can devalue connected products through service termination.
Product manufacturers consistently tell us GDPR is a "tech company problem." Then we show them the connected product they're shipping — the one collecting sensor data and communicating with a smartphone app — and it clicks.
If your company places products on the EU market, you are almost certainly processing personal data in ways that trigger the General Data Protection Regulation (GDPR). Connected devices, supplier records, employee data — all of it counts. On the Sustalium platform, we handle GDPR declarations for IoT manufacturers, industrial equipment makers, and consumer goods companies. Here is what actually applies to product businesses.