What data does a smart doorbell gather, and why? Are my unsuspecting friends and family being recorded by my smart speaker when they visit? How is the data my thermostat gathers used? Last year we published an article about smart home devices, and spoke about this topic with Alexa Becker. She worked as a research fellow at the Hochschule Anhalt in Germany and conducts research on privacy in smart home devices. Alexa organized the workshop ‘Designing Smart Home Products with Privacy in Mind’, to raise awareness for the way these products gather and use data.
The participants in these workshops are experts, who tried to redesign products to make them more privacy-friendly. We also participated in this workshop with our research group. Last time we spoke with Alexa about privacy risks in smart home products. This time we zoom in on the results of the workshop to see how we can minimize those risks by design.
Sensor data may seem so simple; a humidity meter collects data to determine the humidity in a room, or a motion sensor lets you know if someone or something moved past a certain point. But it’s not that simple. Sensor data in smart home products can lead to conflicts between stakeholders, such as users, partners, landlords, bystanders.
Workshop
The workshop that Alexa organized is a way to see how designers and tech practitioners would minimize these privacy conflicts and tensions in smart home devices. Thirty-eight practitioners participated. They all got worksheets with data graphs, for example data about the humidity levels in someone’s home, noise levels during the night or the temperature in a child’s bedroom. The participants then thought about what the collected data could mean for the stakeholder: How can you infer everyday activities and routines from this data? And where are possible conflicts?
Based on the data graphs and some initial stakeholder ideas, the participants developed scenarios that showed possible conflicts. They then designed a device package to illustrate solution strategies that minimize those conflicts. In total there were 14 device packages designed. We will highlight three of them in this article. All 14 designs can be found in Alexa’s publication.
Happy Puppy
One of the examples in the workshop is the scenario of the Dog Walk Tracker Happy Puppy. The actors in this scenario are a couple, their dog and their dog-sitter. Possible tension is created when the dog sitter finds their privacy violated because of the tracker. The Happy Puppy Tracker measures if the dog is walked or not walked by the dog sitter.

Sensemaster
The scenario for the Sensemaster is about two tenants and their landlord. The landlord wants to increase heating in the apartment, because there is mold. But there is tension: one of the tenants interprets the data differently, and the other tenant doesn’t want to pay more for increasing the heat. The participants who worked on this scenario paid attention to transparency and user-control. For example, the user has a choice to control the climate with or without the help of AI.

Sesame Sensor
The Sesame Sensor is a sensor in the bathroom that measures temperature, humidity and air quality. The stakeholder in this scenario is a couple. By reading the sensor data, they can see whether they are ventilating the bathroom properly after a long shower. Tension can arise if data shows that partner 1 consistently does not air the bathroom the right way.

Strategies
The strategies that the workshop-participants used to minimize privacy risk, can be split into four categories:
- Reducing data granularity on the visual layer
- Minimizing data storage
- Offering more sensor data explainability
- Increasing trust through strict data regulations
Reducing data granularity on the visual layer could be done for instance by separating viewing rights, restricting ‘raw’ data access or by personalizing devices. Minimizing data storage speaks for itself and includes reducing data storage and restricting data storage locations. Offering more sensor data explainability means not only explaining and evaluating data, but also transforming data to calls to action. And last but not least, strict data regulations are needed. Bystander consent should be legally required. You can also increase trust by emphasizing company location (Made in Europe or GDPR for example). Legal purposes should be transparent.
All these strategies and things to keep in mind when working/dealing with data illustrate how complex this subject is. Therefore it is important that smart home design shifts from a primary focus on the user, to one that includes all stakeholders. In that way simple sensors don’t facilitate complex harms. The results from Alexa’s workshop show that tech workers already possess the creative strategies to build more trustworthy systems. The next step is to empower these practitioners, so they become the industry standard.
