The General Data Protection Regulation (GDPR) breaks new ground when it comes to privacy law. After years of hidden breaches, stolen identities and negligent data handling,organizationswill finally be forced to get serious about data privacy. Data loss incidents that are due to non-compliance will face fines that run as high as four percent of global turnover, or 20 million euros, whichever is higher. This will prove a threat to some, but for others, it will finally put the weight behind personal data protection that has been lacking for so long. But there is still no specific regulation for the relentlessly growing, and fatally insecure IoT. In 2017, the European Union Agency for Network and Information Security (ENISA) found that there were no "legal guidelines for IoT device and service trust." Nor any "level zero defined for the security and privacy of conn...