By KASS International
The Internet of Things (IoT) has quietly embedded itself into everyday life. From wearables and smart homes to intelligent factories and connected supply chains, IoT devices now sit at the intersection of hardware, software, data, and connectivity.
Yet, as these technologies scale, a deceptively simple question often surfaces: who actually owns the rights?
In practice, disputes over intellectual property rights (IPRs), data usage, and compliance are not academic issues. They determine who may build on the technology, who controls commercialisation, and ultimately, who profits from innovation.
Protect Your IP
Understanding the Internet of Things
At its core, an IoT system is a network of connected electronic devices that collect, transmit, and process data. While implementations vary, most IoT solutions share three fundamental layers.
- Devices : Physical hardware embedded with sensors and actuators
- Connectivity platforms : Networks, gateways, and cloud infrastructure that transmit and process data
- User interfaces : Mobile applications or web dashboards through which users interact with the system
This layered structure is precisely what makes IoT powerful and legally complex.
What Problems Does IoT Actually Solve?
IoT innovation is rarely about novelty alone. It exists to solve very practical, real-world problems, such as:
- Reducing water or energy wastage through smart meters and leak detection systems
- Preserving food and vaccine integrity via cold-chain monitoring
- Predicting machine failure using Remaining Useful Life (RUL) models
- Optimising fertiliser and irrigation in precision agriculture
- Detecting motion anomalies in home and industrial security systems
Each of these solutions embeds multiple forms of intellectual property, often owned by different parties.
What IPRs Exist in an IoT Product?
IoT products are rarely protected by a single right. Instead, they rely on a portfolio of complementary IPRs, each protecting a different aspect of the technology.
Patents protect technical innovations such as new sensor architectures, data processing methods, communication protocols, and system-level integrations.
Copyright protects original works of authorship, including software source code, firmware, APIs, and graphical user interfaces (GUIs).
In certain jurisdictions, industrial design rights protect the visual appearance of IoT products, including device casing and, increasingly, GUIs.
Trade secrets safeguard confidential know-how that provides a competitive edge, such as proprietary algorithms, system architectures, calibration techniques, and network configurations. These assets derive value precisely because they are never disclosed.
Finally, trademarks protect brand identifiers such as product names, logos, and slogans, allowing IoT products to stand out in crowded markets.
Who Owns the IPRs in an IoT Device?
Ownership is not determined by who physically holds the device. Instead, it is governed by contracts and applicable law.
In practice, IPR ownership flows from employment and invention assignment agreements, software and hardware development contracts, licensing arrangements, and joint development or manufacturing agreements. Where these documents are unclear or silent, ownership disputes are almost inevitable
Data Ownership and Control in IoT Systems : Malaysia’s PDPA: A Shift in Focus
Malaysia’s updated Personal Data Protection Act (PDPA) replaces the term “data user” with “data controller.” While individuals do not own personal data as property, they enjoy enforceable rights to be informed, to give or withdraw consent, to access and correct data, and to request portability.
Data controllers must also appoint a Data Protection Officer (DPO) and notify authorities of certain data breaches once the relevant provisions take effect.
Treat IoT Data with Care
Much of the data generated by IoT devices is personally identifiable, directly or indirectly. As a rule of thumb, treat identifiable IoT data as personal data, obtain clear consent especially for sensitive data such as biometrics, collect only what is necessary, and anonymise or pseudonymise data where possible.
These are not merely compliance measures. They are trust-building mechanisms
Cross-Border Data Transfers: The New Reality
Most IoT ecosystems rely on regional or global cloud infrastructure. Under Malaysia’s Cross-Border Personal Data Transfer (CBPDT) Guidelines, organisations must now either conduct a Transfer Impact Assessment or rely on another lawful transfer mechanism. The former “whitelist” approach no longer applies.
For regional operations, ASEAN Model Contractual Clauses can be used to support lawful transfers. Where data flows into jurisdictions participating in the Global CBPR or PRP systems officially launched in June 2025, certification may assist with partner due diligence, although Malaysia is not yet a participating economy
Contracts Matter: More Than You Think
Strong contractual frameworks are essential. Data Processing Agreements (DPAs) should address security obligations, sub-processing, retention periods, and deletion requirements.
Where data feeds into analytics or artificial intelligence, licensing terms should clearly define permitted uses, purpose limitations, retention periods, and rights of reuse or commercialisation. Ambiguity at this stage often becomes costly later.
Software Licensing: You Never Own the Code
IoT software is licensed, not sold. Most products combine proprietary software, third-party SDKs, and open-source software (OSS).
Each licence, whether GPL, MIT, Apache, or others, comes with different obligations. To avoid accidental licence breaches or unintended open-sourcing of proprietary code, organisations should maintain a Software Bill of Materials (SBOM), run Software Composition Analysis (SCA) tools during development, and conduct compliance checks before release.
Interoperability, Standards, and SEPs
Interoperability is foundational to IoT, and many standards are protected by standard-essential patents (SEPs). These are typically licensed on FRAND terms, fair, reasonable, and non-discriminatory.
In Malaysia, FRAND disputes are rare in reported case law and are often resolved through negotiation or arbitration. To manage risk, clearly define which standards are adopted, assess the relevance and essentiality of patents early, participate in standards bodies where possible, and budget conservatively for SEP licensing. Careful documentation of negotiations can be invaluable if disputes arise
Rising Challenges in IoT IP
IoT innovation moves faster than IP registration, particularly for patents. This timing gap exposes inventors during critical development stages.
Global deployment further complicates enforcement. IP rights remain territorial, but IoT products operate across borders. Add the ease of reverse engineering, where devices can be bought, dismantled, and copied, and the risks become clear.
Mitigating IP Risk
Effective risk mitigation starts early. Use the Paris Convention or PCT system to secure priority before product launch. Ensure development, manufacturing, and distribution contracts include clear IP assignment and governing law clauses.
Implement enforcement readiness through monitoring, customs recordals, takedown playbooks, and domain name protection. Maintain robust compliance practices, including SBOMs, SCA scans, and release checklists covering OSS, privacy, and security.
Conclusion
In IoT, assigning rights early is not a formality. It is a strategic necessity. Clear ownership enables licensing, enforcement, and monetisation without friction. It strengthens negotiating positions and protects long-term value. When early rights assignment is paired with timely filings, disciplined licensing, and proactive enforcement, fragile know-how is transformed into a resilient portfolio of high-value assets. This is what allows IoT innovation not just to function, but to scale, compete, and endure.
Kass International Tweet