Whether a mioty deployment processes personal data depends on the application, not the radio: consumption readings tied to a household are personal data, machine condition data in a factory generally is not. For the case where it does, the security guideline has an actual documented answer rather than just general IoT advice: for multi-tenant deployments it proposes a distinct Trust Center role that is the only place in the network holding personal information about customers and their devices, explicitly stated as being done to protect customer privacy and ensure compliance with GDPR. The Service Center only ever sends the Trust Center message counts per device, not personal data, and the Trust Center matches device IDs to customers internally for billing. Application-level end-to-end encryption complements this by keeping the application key, and the data it protects, on the customer’s own premises. This pattern does not make a deployment compliant by itself, the usual controls around lawful basis, retention and access still apply, but it is the alliance’s own structural recommendation rather than something to reconstruct from general principles.

