Your Home Is Spying on You: Taking Back Control of Connected Devices Without Leaving the 21st Century

Back to the blog
19 August 202612 min read

Introduction: the bug is no longer in your pocket, it's in your walls

When people talk about digital privacy, the instinctive move is to look at their phone. That makes sense: it's the object we carry everywhere, the one that knows our movements, our messages, our searches. But over the past five years, a quiet shift has taken place. The densest collection point in your life is no longer mobile: it's fixed, spread across your rooms, plugged into the mains, and running 24 hours a day even while you sleep.

Take a mental inventory. A connected TV in the living room. An ISP router and perhaps a Wi-Fi extender. A smart speaker in the kitchen. Controllable light bulbs. A robot vacuum that has memorised the layout of your flat down to the centimetre. A video doorbell. A smart thermostat. A scale, a watch, a fitness band syncing overnight. A games console. Perhaps a smart meter in the utility cupboard. Add it all up: most French households now have more than ten connected devices, and each one keeps up a regular conversation with servers beyond your control.

Hand holding a smartphone with a VPN app switched on displayed on screen

The paradox is a cruel one: you can encrypt your messages, use anonymous SMS services, compartmentalise your online identities, harden your browser — and still let a television transmit a time-stamped list of everything you watch to an advertising network every evening. Digital hygiene too often stops at the screen. This article proposes to bring it into the home itself.


What the objects in your living room actually collect

The television: the household's quiet collection champion

The connected TV is probably the most underestimated device in the home. Most models sold since 2018 include a technology called ACR (Automatic Content Recognition). The principle: the device periodically captures fingerprints of the image on screen — a few frames per second — and compares them against a reference database on the server side.

The result: the manufacturer knows what you're watching, including when the content doesn't come from an app. A DVD, a USB stick, a console plugged in over HDMI, a broadcast channel: it's all identifiable. Cross-referenced with your IP address, that information amounts to an advertising profile of formidable granularity — and it is frequently resold.

France's data protection authority, the Commission nationale de l'informatique et des libertés (CNIL), has repeatedly issued warnings about connected televisions and reminded manufacturers that such processing requires freely given, informed consent. In practice, that consent is almost always obtained during initial setup, buried in a succession of screens where phrases like "improve your experience" and "personalised recommendations" mask the true nature of the operation.

The smart speaker: the false problem and the real one

No, your speaker is not permanently recording everything you say and shipping it off to the internet — the bandwidth and processing costs would make that absurd. The real problem lies elsewhere, and it has two parts.

First, wake-word detection is imperfect. Accidental activations have been documented for years, and each one produces a genuine audio clip from inside your home, stored and sometimes listened to by human annotators to improve the models. Several manufacturers had to admit this publicly after press revelations between 2019 and 2021.

Second, and more structurally: every deliberate request feeds a history. "What's the dosage for this medication," "what time does the mosque open," "remind me about my hospital appointment": these are no longer metadata, they are sensitive data within the meaning of Article 9 of the GDPR, tied to a named account.

The robot vacuum: the floor plan of your private life

A modern robot vacuum builds a SLAM map (simultaneous localisation and mapping) of your home. That map is not a simple outline: it shows floor area, the number of rooms, the position of furniture, sometimes even furniture height. Some models carry a front-facing camera. Research work and several journalistic investigations have shown that images captured by these devices have leaked outside their intended channels.

A floor plan is commercially valuable data: it reveals your standard of living, the probable make-up of the household, the presence of children or pets. If you want domestic robotics without that trade-off, there are robot vacuums with no cloud connection that can be controlled locally only or via a physical remote — still a narrow category, but a real one.

Video doorbells and cameras: the neighbourhood enters the equation

The connected doorbell raises an additional legal issue: it films public space or shared areas of a building. In France, the CNIL is explicit: a private individual may film the boundaries of their own property, but not the public highway or a neighbour's doorway. A badly aimed camera exposes its owner to a complaint and, in a shared building, to litigation.

Then there's the question of storage. Subscription cloud offerings keep your footage at the provider's premises, often outside Europe. An alternative exists: cameras with local storage on a memory card or a NAS, keeping the images at home. A high-endurance microSD card designed for continuous video recording costs a few tens of euros and eliminates the entire external transmission chain in one go.

Hand holding a smartphone with a connected VPN app in front of a television showing a football match


Step 1: map before you fix

You can't secure what you don't know about. The first move isn't technical, it's a matter of stocktaking.

Write down an inventory of everything in your home that has a network chip. The simplest approach: open your router's admin interface (usually reachable at a local address such as 192.168.1.1) and look at the list of connected devices. You'll often find names you don't immediately recognise — an old gadget, a flatmate's device, a piece of equipment left behind by the previous occupant.

For each device, ask three questions:

QuestionWhy it matters
Do I actually need its connected function?Plenty of objects work perfectly well without a network (a TV fed by an external box, a scale that simply displays your weight).
Where does the data go, and under which jurisdiction?A server outside the EU escapes GDPR guarantees in practice.
Will the manufacturer still exist in three years?A device whose cloud service shuts down becomes either unusable or an unpatched vulnerability.

That last point is very concrete: the home automation market has a high mortality rate, and a device that no longer receives security updates stays plugged into your network with known, published vulnerabilities.


Step 2: segment the network, the highest-return measure

If you take only one action away from this article, make it this one. Separate your connected objects from your personal devices.

The logic is the same as compartmentalising digital identities: a compromised device must not grant access to everything else. A poorly secured TV or light bulb sitting on the same network as your work computer can serve as a lateral entry point.

The simple method: the guest network

Almost every French ISP router now offers a "guest network" or "guest Wi-Fi" function. It creates a second wireless network, isolated from the main one. Put all your connected objects there: TV, speakers, bulbs, vacuum, doorbell. Keep your computers, phones and any NAS on the main network.

It's free, it takes twenty minutes, and it eliminates an entire class of risk.

The advanced method: a dedicated router and DNS filtering

To go further, a router compatible with open-source firmware (OpenWrt in particular) lets you create genuine VLANs, log outbound traffic and block by destination. Many users add local DNS filtering: a small single-board computer such as a Raspberry Pi is enough to run a filtering DNS resolver that blocks telemetry and advertising domains at source for the whole household.

The effect on televisions is spectacular: watching the logs, you discover the real rhythm of outbound connections, sometimes several hundred a day to analytics domains. Blocking those domains generally doesn't stop the device from working; it simply loses its ability to narrate your life.

Rule of thumb: a connected object that stops working when you cut off its access to advertising servers was never a household appliance — it was a commercial sensor in disguise.


Step 3: the settings that genuinely make a difference

On the television

Look in the menus for the following labels, often buried three or four levels deep:

  • Content recognition / ACR / Viewing Information Services → disable
  • Personalised advertising / advertising identifier → disable and reset the identifier
  • Usage-based recommendations → disable
  • Voice assistant / remote control microphone → disable if unused
  • Additional terms of use → withdraw optional consents

If the menus are too opaque, the radical option remains effective: never connect the TV to Wi-Fi and use an external media box you control. The screen goes back to being what it should have stayed — a screen.

On speakers and assistants

  • Switch off the microphone using the physical toggle when you're not using it (one of the rare cases where a hardware cut-off is reliable).
  • Regularly delete the voice history in the settings of the associated account.
  • Explicitly refuse the option to "improve services by allowing human review of recordings."

On health and fitness devices

Watches, scales and fitness bands generate health data — heart rate, sleep, menstrual cycle, weight. Legally these are sensitive data. Check whether the manufacturer offers a local sync mode, and disable sharing with "partners" by default. For anyone who wants to track their activity without exporting their physiology to a cloud, a GPS sports watch that doesn't require an account — or, more simply, a mechanical pedometer — remains a surprisingly relevant option.

Hand inserting an electronic ID card into a PIN-based eID reader in front of a laptop


Step 4: the devices everyone forgets

The smart meter. In France, Linky transmits consumption readings. A fine-grained load curve — hourly or sub-hourly — makes it possible to infer when you get up, go to bed, leave the house, even which appliances you use. Its transmission isn't automatic: it depends on a consent you can grant or refuse from your Enedis customer account. Check yours.

The printer. Connected models regularly report usage data, and some ink subscription services monitor levels continuously. A printer connected by USB to a single computer remains perfectly functional.

Children's toys and devices. Connected soft toys, GPS watches for children, night lights with microphones: the sector has seen several massive data leaks, including voice recordings of children. The CNIL and its European counterparts have sanctioned a number of players. Here the question isn't how to configure the device but whether it belongs in a child's bedroom at all.

The car. A recent vehicle records journeys, speeds, and contacts synced from your phone. Remember to delete your profile from the infotainment system before selling the car or returning a rental — something almost nobody does.


The legal lever: you have rights, use them

The GDPR applies fully to connected objects. In practical terms, for any device tied to an account, you can:

  • Exercise your right of access (Article 15): ask the manufacturer for all the data it holds about you. The answers are often instructive — and sometimes eye-opening about the sheer volume collected.
  • Exercise your right to erasure (Article 17): request deletion of the history.
  • Withdraw your consent (Article 7): it must be as easy to withdraw consent as it was to give it.
  • Refer the matter to the CNIL if you get no reply within one month.

These steps are taken in writing, addressed to the data protection officer (DPO) named in the privacy policy. An email is enough, but registered post gives you a certain date should you consider filing a complaint.

Worth noting too is the European Cyber Resilience Act, adopted in 2024, which progressively imposes on manufacturers of connected objects sold in the Union obligations of security by default and a minimum update support period. Its effects roll out through to 2027: when buying, the announced support duration becomes a selection criterion as important as the spec sheet.


Getting informed and equipped: a few concrete supports

Taking back control of your connected home is less about technical prowess than about method. A few material and intellectual supports genuinely help:

  • A general-audience book on home cybersecurity helps you understand the mechanisms rather than apply recipes — and therefore keep it up over time.
  • Smart plugs with local control (Zigbee or Matter running locally, with no mandatory trip through a cloud) let you keep the convenience of home automation without the data exfiltration.
  • A personal NAS centralises photos, backups and camera feeds at home rather than at a provider's.

None of these items is indispensable on its own. But together they sketch out a credible alternative to the default model, which amounts to renting the use of your own home in exchange for surrendering your data.


Conclusion: privacy is also a matter of square metres

We have learned to be wary of apps, cookies and social networks. What remains is to apply the same vigilance to objects we don't think of as computers: a screen, a light bulb, a scale, a doorbell. The shift happened without any announcement, device by device, replacement after replacement.

The good news is that the effective steps are few and within everyone's reach: take inventory, segment onto a guest network, disable content recognition and personalised advertising, favour local storage, exercise your GDPR rights when a manufacturer drags its feet. It doesn't take a whole weekend, just a few evenings.

And the principle is the same as for a message sent without giving your name: the best data is the data that is never transmitted. What holds true for an anonymous text message holds true for your living room.

#Vie privée#Confidentialité#Sécurité#RGPD#CNIL#Anonymat

On the same topic

// Anonymous SMS · Hidden number · To France

Envoyez votre message, gardez l'anonymat

Votre numéro reste masqué, aucune inscription, aucune trace. Rédigez, confirmez, et votre SMS part de façon totalement anonyme.

Envoyer un SMS anonyme