Introduction: the room where no one is watching you no longer exists
Tuesday, 11:14 p.m. The thermostat notes that the heating has stayed at 19 °C when it should have dropped: someone is still up. The living-room speaker logged three wake-ups of its microphone during the evening — two of them false positives, along with the few seconds of audio that go with them. The robot vacuum has finished mapping the hallway and now knows that a piece of furniture has been moved. The video doorbell filmed four people passing your door, including your neighbour at 7:40 p.m. And the bedroom light went off at 11:51 p.m.
None of these devices is a spy. Each one provides a genuine service. But strung together, they write an extraordinarily precise daily logbook: the times you get up and go to bed, your absences, who lives in the household, how often you have visitors, the exact layout of your home, and — in some cases — snippets of what is said inside it.

Historically, the home was the last space where you weren't being measured. That's no longer true, and the shift happened without any conscious decision: a Christmas present, a box handed out by your energy supplier, a remote-monitoring subscription, a robot on special offer. This guide takes an honest inventory of what actually leaves your home, what the law requires of manufacturers, and which settings genuinely make a difference — without demanding that you live by candlelight.
What each device really knows about you
The inventory, room by room
Manufacturers talk about the function. The interesting subject is the derived data: what can be inferred from ordinary use.
| Device | Raw data collected | What can be inferred |
|---|---|---|
| Smart speaker / voice assistant | Wake word, audio clips, query history | Household composition, language, interests, schedules, children |
| Connected thermostat | Temperature, presence, schedule settings | Wake-up/bedtime hours, absences, holidays, remote working |
| Video doorbell or camera | Video feed, time-stamped motion detections | Visitors, daily rhythm, neighbourhood, delivery drivers, comings and goings |
| Robot vacuum | LiDAR mapping, obstacles, surfaces | Floor plan, number of rooms, furniture, actual floor area |
| Smart TV | Content displayed (ACR), apps, viewing time | Cultural habits, opinions, schedules, household with children |
| Smart meter | Electricity load curve | Presence, appliances used, shower or cooking times |
| Smartwatch / connected scale | Weight, sleep, heart rate, cycles | Health data within the meaning of Article 9 GDPR |
| Smart bulbs and plugs | Switch-on times, scenes | Room-by-room occupancy |
Taken on its own, each line looks harmless. The problem is correlation: an electricity load curve cross-referenced with lighting schedules and doorbell detections produces a behavioural portrait that no questionnaire could ever get you to fill in.
The special case of listening
This is fear number one, and it deserves a precise answer. Consumer voice assistants work with local wake-word detection: the device listens continuously, but in principle only transmits once triggered. The real issue is false triggers — a similar-sounding word, a line of dialogue from a TV series — which send a few seconds of private conversation to a server, sometimes later listened to by human annotators to improve recognition.
This isn't a theoretical point: the CNIL and several European authorities worked on the subject from 2019 onwards, after revelations about human transcription of voice clips at several major providers. The platforms have since made these programmes optional and added viewable histories. Practical conclusion: turn off contributions to service improvement and regularly purge your voice history in your account settings. This isn't some obscure option — every major player offers it.
The special case of the robot vacuum
A high-end robot carries a laser rangefinder and builds a measured plan of your home. That plan is stored in the manufacturer's cloud to allow remote control. Research has shown that a domestic map makes it possible to infer floor area, approximate standard of living, the presence of children and the furniture. Incidents involving leaked images captured by camera-equipped robots have also been documented by the US tech press. So check whether your model offers a cloud-free operating mode or map deletion, and when buying, favour a robot vacuum without a camera when you don't need that feature.
The real risks, ranked by likelihood
Distinguishing the spectacular threat from the probable one avoids needless paranoia.
Very likely — commercial exploitation. Your usage feeds advertising profiles and recommendation models. This is the dominant business model, particularly on smart TVs, whose automatic content recognition (ACR) identifies whatever appears on screen, including from an external HDMI stick.
Likely — a leak at the provider's end. One compromised customer account database, and addresses, phone numbers, sometimes video feeds start circulating. There's nothing the household can do: the risk sits with the supplier.
Moderately likely — misused domestic access. An indoor camera checked by a spouse, a voice history read by a family member, location sharing set up "for safety" that turns into a control tool. In practice, this is the scenario most frequently reported to victim-support organisations.
Unlikely but severe — technical intrusion. Devices that are never updated, default passwords, open ports. IoT botnet campaigns exploit this ground on a massive scale. France's ANSSI regularly points out that connected objects are the weak link in a home network.
Remember the hierarchy: the risk is almost never "a hacker is spying on you", it's "a company is profiling you" and "someone close to you has access".
What the law guarantees you (and what it doesn't)
The GDPR foundation
A connected object that processes personal data falls squarely under the General Data Protection Regulation. In practice, the manufacturer owes you:
- clear information about purposes and retention periods;
- freely given consent for anything not necessary to the service — targeted advertising is never "necessary";
- a right of access to your data and a right to erasure;
- portability of what you have provided;
- security by default and by design (Article 25).
The CNIL publishes dedicated guidance on voice assistants, cameras and smart-home devices: it's the French reference source, free and readable.
Cameras and doorbells: the rule that catches people out
You may film your property. You may not film a public road, a shared landing in a building, a neighbour's doorway or their garden. A badly aimed video doorbell is an offence, and the issue accounts for a growing share of neighbour disputes. The fix is simple: set the detection zones to exclude anything that isn't your own property, and display visible notice if visitors are being filmed.
What's new at European level
Two pieces of legislation are changing the picture in the medium term. The European Data Act, applicable from September 2025, requires that the user of a connected object be able to access the data that object generates and transfer it to a third party — enough to break open closed ecosystems. The Cyber Resilience Act, adopted in 2024, will progressively impose security requirements and a minimum update-support period on connected products sold in the Union. That last point is decisive: a device that isn't updated is a dangerous device, and software obsolescence has been the norm until now.
The action plan: five levels, from easiest to most demanding

Level 1 — The inventory (30 minutes)
Open your internet router's admin interface and list the connected devices. Most households discover two to four forgotten pieces of kit: an old tablet, a printer, a games console, something left behind by a former flatmate. Anything connected but unused should be disconnected. Write the results down in a paper notebook — a simple hardback notebook does the job perfectly for keeping the list, the models and the update dates up to date.
Level 2 — The settings that matter (one evening)
For each remaining device, systematically look for these five things:
- A unique password — never the default one, never reused.
- Two-factor authentication on the manufacturer's account, especially for cameras.
- Turning off product-improvement contributions (audio, diagnostics, usage statistics).
- Opting out of ad targeting in the privacy settings.
- Purging history (voice, video, mapping) and reducing the retention period to the shortest option offered.
On televisions, look specifically for the setting relating to content recognition: its name varies from brand to brand and it's often hidden behind a label promising "personalised recommendations".
Level 3 — Separate your networks (one hour)
This is the most effective step and the most widely ignored. Create a guest wifi network on your router and put all your connected objects on it. Your computers, phones and backup drives stay on the main network. The result: a compromised device can no longer reach your personal files. If your router doesn't handle this properly, adding a wifi router with a guest network settles the matter for a modest sum.
Level 4 — Cut the power physically (five minutes)
Nothing beats a switch. A smart plug with a timer lets you cut power to a speaker or an indoor camera during the hours when it serves no purpose. For computer webcams and some cameras, an adhesive webcam cover remains the most reliable device on the market: it doesn't need updating, it can't be hacked and it costs less than a coffee. And if you go away on holiday, unplug: the house doesn't need to be chatty while you're gone.
Level 5 — The local alternative (one weekend)
For anyone who wants to go further, there's an ecosystem of local home automation where the data never leaves the house. Open solutions let you control lighting, shutters, thermostats and sensors with no cloud account, relying on protocols such as Zigbee, Z-Wave or Matter running locally. The entry ticket is a small computer such as a Raspberry Pi single-board computer plus a radio communication dongle. It isn't for everyone, but it's currently the only setup where you can genuinely say the house isn't talking to anyone.
The blind spots nobody ever mentions
Guests
Your friends, the babysitter and the plumber never consented to being recorded. An indoor camera filming someone employed in your home raises a genuine legal problem: permanently monitoring an employee in their workplace is prohibited, and a home becomes a workplace as soon as you employ someone there. Tell people, or switch it off.
Children
A smart speaker in a child's bedroom records the queries of a minor who has no idea what a privacy policy is. Microphone-equipped connected toys have in fact been pulled from the market in several European countries after regulators raised the alarm. For listening to stories or music, an audio speaker with no microphone provides the same service without generating a single piece of data.
Moving house and resale
An object sold on without a full reset carries the history, the maps and sometimes the wifi credentials with it. Before any resale or donation: factory reset and removal of the device from the manufacturer's account — both, because one does not do the other.
Rented accommodation
A landlord cannot install a camera inside a rented home, nor in the private areas of a holiday let. Platforms also ban them in indoor spaces. If you find one, photograph it, report it, and know that invasion of privacy is a criminal offence.
And when you need to say something without naming yourself
Sometimes you discover a problematic setup: a neighbour's camera pointed at your window, a connected object forgotten in a shared home, a piece of equipment installed by a third party without notice. Raising it head-on can expose you to neighbourhood retaliation or a long-running family conflict.
In these situations, a message detached from your identity lets you raise the alarm, request removal or open a discussion without putting your name on the line. That is exactly what sending an anonymous SMS is for: state a fact, let the other person react, and keep open the option of going down the official route — registered letter, formal complaint, or a referral to the CNIL — if nothing changes.
Key takeaways
- Your connected objects aren't spying on you individually; together, they describe your life with a precision you'd never accept from any questionnaire.
- The three highest-yield actions: a guest wifi network, purging histories, and disabling targeted advertising in every app.
- The most common risk is domestic and relational, not criminal.
- A camera should only film your own property; a badly aimed doorbell is an offence.
- The Data Act and the Cyber Resilience Act strengthen your rights: when buying, start looking at the software support period the way you look at the warranty.
The connected home isn't something to reject wholesale. It simply calls for the questions we were never taught to ask: what is this device for, who is it talking to, and what happens if I unplug it? In nine cases out of ten, the answer to the last question is: absolutely nothing.
Sources and resources: CNIL (guidance on "objets connectés", "assistants vocaux" and "caméras et vidéosurveillance chez soi"), ANSSI (recommendations for securing a home network), Regulation (EU) 2016/679 (GDPR), Regulation (EU) 2023/2854 known as the Data Act, Regulation (EU) 2024/2847 known as the Cyber Resilience Act.



