Rules connected products must meet
Electronics sold in India often need BIS registration under the Compulsory Registration Scheme, wireless devices need equipment type approval for their radio modules, and some telecom and networked equipment falls under mandatory testing and certification. E-waste rules place extended producer responsibility on manufacturers and importers. The companion app and cloud also handle personal data, so the DPDP Act applies to owner accounts, usage history and location.
Export markets add cybersecurity requirements. The EU's Radio Equipment Directive now includes cybersecurity rules for internet-connected radio products, and the Cyber Resilience Act will extend obligations to most products with digital elements. The UK bans universal default passwords on consumer connected products. This is general information, not legal advice; certification bodies and counsel should confirm requirements per market.
- Give every device unique credentials, never a shared default password.
- Sign firmware and verify signatures before installing updates.
- Publish how long devices will receive security updates.
- Provide a way for researchers to report vulnerabilities.
- Collect only the telemetry you need, with owner consent.
- Register products and report compliance under e-waste rules.



