A textile factory connects sensors to its production lines and starts collecting real-time data: machine temperatures, downtime intervals, energy consumption. The contract signed at installation, however, contains not a single clause about who owns that data. The hardware manufacturer, the software platform provider, and the factory owner all look at the same data stream through entirely different lenses. This scenario captures a structural problem that SME managers in Turkey are only beginning to confront as the Internet of Things gains traction across industrial sectors.
Data ownership in the IoT ecosystem looks like a technical question on the surface, but it is fundamentally a legal and commercial framing problem. Raw data generated by a device acquires meaning only after it passes through a platform’s processing infrastructure. That processed data then flows — sometimes into the manufacturer’s product development pipeline, sometimes into third-party analytics channels. The end user, the factory or business that operationally generates the data, is often unaware of these flows. Broad contractual language such as ‘the platform may use anonymised usage data for service improvement’ quietly authorises a far wider range of data sharing than most managers realise when they sign.
Three actors drive this ambiguity. The hardware manufacturer can argue technical ownership because the sensor design and data format originate with them. The platform provider claims rights over added value because it operates the infrastructure that makes raw data actionable. The end user expects full control because the data source is their own operational process. From a legal standpoint, Turkey does not yet have specific legislation governing this three-party relationship directly; the Personal Data Protection Law (KVKK) is still in its preparatory stages, and general contract law fills the gap unevenly. That gap consistently works in favour of the party with greater negotiating leverage — almost always the platform provider.
The commercial consequences are concrete and measurable. An SME may believe it is building a proprietary efficiency advantage by analysing its production line data, while the same data feeds into sectoral benchmarking reports on the platform — potentially accessible, in aggregated form, to competitors. A more critical scenario arises when the business decides to switch platforms: if the contract does not guarantee the right to export historical operational data in a portable format, vendor lock-in becomes structurally unavoidable. Total cost of ownership (TCO) calculations rarely incorporate this migration cost or data access risk, which makes investment decisions systematically misleading.
The revenue models behind data sharing deserve separate scrutiny. Some IoT platforms generate income by selling anonymised, aggregated user data to third parties; this model finances the ‘low-cost’ or ‘free’ service proposition that attracts cost-conscious SMEs. A manager who does not ask why a platform’s monthly fee is significantly below market rate may not recognise that the real payment is being made in data. A sound ROI analysis requires the manager to answer one question clearly before signing: what is this platform’s revenue model, and where does my operational data sit within it?
The practical difficulty surfaces at the contract negotiation table. A small or mid-sized business sitting across from a large IoT platform provider typically lacks the leverage to amend standard contract terms. Platforms routinely close off data ownership clauses under the banner of ‘standard conditions.’ Compounding this, the habit of involving legal counsel in technical procurement decisions has not yet taken root in most Turkish SMEs. Purchasing decisions are driven by feature sets and pricing; data rights surface only after the contract is signed and a dispute arises.
For decision-makers, the operational criterion is straightforward: before committing to any IoT solution, four points must be explicitly defined in the contract. First, ownership of raw data and processed data must be stated separately and clearly. Second, the right to export data upon platform migration — including the technical format — must be guaranteed. Third, conditions under which data may be shared with third parties must be enumerated, not left to general clauses. Fourth, data deletion obligations at contract termination must be specified. If these four points are absent or buried in vague language, the operational dependency the business is entering into will outlast any efficiency gain the technology delivers. The productivity benefits of IoT are real; making them sustainable requires settling the question of data ownership before the first sensor goes online.
This article was originally written in Turkish by Gökhan MERCANOĞLU on June 22, 2015 and has been automatically translated into English and other languages using machine translation.