Abstract

Digital transformation has changed the way people, businesses, and governments work, deliver services, and respond to disruption. Artificial intelligence, cloud computing, and the Internet of Things have supported this change, but the COVID-19 pandemic made one limitation clear: technology by itself does not create resilience. Organisations also need to understand how people behave during uncertainty and how that behaviour affects demand, risk, compliance, and recovery. The Internet of Behaviour (IoB) addresses this requirement by combining data from connected devices with behavioural science and analytics. This chapter discusses the role of IoB in digital transformation and strategic resilience through four outcomes: anticipate, adapt, recover, and transform. Examples from Amazon, Netflix, behavioural biometrics, smart infrastructure, and contact-tracing applications show how behaviour-related data can be used for practical decision-making. The chapter also discusses important concerns such as privacy, security, fairness, manipulation, consent, and public trust. Governance requirements are also explained with reference to GDPR, India's Digital Personal Data Protection Act, ISO 22316, and the NIST AI Risk Management Framework. The chapter suggests that IoB should be designed with privacy, accountability, auditability, and public participation from the beginning.

Keywords: Internet of Behaviour (IoB); digital transformation; strategic resilience; behavioral analytics; privacy; ethics; governance; Aarogya Setu; GDPR; NIST AI RMF

Introduction

Digital technologies have become a part of almost every organisational and public activity. Businesses use these technologies to improve their products, services, and internal operations. Governments use them to provide public services and manage large systems. As a result Artificial intelligence, cloud platforms, and connected devices have become important parts of digital transformation (Lengnick-Hall & Beck, 2005; Verhoef et al., 2021). However, a digitally advanced organisation is not automatically a resilient organisation. The COVID-19 pandemic showed that even strong digital infrastructure can fail to meet its purpose when public behaviour, demand, movement, or risk changes faster than the organisation can respond. Strategic resilience is therefore concerned with more than continuity. It refers to the ability to identify an emerging problem, manage its effects, adjust operations, recover from disruption, and make necessary changes (International Organization for Standardization [ISO], 2017; Javaid et al., 2021; National Institute of Standards and Technology [NIST], 2019b).

The Internet of Behaviour adds the human behaviour aspect to this discussion. IoT systems mainly connect devices and collect data, whereas IoB uses this data together with other digital records, to understand people’s actions, preferences, habits, and possible risk patterns. It combines behavioural science with machine learning to identify such patterns and, in some cases, to recommend or initiate an appropriate intervention (Javaid et al., 2021; Moghaddam et al., 2022; Sun et al., 2022). Gartner listed IoB among its strategic technology trends and expected behaviour-based programmes to expand across sectors such as healthcare, retail, public safety, and financial services (Panetta, 2020).

Most commonly used systems already follow this approach. Amazon uses user’s interaction and purchase data to recommend relevant products (Amazon Web Services, 2023). Netflix analyses viewing behaviour to help users discover suitable content(Gomez-Uribe & Hunt, 2016). Banks and digital platforms also use behavioural biometrics to detect unusual account activity (Nnamoko et al., 2022). During the pandemic, Aarogya Setu used proximity, location, and self-reported health information to provide risk-related information and contact alerts (Ministry of Electronics and Information Technology [MeitY], 2020b; Pulla, 2020). However, this example also highlights an important concern related to IoB. The same data that helps an organisation respond quickly may also be used for excessive surveillance, unfair profiling, hidden behaviour influence, or decisions that users are unable to understand or question (Government of India, 2023; Internet Freedom Foundation [IFF], 2020; Raman, 2020; Sharma, 2020; Wired, 2020).

This chapter first explains IoB and its difference from IoT. It then reviews applications in digital transformation and connects IoB mechanisms with four resilience outcomes: anticipate, adapt, recover, and transform. Aarogya Setu is discussed as an Indian case where public-health value, technical design, and governance concerns appeared together. The later sections examine ethical, privacy, and security issues and suggest a practical governance approach for responsible IoB.

Understanding the Internet of Behaviour (IoB)

Conceptual Foundations

The Internet of Behaviour extends connected technology from devices to human action. An IoT system may record steps, heart rate, location, clicks, or device activity. An IoB system asks what these records show about habits, choices, risks, or likely future actions. The purpose is not only to collect data. The purpose is to use it for personalisation, prediction, risk assessment, or a timely response.

Researchers generally describe IoB as a combination of connected technologies, behavioural science, and data analytics used to study both online and offline behaviour (Moghaddam et al., 2022; Sun et al., 2022; Wijaya et al., 2024). A fitness tracker gives a simple example. At the IoT level, it records steps, sleep, or heart rate. At the IoB level, the same records may be used to identify a change in routine, suggest an achievable target, or send a reminder when the user is most likely to act. The difference lies in the move from measurement to behavioural interpretation.

In an IoB system, the person is not outside the technical process. Human activity becomes an important source of input for the system. For example, Moghaddam et al. (2022), discuss how sensor-based crowd data was used at the Uffizi Galleries in Florence. The information supported live decisions about visitor movement and queue management. This type of use shows how behaviour-related data can improve an immediate service without waiting for a later manual review.

IoB also differs from a one-time behavioural analysis. It usually works as a continuing cycle. Data is collected, interpreted, used to support an action, and collected again to see what changed. This feedback can improve the service, but it can also increase the level of influence exercised over the user. For that reason, the technical value and the governance risk must be examined together.

Table 1. The Four-Layer IoB Architecture

Layer Examples Main purpose
Data sources Sensors, wearables, smartphones, applications, and social or media feeds Collect behaviour-related signals
Technical enablers AI and machine learning, cloud and edge analytics, natural language processing, and real-time streams Process data and identify patterns
Behavioural models Nudge theory, behavioural economics, and habit-formation models Interpret behaviour and plan an intervention
Feedback mechanisms Personalised alerts, adaptive interfaces, and automated rules Use the result and observe the response

Note. Synthesized from Elayan et al. (2023), Thaler and Sunstein (2008), and Wijaya et al. (2024).

Analytical Distinction: IoB versus IoT

IoT and IoB are related, but they do not perform the same function. IoT records events generated by devices. IoB studies those events in relation to behaviour and may use the result to shape a later action. A fitness tracker may record the number of steps completed in a day. An IoB application can compare that number with the user's earlier routine, notice a continuing decline, and provide a suitable reminder or health suggestion (Lupton, 2013; Thaler & Sunstein, 2008). In an organisation, the same approach can be used to improve the customer journey, apply security checks, or support policy-related decisions (Javaid et al., 2021; Nnamoko et al., 2022; Wijaya et al., 2024).

Behavioral Science Integration

Behavioural science helps explain why people may respond differently to the same message or digital choice. The nudge theory proposed by Thaler and Sunstein (2008) explains how the way choices are presented can influence people without restricting their freedom to decide. In IoB, this concept may be applied through reminders, comparison, default options, warnings, and personalised feedback. Elayan et al. (2023) found that feedback based on user behaviour helped in reducing energy consumption. However, technology alone cannot determine whether nudge is useful or unfair. The purpose of the intervention, and the user’s freedom to reject or question it are also important.

Sectoral Applications: A Comparative Overview

IoB is used in areas where a digital service depends on understanding how people act. In customer service and marketing, organisations study searches, clicks, purchases, and responses to earlier offers to improve personalisation (Javaid et al., 2021; Wijaya et al., 2024). In e-commerce, these records help platforms show products that are more relevant to the user's current interests.

Healthcare applications can use data collected from wearable devices and mobile phones for remote monitoring, lifestyle support, and early identification of health risk (Fiore et al., 2023). Financial institutions use typing patterns, mouse movement, swipe behaviour, and device handling as additional indicators for detecting fraud and account-takeover (Eberle & Holder, 2009; Nnamoko et al., 2022). Airports and other large public spaces can study movement patterns to manage congestion and improve passenger routing (Salis, 2021).

These examples have a common pattern. Ordinary digital activity becomes a source of operational information. The information may help an organisation personalise a service, detect an unusual event, plan resources, or respond before a problem becomes serious. Its value is therefore not limited to marketing. It also appears in safety, health, security, and service continuity.

At the same time, IoB moves a system closer to the user's decisions. A recommendation, warning, or risk score does not only describe behaviour; it may also change it. This makes IoB more powerful than routine data collection but it also makes it more sensitive. The organisation should be able to explain what data is being used, why it is required, and what action will be taken if the system reaches an incorrect conclusion (Elayan et al., 2023; Fiore et al., 2023; Javaid et al., 2021; Moghaddam et al., 2022; Sun et al., 2022; Thaler & Sunstein, 2008; Wijaya et al., 2024).

IoB in the Context of Digital Transformation

Digital transformation refers to the use of digital technologies to improve organisational processes, provide better services to users, create value (Lengnick-Hall & Beck, 2005; Verhoef et al., 2021). Earlier programmes often concentrated on automation, online access, and process efficiency. These remain important, but many services now depend on how well the organisation understands changing user behaviour.

IoB adds this behaviour-related view. It helps a digital system respond to what users actually do rather than relying only on fixed assumptions. The system may personalise an interface, identify a security concern, adjust a service, or support a faster operational decision. The following examples show how this approach appears in different sectors.

Retail and E-Commerce: Amazon

Amazon’s recommendation systems analyse browsing activity, search history, ratings, and previous purchases to suggest products that may be relevant to the customer (Amazon Web Services, 2023). The recommendations reduce the effort required to search a very large catalogue and are built into the normal shopping process.

This is also an example of digital transformation at the business-model level. Behavioural information supports product discovery and gives the platform a current view of customer interest. During a change in demand, the same information can support decisions related to stock management, promotions, and service priorities. It does not remove supply-chain risk, but it helps the organisation identify customer behaviour at an early stage (Amazon Web Services, 2023; Lengnick-Hall & Beck, 2005; Verhoef et al., 2021).

Media and Entertainment: Netflix

Netflix uses viewing history, searches, watch time, pauses, ratings, and other interaction data to recommend films and programmes (Gomez-Uribe & Hunt, 2016). The immediate aim is to help each user find suitable content without manually examining the whole library.

Gomez-Uribe and Hunt (2016) explain that recommendation is central to content discovery on Netflix. The quality of the service therefore depends not only on the amount of content available but also on how effectively the platform connects a user with that content. Behavioural data becomes part of service design rather than a separate reporting activity.

This approach also supports resilience. Audience interests can change quickly, and a fixed content arrangement may become less useful. A system that studies current viewing behaviour can change its recommendations when the user’s interests change. This helps the platform remain relevant when customer preferences and market conditions are uncertain.

Smart Infrastructure: Airports

Airports use connected systems to support passenger movement, gate communication, queue management, and congestion control. In a fog-to-cloud IoB model, current movement data can be used to suggest a less crowded route or direct passengers away from a developing bottleneck. The same records can later help planners understand where extra staff, signs, or space may be required (Salis, 2021). The resilience benefit is practical: small flow problems can be managed before they affect a larger part of the terminal.

Financial Services: Behavioral Biometrics

Behavioural biometrics is one of the more established security uses of IoB. Instead of checking a user only at login, the system observes how the person uses the device during the session. Signals may include typing rhythm, mouse movement, swipe speed, navigation order, device angle, and scrolling behaviour (Eberle & Holder, 2009; Nnamoko et al., 2022). These patterns are useful because they are more difficult to copy than a password or security token.

A continuously updated behavioural profile can detect when a user session no longer matches the person’s normal behaviour. This may indicate stolen credentials, account takeover, or another type of misuse. The system may then ask the user to complete an additional security check or may restrict a sensitive action. Since the behavioural profile is updated over time, it can adjust to genuine changes in the user's behaviour. This reduces dependence on fixed rules and may help reduce unnecessary alerts while still detecting important changes from normal behaviour (Eberle & Holder, 2009; Nnamoko et al., 2022).

The resilience value comes from this ability to adjust. Attack methods change, and a rule written for one fraud pattern may soon become less effective. Behavioural monitoring gives the organisation another source of evidence during the session. It should not be treated as infallible, but it can improve detection without forcing every user to complete repeated authentication steps.

Supply Chain and Logistics

Supply-chain systems increasingly combine operational records with information about decisions made by suppliers, drivers, warehouse teams, and automated systems. This information can be used to identify a delay, reconsider a route, or activate a contingency plan when conditions change (Amazon Web Services, 2022). Here the use is close to IoB because the system studies patterns of action as part of the operational picture. The main resilience benefit is earlier situational awareness during logistical, climatic, or geopolitical disruption.

Across these sectors, IoB makes digital transformation more responsive to actual use. The organisation can see a change in behaviour, relate it to an operational concern, and adjust the service. This can support personalisation, risk identification, resource planning, and operational continuity. However, its effectiveness depends on the quality of the data and the presence of proper controls to prevent unfair or excessive use (Amazon Web Services, 2022, 2023; Gomez-Uribe & Hunt, 2016; Javaid et al., 2021; Lengnick-Hall & Beck, 2005; Nnamoko et al., 2022; Salis, 2021; Verhoef et al., 2021; Wijaya et al., 2024).

Strategic Resilience and the Internet of Behaviour

Defining Strategic Resilience

ISO 22316:2017 describes organisational resilience as the ability to absorb and adapt in a changing environment while continuing to meet objectives (ISO, 2017). Hamel and Välikangas (2003) treat resilience as continuing renewal rather than a response that begins only after a crisis. Duchek (2020) explains resilience through three related capabilities: anticipating a problem, managing its effects, and adapting after learning from the experience. NIST SP 800-160 Volume 2 describes similar outcomes for cyber-resilient systems: anticipate, withstand, recover, and adapt (NIST, 2019b). Based on these concepts, this chapter uses the AART model: Anticipate, Adapt, Recover, and Transform.

The literature also shows that resilience is not created by infrastructure alone. During a disruption, employees change how they work, customers change what they need, and communities change movement, communication, and risk-taking behaviour. These responses may support recovery, or they may place additional pressure on the system.

IoB can help an organisation observe these changes earlier. Behaviour-related data may show where demand is increasing, where users are not following a safety message, or where a normal pattern has changed. This information can support warnings, targeted communication, operational adjustments, and later learning. The purpose is not to replace human judgement, but to give decision-makers a more current view of what is happening.

Figure 1. Conceptual model linking IoB to strategic resilience

Conceptual model linking IoB to strategic resilience through anticipate, adapt, recover and transform outcomes

Mapping IoB Mechanisms to AART Resilience Outcomes

Table 2 links specific IoB mechanisms with the four AART outcomes and gives examples from published studies.

Table 2. IoB Mechanisms Mapped to AART Resilience Outcomes

AART outcome IoB mechanism Evidence and reference
Anticipate Mobility and proximity data Supported analysis of viral spread and reopening decisions (Chang et al., 2021; Kraemer et al., 2020).
Anticipate UEBA change detection Supports detection of insider misuse and account compromise (Eberle & Holder, 2009; NIST, 2019b).
Adapt Real-time feedback and information about social behaviour Opower program reported sustained energy reductions from 1.4% to 3.3% (Allcott, 2011; Allcott & Rogers, 2014).
Recover Privacy-preserving exposure notification systems NHS app study found higher adoption associated with reduction in lower case growth (Wymant et al., 2021).
Transform Behaviour-based service model Usage-based insurance linked driving behaviour with feedback and pricing (Bolderdijk et al., 2011).

Note. Synthesized from Allcott (2011), Allcott and Rogers (2014), Bolderdijk et al. (2011), Chang et al. (2021), Eberle and Holder (2009), Kraemer et al. (2020), NIST (2019b), Teece (2007), and Wymant et al. (2021).

Anticipate

Mobility and proximity information supported early warning during the COVID-19 pandemic. Kraemer et al. (2020) showed that detailed human-mobility data could help explain and predict the spread of infection. Chang et al. (2021) used mobility networks to study infection risk and examine how reopening decisions could affect disease spread. In cybersecurity, User and Entity Behaviour Analytics develops a baseline of normal activity and identifies unusual changes that may indicate insider misuse or compromised user credentials (Eberle & Holder, 2009; NIST, 2019b). In both cases, behaviour provides an additional signal before the full effect of the problem is visible.

Adapt

IoB supports adaptation when a system changes its response on the basis of current behaviour. The Opower energy-conservation programme used personalised comparisons and social-norm feedback in household energy reports. Studies found sustained reductions of about 1.4% to 3.3% across large groups of customers (Allcott, 2011; Allcott & Rogers, 2014). The intervention was not a one-time public message. It was repeated and adjusted through continuing feedback, which is why it provides a useful example of behaviour-based adaptation.

Recover

The NHS COVID-19 app in England and Wales provides evidence of behaviour-supported recovery. Wymant et al. (2021) reported that a 1% increase in app use was associated with an estimated 0.8% to 2.3% reduction in cases. The study estimated that approximately 284,000 to 594,000 infections were prevented. The app used privacy-preserving exposure notifications rather than a centralised record of every contact. Its value depended on adoption, timely alerts, and the willingness of users to act on the information.

Transform

Usage-based insurance shows how behaviour-related data can change an existing business model. Instead of relying only on general categories, the insurer can use driving information to support pricing and feedback. Bolderdijk et al. (2011) found that pay-as-you-drive insurance influenced speed choices among young drivers. The approach creates a service in which price and risk are linked more closely to actual use. It also requires clear rules because an incorrect or poorly explained behavioural profile can affect cost and access.

The four outcomes are connected. Behavioural data can provide an early warning, help a service adjust, support recovery, and create a different way of delivering value. IoB contributes to resilience when the information leads to a useful and proportionate response. It does not contribute when the data is unreliable, the intervention is unfair, or users lose trust in the system.

Case Study: Aarogya Setu—A Technical and Governance-Oriented IoB Analysis

Background and Purpose

Aarogya Setu was launched in April 2020 by India's National Informatics Centre. It used Bluetooth-based proximity data, GPS location, and self-reported health data to assess COVID-19 risk and provide alerts. The application reached more than 100 million downloads within a short period and became one of India's largest public digital-health applications (MeitY, 2020a, 2020b; Pulla, 2020).

Functional Capabilities and Resilience Role

The app used Bluetooth encounters to identify possible exposure, GPS data to support hotspot mapping, and user-provided responses to collect additional health information. Based on this information, it could advise users to isolate, get tested, or avoid a high-risk area (Pulla, 2020). These functions supported three parts of resilience. The app helped anticipate risk through proximity and location data, adapt communication to the user's situation, and support recovery by providing early warnings and behavioural guidance.

The case is important because it shows the value of combining more than one type of information. Bluetooth proximity alone could not provide the same spatial view as GPS data, and self-reported symptoms added a further source of context. Together, these records gave public-health authorities a broader, although still incomplete, picture of possible risk.

Ethical and Legal Challenges: A Balanced Assessment

Aarogya Setu also raised public questions about data governance, required use, security testing, and the protection of behaviour-related health information. These questions should not be treated as separate from the technical design. A national application depends on public confidence, so consent, communication, purpose limits, and accountability affect both legitimacy and practical use.

  • Privacy and data governance: Digital-rights organisations and policy commentators, including the Internet Freedom Foundation, questioned the legal basis for some data collection, the period for which data could be retained, and the transparency of access to aggregated information (Internet Freedom Foundation [IFF], 2020; Raman, 2020). These concerns should be understood in the context of the data-protection framework that was available when the app was launched. The Digital Personal Data Protection Act, 2023 (Government of India, 2023) now provides a clearer basis for examining user’s consent, lawful processing of data, the rights of data principals, and the duties of organisations that process personal data (Government of India, 2023).

  • Required use in some contexts: Reports published during that time stated that the application was required for entry into certain workplaces, travel arrangements, or services (Wired, 2020). In such situations, user’s consent may not be considered completely voluntary because users may have had little practical choice.

  • Technical security concerns: Researchers reported several possible security weaknesses. These included GPS spoofing and the possibility of using application responses to infer information about nearby users (Sharma, 2020). Such findings do not remove the public-health purpose of the application, but they show why threat modelling, independent testing, secure updates, and privacy-by-design are necessary before and during a large deployment.

  • Positive outcomes and limitations: Government reports stated that the application supported hotspot identification, public information, and behavioural guidance (Press Information Bureau [PIB], 2020). However, an independent epidemiological evaluation comparable to the study of the NHS app was not publicly available at the time of writing (Wymant et al., 2021). It is therefore safer to describe the operational contribution of Aarogya Setu than to make a precise causal claim about the number of infections it prevented.

  • Aarogya Setu shows both sides of a national IoB deployment. Behaviour-related data can support alerts, hotspot identification, and timely health communication during a crisis. The same system also needs a defined purpose, limited retention, clear conditions of use, strong security, independent assessment, and honest communication with the public. These observations highlight the need for stronger security testing, privacy-by-design, and threat modelling when public digital-health applications are deployed at large scale. (Government of India, 2023; IFF, 2020; Raman, 2020; Sharma, 2020; Wired, 2020).

Ethical, Privacy, and Security Challenges in IoB

Ethics: Freedom, Control, and Fairness

IoB systems can influence behaviour through recommendations, reminders, risk scores, and digital nudges. This can be beneficial in healthcare, fraud prevention, energy conservation, and emergency communication. The ethical difficulty begins when users do not know what information has been collected, how the system has interpreted it, or why a particular intervention has appeared.

The central question is whether the system is helping the user or using behavioural knowledge mainly for the interest of the organisation. A reminder to complete a security check or avoid a high-risk area may be reasonable. A hidden technique that keeps a person engaged, discourages a valid choice, or produces a disadvantage without explanation is different. Transparency, meaningful user control, fairness testing, and a clear line of responsibility should therefore be part of the design.

Zuboff (2019) uses the term behavioural surplus for information collected beyond what is needed to provide a service and then used to predict or influence later behaviour. This concern is especially relevant to platforms that can observe users across long periods. Nissenbaum's (2010) idea of contextual integrity adds another useful test. Information given in one setting should not automatically be used in a different setting with different expectations. Health information, for example, should not move into employment screening or insurance decisions simply because it is technically available. Purpose limitation must be enforced through access rules and system controls, not only described in a privacy notice.

The OECD AI Principles (Organisation for Economic Co-operation and Development [OECD], 2019/2024) and UNESCO's (2021) Recommendation on the Ethics of Artificial Intelligence both give importance to human rights, transparency, fairness, and accountability. For IoB, these principles need practical implementation. Developers should test whether a behavioural model treats groups differently, decision-makers should be able to explain the purpose of an intervention, and affected users should have a way to challenge an important decision. An ethical requirement that appears only in policy documents will not correct a harmful model after deployment.

Privacy: Identifiability and Regulatory Compliance

Behavioural data can be difficult to anonymise because patterns of movement, device use, or interaction may be distinctive. A dataset that does not contain a person's name may still become identifiable when it is combined with location, time, or other contextual information. Organisations should not assume that privacy risks are removed only by detecting direct identifiers from the data.

Article 5 of the GDPR requires personal data to be processed lawfully, fairly, and transparently. It also includes requirements related to purpose limitation, data minimisation, accuracy, and storage limitation (European Union, 2016). Article 22 covers certain decisions made solely through automated processing, while Article 35 requires a Data Protection Impact Assessment for high-risk processing activities, including systematic monitoring. India's DPDP Act 2023 also sets duties for data fiduciaries and provides rights to data principals (Government of India, 2023). An IoB system operating across borders may also need to address the Schrems II judgment and, where relevant, the EU-US Data Privacy Framework (Court of Justice of the European Union [CJEU], 2020; European Commission, 2023). Compliance therefore depends on where the data is collected, what the system infers, who receives the result, and how long the information is kept.

Security: Enlarged Attack Surface

IoB uses the same sensors, applications, networks, and cloud services that create security concerns in IoT. It then adds behavioural models and decision logic. A weakness at any layer can affect both the raw data and the conclusion drawn from it. NISTIR 8228 explains the main cybersecurity and privacy risks associated with IoT devices. NISTIR 8259A provides a basic set of requirements for device identity, software updates, configuration, and data protection (NIST, 2019a, 2020a). ENISA guidance and ETSI EN 303 645 also provide related security controls for connected and consumer devices (ENISA, 2017; ETSI, 2024).

Digital contact tracing shows why the architecture matters. DP-3T and the Apple/Google Exposure Notification system were designed to reduce central collection of contact information (Apple & Google, 2020a, 2020b, 2020c; Troncoso et al., 2020). Less central data can reduce exposure and may improve user confidence. However, Ellis et al. (2022) identified replay and proximity-leakage weaknesses in implementation. A privacy-oriented design is therefore only the starting point. Cryptography, coding, testing, updates, and operational monitoring must also work correctly.

The behavioural models used by IoB introduce another security concern. Data poisoning, model drift, adversarial input, and bias can change the output even when the underlying device is secure. The NIST AI RMF 1.0 provides a structure for governing, mapping, measuring, and managing these risks across the model lifecycle (NIST, 2023). Where a model affects access, safety, price, employment, or health advice, its integrity should be treated as a security and accountability issue, not only as a matter of predictive accuracy.

A Governance Stack for Responsible IoB

IoB covers data protection, device security, behavioural analytics, automated decisions, privacy management, and organisational resilience. No single framework deals with all of these areas. Table 3 shows how existing standards and legal instruments can be combined for practical governance.

Table 3. IoB Governance Framework Stack

Area Framework IoB use and practical requirement
Data protection GDPR Applies to behavioural inference and automated decisions. Requires a lawful basis, Article 22 safeguards, and a DPIA where processing is high risk.
Data protection DPDP Act 2023 Applies to processing of IoB data in India. Requires lawful processing, user rights, safeguards, and accountability.
Cybersecurity NIST SP 800-160 Vol. 2 Supports cyber-resilient IoB design through anticipate, withstand, recover, and adapt outcomes.
AI risk NIST AI RMF 1.0 Applies to behavioural analytics and machine-learning models. Requires risks to be governed, mapped, measured, and managed.
Privacy management NIST Privacy Framework Supports privacy controls across behavioural-data pipelines through Identify-P, Govern-P, and Control-P.
Privacy management ISO/IEC 27701:2019 Links privacy information management controls with an information security management system.
Privacy by design ISO 31700-1:2023 Supports the inclusion of privacy controls in the design of consumer IoB products.
IoT security NISTIR 8259A; ETSI EN 303 645 Applies to the device and sensor layer, including identity, updates, configuration, and data protection.
AI ethics OECD Principles; UNESCO Recommendation Applies to systems that analyse or influence human behaviour and gives importance to human rights, transparency, fairness, and accountability.

Note. Synthesized from Apple and Google (2020a, 2020b, 2020c), CJEU (2020), Ellis et al. (2022), ENISA (2017), ETSI (2024), European Commission (2023), European Data Protection Board (EDPB, 2017, 2018), European Union (2016), Government of India (2023), ISO (2019, 2023), NIST (2019a, 2020a, 2020b, 2023, 2024, 2025), OECD (2019/2024), Troncoso et al. (2020), UNESCO (2021), and U.S. Department of Commerce (2023).

In practice, responsible IoB should begin with a clear purpose and the collection of only the data that is actually required. Data-retention periods should be clearly defined and enforced through technical controls. Processing should be carried out on the device or at the edge when centralised data collection is not necessary. Where suitable, methods such as differential privacy can be used for aggregated reporting (Dwork, 2006). Access logs, consent records, model versions, and important decision rules should be maintained for audit purposes. These measures help reduce the unnecessary concentration of personal data and make it easier to identify who accessed the information, how it was used and for what purpose (Apple & Google, 2020a, 2020b, 2020c; Ellis et al., 2022; ISO, 2019, 2023; NIST, 2020b; Troncoso et al., 2020).

Future Directions and Strategic Governance

Emerging IoB Technologies

Cognitive IoB: AI Agents

Reinforcement-learning recommendation systems and autonomous AI agents can change an intervention when user’s behaviour or surrounding environment changes (Afsar et al., 2022). This may improve timing and relevance of the intervention. However, it may also allow the system to increase its influence without human review at every stage. For this reason, explainability and human oversight are important. The system should have a clearly defined purpose, fixed limits on the actions it can perform, and a process for stopping or reviewing any behaviour that goes outside those limits.

Behavioral Digital Twins

A behavioural digital twin is a model used to simulate how an individual or group may respond to a possible event. It can be used to support evacuation planning, outbreak response, transport management, or infrastructure design before a real emergency occurs (European Commission, 2022; Fuller et al., 2020). The model, however, is only as reliable as its assumptions and data. Synthetic output derived from real behavioural records may still create privacy risk, and a simulated result should not be treated as proof that a policy will affect every group in the same way.

Blockchain for Behavioral Data Governance

Blockchain has been proposed for consent records, audit trails, and self-sovereign identity in systems where several organisations share data (Casino et al., 2019). A properly designed ledger can record when consent was given, updated, or withdrawn. It can also improve traceability where several parties are involved. It does not solve poor data collection or unfair decision-making on its own. The information written to the ledger, the authority of each participant, and the procedure for correcting an error still need governance.

Immersive Metaverse Environments

Virtual and augmented reality systems can collect detailed records of gaze, movement, interaction, and response. These records can help improve accessibility and provide more personalised services. However, they may also reveal sensitive information that users do not realise they are sharing (Mystakidis, 2022; Rospigliosi, 2022). The immersive setting makes notice and consent more difficult because attention is focused on the experience. Rules for collection, retention, advertising, profiling, and transfer should therefore be defined before such monitoring becomes routine.

Policy and Regulatory Evolution

GDPR, the DPDP Act 2023, and sector-specific laws provide important protections, but they do not address every issue created by large-scale behavioural inference. IoB governance also requires clear rules on permitted uses, limits on manipulative design, understandable explanations, fixed data-retention deadlines, and human review of decisions that may have a serious impact. These controls can be developed through existing legal and standards frameworks. They should address not only the collection of identifiable data but also influence created through behavioural prediction and profiling (European Union, 2016; Floridi & Taddeo, 2016; Government of India, 2023; Nnamoko et al., 2022; OECD, 2019/2024; Raman, 2021; Thaler & Sunstein, 2008; UNESCO, 2021).

Towards Responsible Resilience

A responsible approach to IoB can be built based on three principles:

  • Ethics by design: Privacy, fairness, non-discrimination, and accountability should be considered during the design of the system. A compliance statement added later cannot correct a model trained on unsuitable data or a process in which responsibility has not been clearly assigned. Impact assessments at the design stage, testing across relevant user groups, clear purpose limits, and named responsibility for automated decisions are therefore required (European Union, 2016; Floridi & Taddeo, 2016; ISO, 2019, 2023; NIST, 2020b; OECD, 2019/2024; UNESCO, 2021).

  • Dual accountability: Technical and institutional controls should work together. Technical requirements include security testing, model validation, access control, and explainability. Institutional requirements include independent audits, regulatory oversight, complaint handling procedures, and legal responsibility. A technically secure system can still be misused, while an organisation with good intentions may still cause harm if the system is insecure (ISO, 2019, 2023; NIST, 2020b, 2023, 2024, 2025).

  • Societal dialogue: Decisions about the acceptable level of behavioural monitoring should not be made only by developers or service providers. People should be clearly informed about what is being observed, how the findings will be used, and what choices are available to them. Public consultation, representative oversight, accessible explanations, and meaningful opt-out or review procedures help create the legitimacy required for long-term use (European Union, 2016; OECD, 2019/2024; UNESCO, 2021).

Conclusion

IoB adds a behavioural layer to digital transformation. This layer can help organisations and governments notice an emerging risk, adjust a service, support recovery, and develop new ways of working. The AART examples in this chapter show that these outcomes are not only theoretical. Mobility data supported early warning, behavioural feedback changed energy use, exposure notifications supported public-health recovery, and usage-based insurance linked service design with actual behaviour (Allcott, 2011; Allcott & Rogers, 2014; Bolderdijk et al., 2011; Chang et al., 2021; Kraemer et al., 2020; Wymant et al., 2021).

Commercial and security applications show a similar value. Recommendation systems help Amazon and Netflix respond to current user interest, while behavioural biometrics gives financial services an additional way to identify unusual activity (Amazon Web Services, 2023; Gomez-Uribe & Hunt, 2016; Eberle & Holder, 2009; Nnamoko et al., 2022). The Aarogya Setu case also shows that scale alone is not enough. A public IoB system needs security, transparency, a lawful purpose, and public trust. Weakness in any of these areas can reduce participation and undermine the intended benefit (Government of India, 2023; IFF, 2020; Raman, 2020; Sharma, 2020; Wired, 2020).

Responsible resilience requires governance to be part of the technical design. GDPR and the DPDP Act provide rules for data processing and user rights. The NIST AI RMF supports the management of risks in behavioural models. ISO 22316 and NIST SP 800-160 provide resilience principles, while ISO/IEC 27701 and ISO 31700-1 support privacy management and privacy-by-design. These frameworks should be applied as working controls, with evidence of implementation and review, rather than listed only as policy references.

Future IoB systems will include more autonomous agents, behavioural digital twins, distributed consent records, and immersive environments. These technologies may improve planning and personalisation, but they will also collect or infer more detailed information about people. Organisations should therefore treat behaviour as useful operational information and as information that deserves strong protection.

Further research is needed in four areas. First, national IoB deployments should be evaluated independently, with clear outcome measures similar to the NHS app study (Wymant et al., 2021). Second, standards should address behavioural inference and influence more directly. Third, fairness should be tested across relevant population groups. Fourth, behavioural digital twins should be studied over time to determine when their predictions remain valid and when policy decisions should not rely on them.

References

Afsar, M. M., Crump, T., & Far, B. (2022). Reinforcement learning based recommender systems: A survey. ACM Computing Surveys, 55(7), 1–38. https://doi.org/10.1145/3543846

Allcott, H. (2011). Social norms and energy conservation. Journal of Public Economics, 95(9–10), 1082–1095. https://doi.org/10.1016/j.jpubeco.2011.03.003

Allcott, H., & Rogers, T. (2014). The short-run and long-run effects of behavioral interventions: Experimental evidence from energy conservation. American Economic Review, 104(10), 3003–3037. https://doi.org/10.1257/aer.104.10.3003

Amazon Web Services. (2022). Digital supply-chain resiliency: ML-driven risk orchestration [Solution brief].

Amazon Web Services. (2023). Amazon Personalize: Recommender service [Product documentation]. https://aws.amazon.com/personalize/

Apple & Google. (2020a). Exposure Notification—Bluetooth specification (Version 1.2).

Apple & Google. (2020b). Exposure Notification—Cryptography specification (Version 1.2.1).

Apple & Google. (2020c). Exposure Notification—Overview and FAQs.

Bolderdijk, J. W., Knockaert, J., Steg, E. M., & Verhoef, E. T. (2011). Effects of pay-as-you-drive vehicle insurance on young drivers’ speed choice: Results of a Dutch field experiment. Accident Analysis & Prevention, 43(3), 1181–1186. https://doi.org/10.1016/j.aap.2010.12.032

Casino, F., Dasaklis, T. K., & Patsakis, C. (2019). A systematic literature review of blockchain-based applications: Current status, classification and open issues. Telematics and Informatics, 36, 55–81. https://doi.org/10.1016/j.tele.2018.11.006

Chang, S., Pierson, E., Koh, P. W., Gerardin, J., Redbird, B., Grusky, D., & Leskovec, J. (2021). Mobility network models of COVID-19 explain inequities and inform reopening. Nature, 589(7840), 82–87. https://doi.org/10.1038/s41586-020-2923-3

Court of Justice of the European Union. (2020, July 16). Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (C-311/18).

Duchek, S. (2020). Organizational resilience: A capability-based conceptualization. Long Range Planning, 53(1), Article 101792. https://doi.org/10.1016/j.lrp.2019.101792

Dwork, C. (2006). Differential privacy. In M. Bugliesi, B. Preneel, V. Sassone, & I. Wegener (Eds.), Automata, languages and programming (Lecture Notes in Computer Science, Vol. 4052, pp. 1–12). Springer.

Eberle, W., & Holder, L. (2009). Insider threat detection using graph-based anomaly detection. In Proceedings of the IEEE Symposium on Security and Privacy Workshops.

Elayan, H., Aloqaily, M., Karray, F., & Guizani, M. (2023). Internet of Behavior and Explainable AI systems for influencing IoT behavior. IEEE Network, 37(1), 62–68. https://doi.org/10.1109/MNET.009.2100500

Ellis, C., Wen, H., Lin, Z., & Arora, A. (2022). Replay (far) away: Exploiting and fixing Google/Apple Exposure Notification contact tracing. Proceedings on Privacy Enhancing Technologies, 2022(4), 727–745. https://doi.org/10.56553/popets-2022-0130

ENISA. (2017). Baseline security recommendations for IoT in the context of critical information infrastructures. ENISA.

ETSI. (2024). Cyber security for consumer Internet of Things: Baseline requirements (ETSI EN 303 645 V3.1.3).

European Commission. (2022). Human-centric digital twin vision for smart societies. Publications Office of the European Union.

European Commission. (2023, July 10). Adequacy decision for the EU–US Data Privacy Framework. European Commission.

European Data Protection Board. (2017). Guidelines on Data Protection Impact Assessments (Art. 35 GDPR).

European Data Protection Board. (2018). Guidelines on automated individual decision-making and profiling (Art. 22 GDPR).

European Union. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). Official Journal of the European Union.

Fiore, U., Palmieri, F., & Castiglione, A. (2023). IoB in healthcare: Security and privacy implications. Future Generation Computer Systems, 142, 172–185.

Floridi, L., & Taddeo, M. (2016). What is data ethics? Philosophical Transactions of the Royal Society A, 374(2083), Article 20160360. https://doi.org/10.1098/rsta.2016.0360

Fuller, A., Fan, Z., Day, C., & Barlow, C. (2020). Digital twin: Enabling technologies, challenges and open research. IEEE Access, 8, 108952–108971. https://doi.org/10.1109/ACCESS.2020.2998358

Gomez-Uribe, C. A., & Hunt, N. (2016). The Netflix recommender system: Algorithms, business value, and innovation. ACM Transactions on Management Information Systems, 6(4), Article 13. https://doi.org/10.1145/2843948

Government of India. (2023). Digital Personal Data Protection Act, 2023 (No. 22 of 2023). Gazette of India, Ministry of Electronics and Information Technology.

Hamel, G., & Välikangas, L. (2003). The quest for resilience. Harvard Business Review, 81(9), 52–63.

Internet Freedom Foundation. (2020). Is Aarogya Setu privacy-first? An analysis. Internet Freedom Foundation.

International Organization for Standardization. (2017). Security and resilience—Organizational resilience—Principles and attributes (ISO 22316:2017).

International Organization for Standardization. (2019). Security techniques—Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management (ISO/IEC 27701:2019).

International Organization for Standardization. (2023). Consumer protection—Privacy by design for consumer goods and services (ISO 31700-1:2023).

Javaid, M., Haleem, A., Singh, R. P., Rab, S., & Suman, R. (2021). Internet of Behaviours (IoB) and its role in customer services. Sensors International, 2, Article 100122. https://doi.org/10.1016/j.sintl.2021.100122

Kraemer, M. U. G., Yang, C.-H., Gutierrez, B., Wu, C.-H., Klein, B., Pigott, D. M., du Plessis, L., Faria, N. R., Li, R., Hanage, W. P., Brownstein, J. S., Layan, M., Vespignani, A., Tian, H., Dye, C., Pybus, O. G., & Scarpino, S. V. (2020). The effect of human mobility and control measures on the COVID-19 epidemic in China. Science, 368(6490), 493–497. https://doi.org/10.1126/science.abb4218

Lengnick-Hall, C. A., & Beck, T. E. (2005). Adaptive fit versus robust transformation: How organizations respond to environmental change. Journal of Management, 31(5), 738–757.

Lupton, D. (2013). Self-tracking, health and medicine. Health Sociology Review, 22(3), 272–283.

Ministry of Electronics and Information Technology, Government of India. (2020a). Aarogya Setu: 100 million downloads milestone [Press release].

Ministry of Electronics and Information Technology, Government of India. (2020b). Aarogya Setu: Official release note. MeitY.

Moghaddam, M., Trovati, M., & Palmieri, F. (2022). Toward the Internet of Behavior: Modeling and applications [Preprint]. arXiv.

Mystakidis, S. (2022). Metaverse. Encyclopedia, 2(1), 486–497. https://doi.org/10.3390/encyclopedia2010031

National Institute of Standards and Technology. (2019a). Considerations for managing Internet of Things (IoT) cybersecurity and privacy risks (NISTIR 8228).

National Institute of Standards and Technology. (2019b). Developing cyber resilient systems: A systems security engineering approach (NIST SP 800-160, Vol. 2).

National Institute of Standards and Technology. (2020a). IoT device cybersecurity capability core baseline (NISTIR 8259A).

National Institute of Standards and Technology. (2020b). Privacy framework, Version 1.0 (NIST CSWP 01162020).

National Institute of Standards and Technology. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (NIST AI 100-1). https://doi.org/10.6028/NIST.AI.100-1

National Institute of Standards and Technology. (2024). AI RMF profile for generative AI (NIST AI 600-1).

National Institute of Standards and Technology. (2025). AI Risk Management Framework playbook. AI Resource Center. https://airc.nist.gov/AI_RMF_Knowledge_Base/Playbook

Nissenbaum, H. (2010). Privacy in context: Technology, policy, and the integrity of social life. Stanford University Press.

Nnamoko, N., Korkontzelos, I., Barrowclough, J., & Liptrott, M. (2022). CyberSignature: A user authentication tool based on behavioural biometrics. Software Impacts, 14, Article 100443. https://doi.org/10.1016/j.simpa.2022.100443

Organisation for Economic Co-operation and Development. (2019/2024). Recommendation of the Council on Artificial Intelligence (OECD AI Principles). OECD.

Panetta, K. (2020, October 19). Gartner top strategic technology trends for 2021. Gartner. https://www.gartner.com/smarterwithgartner/gartner-top-strategic-technology-trends-for-2021

Press Information Bureau, Government of India. (2020, May 26). Aarogya Setu is now open source [Press release].

Pulla, P. (2020). Mobile health apps in India: The case of Aarogya Setu. The Lancet Digital Health, 2(8), e388–e389. https://doi.org/10.1016/S2589-7500(20)30145-5

Raman, N. (2020). The Aarogya Setu app and data protection in India. Economic & Political Weekly, 55(21), 12–15.

Raman, N. (2021). Regulating behavioural surveillance in the digital era. International Data Privacy Law, 11(3), 225–235. https://doi.org/10.1093/idpl/ipab014

Rospigliosi, A. (2022). Metaverse as a virtual form of smart cities: Opportunities and challenges for technology, pedagogy and human interaction. Journal of Information, Communication and Ethics in Society, 20(3), 1–10. https://doi.org/10.1108/JICES-12-2021-0122

Salis, A. (2021). Towards the Internet of Behaviors in airports with a fog-to-cloud approach [Preprint]. arXiv.

Sharma, A. (2020). Security analysis of Aarogya Setu: Vulnerabilities and lessons [Preprint]. arXiv.

Sun, J., Gan, W., Chao, H.-C., Yu, P. S., & Ding, W. (2022). Internet of Behaviors: A survey. arXiv. https://arxiv.org/abs/2211.15588

Teece, D. J. (2007). Explicating dynamic capabilities: The nature and microfoundations of (sustainable) enterprise performance. Strategic Management Journal, 28(13), 1319–1350.

Thaler, R. H., & Sunstein, C. R. (2008). Nudge: Improving decisions about health, wealth, and happiness. Yale University Press.

Troncoso, C., Payer, M., Hubaux, J.-P., Salathé, M., Larus, J., Bugnion, E., Lueks, W., Stadler, T., Pyrgelis, A., Antonioli, D., Barman, L., Chatel, S., Paterson, K. G., Čapkun, S., Basin, D., Beutel, J., Jackson, D., Preneel, B., Smart, N. P., & Varia, M. (2020). Decentralized privacy-preserving proximity tracing [Preprint]. arXiv. https://arxiv.org/abs/2005.12273

UNESCO. (2021). Recommendation on the ethics of artificial intelligence. UNESCO.

U.S. Department of Commerce. (2023). Data Privacy Framework program overview.

Verhoef, P. C., Broekhuizen, T., Bart, Y., Bhattacharya, A., Dong, J. Q., Fabian, N., & Haenlein, M. (2021). Digital transformation: A multidisciplinary reflection and research agenda. Journal of Business Research, 122, 889–901. https://doi.org/10.1016/j.jbusres.2019.09.022

Wired. (2020). India’s contact-tracing app and mandatory usage debates. Wired.

Wijaya, E., Christian, J., Venna, C., Rowan, J., Surachman, I., Sellyna, & Oktavia, T. (2024). Examining the efficacy of the Internet of Behaviour (IoB) in the identification of client needs on electronic commerce platforms. Journal of Theoretical and Applied Information Technology, 102(8), 3451–3462.

Wymant, C., Ferretti, L., Tsallis, D., Charalambides, M., Abeler-Dörner, L., Bonsall, D., Hinch, R., Kendall, M., Milsom, L., Ayres, M., Holmes, C., Briers, M., & Fraser, C. (2021). The epidemiological impact of the NHS COVID-19 app. Nature, 594(7863), 408–412. https://doi.org/10.1038/s41586-021-03606-z

Zuboff, S. (2019). The age of surveillance capitalism: The fight for a human future at the new frontier of power. PublicAffairs.