For corporations considering immersive technologies, however, the issue goes considerably further than personal privacy. There are really two assets that need to be protected:
- the individual
- the corporation itself.
An employee using an immersive device may generate data about movement, behaviour and interaction.
At the same time, the device may be operating inside an office, factory, laboratory, training centre or research environment containing proprietary processes, equipment, documents, layouts, workflows and intellectual property.
That changes the procurement question.
When a corporation purchases an immersive device, what exactly is it purchasing — and what is it potentially allowing into its environment?
A specification sheet tells only part of the story
We have become very good at comparing technology by specification.
- How fast is the processor?
- What is the screen resolution?
- How much storage does it have?
- Does it track hands?
- Does it have cameras?
- Does it map its surroundings?
- How many degrees of freedom does it support?
Those are legitimate questions. But they are no longer sufficient.
A corporation is not simply purchasing a piece of hardware containing a processor and display.
Increasingly, it is joining an ecosystem.
That ecosystem may include:
- user accounts
- cloud services
- software stores
- analytics
- telemetry
- subscriptions
- online identity systems
- automatic updates
- device-management platforms
- data-processing arrangements
- third-party services
Some of those relationships may continue for years after the hardware has been purchased. So corporate procurement requires another set of questions.
- Who operates the ecosystem?
- What information does the system require?
- What information can it collect?
- Where is that information processed?
- Does the training objective actually require that data to exist?
- Can the device perform its intended function without sending information outside the organization?
- What can the device perceive about the environment in which it is being used?
- What happens to that information?
These are not anti-technology questions. They are responsible corporate governance questions.
VR raises the stakes
A conventional computer can know quite a lot about what a person does. Immersive technology can potentially know something different:
- how that person moves.
That distinction matters.
A Scientific Reports study involving 511 participants found that researchers could identify approximately 95% of participants using less than five minutes of typical VR tracking data. The researchers concluded that non-verbal tracking data should be considered personally identifying information.
A much larger study presented at the 2023 USENIX Security Symposium examined 55,541 VR users.
After training on five minutes of motion per person, researchers were able to identify an individual from the entire group with 94.33% accuracy using only 100 seconds of head-and-hand motion data.
In other words, movement itself can begin to function like a biometric identifier.
This does not mean VR is inherently unsafe. It means that VR data deserves to be treated with the same seriousness as other forms of sensitive information.
Why collect the data at all if the application does not require it?
Corporate privacy is only half of the equation
For a corporation, the user is not the only thing worth protecting.
Consider where an immersive device might eventually be used:
- a manufacturing floor
- an R&D laboratory
- an engineering department
- a prototype facility
- a training centre
- a maintenance environment
- a design studio
- an office
- a restricted production area
These environments may contain information the corporation would never knowingly place on a public server.
- Equipment configurations.
- Prototype products.
- Production layouts.
- Manufacturing processes.
- Maintenance procedures.
- Computer screens.
- Technical documentation.
- Internal signage.
- Operational workflows.
- And simply the physical arrangement of a facility.
A sophisticated immersive device may require cameras, environmental sensing, spatial mapping or continuous connectivity to deliver particular capabilities.
Those capabilities may be entirely justified for some applications.
But corporations should not assume that because a device can perceive something, it should be allowed to perceive it everywhere.
The question becomes:
What information about our people and our environment must this system acquire in order to perform the task we are asking it to perform?
That is both a privacy question and an intellectual-property question.
This is not an argument against sophisticated VR
That distinction is important. Modern 6 DoF immersive systems are extraordinarily capable. There are corporate applications where positional tracking, hand tracking and detailed physical interaction are genuinely valuable.
- A technician practicing a complex physical procedure may require them.
- A designer evaluating spatial relationships may require them.
- A safety exercise involving movement through a physical environment may require them.
- A highly skilled procedural simulation may require them.
In those circumstances, the additional capability may easily justify the additional complexity. The issue is not whether advanced immersive technology is useful.
Clearly it is.
The question is whether every immersive application requires every available capability.
A company should consider the hardware, certainly. But it should also consider the platform, ecosystem, data architecture and business model surrounding that hardware. We already apply this thinking to other corporate systems.
A corporation would not select an enterprise information system solely because its user interface looked better.
- It would ask where its information was stored.
- It would not adopt a cloud platform solely because it offered more features.
- Its IT and security teams would want to understand access, control and data flows.
- It would not install cameras throughout an R&D facility merely because the cameras had outstanding resolution.
- It would first ask why those cameras were necessary.
Immersive technology should receive the same scrutiny.
Capability is not the same as necessity
This is where technology procurement can sometimes lose its way.
- If a device can track something, there is a tendency to assume that tracking it adds value.
- If a platform can connect continuously to the internet, connectivity becomes the default.
- If software can gather analytics, analytics become expected.
- If hardware can map a room, track hands, understand movement and maintain an online identity, those capabilities begin to look automatically desirable.
But a corporation has a different test.
Does this capability improve the outcome enough to justify its cost, complexity, privacy implications and potential exposure of corporate information?
Sometimes the answer will unquestionably be yes.
But not always.
If the objective is to place an employee inside a machine they could never safely enter, allow them to observe a manufacturing process, understand an engineering concept, experience a dangerous environment safely, learn a procedure or become familiar with a facility, the requirement may simply be presence and understanding.
That is a different problem from precise physical simulation. Different problems need not require identical technology.
Data minimization should become a corporate principle
The approach is remarkably simple:
- Collect what the task requires.
- Not what the hardware makes possible.
- Not what might be useful someday.
- Not everything that happens to be available through an API.
- Only collect what the task requires.
If an instructor needs to know whether an employee completed a training module, understood a safety procedure or answered an assessment correctly, collecting that information has a clear business purpose.
That does not automatically create a requirement to collect:
- detailed biomechanical movement
- continuous positional data
- environmental imagery
- room maps
- unrelated application activity
- behavioural patterns outside the training objective
We should be able to distinguish training telemetry from human telemetry.
And in a corporate setting, we should add another distinction:
- operational information vs corporate environmental data.
The more sophisticated immersive devices become, the more important those distinctions will become.
Intellectual property should be part of the VR discussion
Corporate IP protection is often discussed in relation to laptops, USB storage, cloud services, mobile phones and cameras.
Immersive hardware deserves to join that discussion.
The purpose is not to suggest that every device is extracting proprietary information.
It is to recognize that modern immersive hardware may possess sensors and connectivity capable of acquiring information that would be commercially sensitive if it left the organization.
A procurement team should therefore understand not simply what a device is capable of displaying. It should understand what the device is capable of seeing, sensing, recording, inferring and transmitting.
This becomes especially important in manufacturing and R&D environments, where seemingly ordinary environmental information can reveal significant commercial knowledge.
- A factory layout can contain know-how.
- A production sequence can contain know-how.
- The positioning of equipment can contain know-how.
- A prototype sitting in the background can contain know-how.
How experienced employees physically perform a specialized task can itself represent organizational knowledge developed over decades.
The question therefore cannot simply be:
Is our data encrypted?
A more fundamental question comes first:
- Did this information ever need to be collected?
The procurement question needs to change
Technology procurement often begins with:
What can this device do?
Perhaps the better starting point is:
What do we need this device to do?
Only after answering that question should an organization decide how much technology, connectivity, tracking and complexity are justified.
This philosophy shaped Sensible-VR.
Our default approach is offline. We do not begin with the assumption that users need to be tracked. Where training telemetry is valuable, our position is that it should be limited to what is genuinely required to support the training objective.
- Assessment score? Absolutely.
- Completion status? Of course.
- Detailed biometric or behavioural inference simply because the device makes it technically possible? That requires a much stronger justification.
That does not make us anti-data. It makes us pro-purpose.
The same philosophy applies to hardware. We believe simpler 3 DoF VR and more sophisticated 6 DoF VR both have legitimate roles.
The right tool depends upon the objective. If accurate physical interaction is essential, use the technology capable of providing it. If it is not essential, additional sensing, tracking and complexity should not automatically be considered an advantage.
More capability is valuable when the capability is needed.
Unnecessary capability can become unnecessary cost, unnecessary complexity and unnecessary exposure.
Privacy and IP protection should be designed in, not added later
For large organizations, cybersecurity and intellectual-property protection are already part of normal business.
Immersive technology should not sit outside that framework merely because the hardware is new.
Procurement teams, information-security teams, instructors and business leaders should be asking questions that go beyond resolution, processing power and price.
- What data does this system actually need?
- What can its sensors perceive?
- Where is information processed?
- Can the application operate offline?
- Who controls the ecosystem?
- What ongoing obligations are being created for IT?
- What information about our employees could be generated?
- What information about our facilities or operations could be generated?
- Can we achieve the same objective with less collection and less complexity?
- Are we selecting capabilities because the task requires them, or simply because the hardware offers them?
The goal is not to fear sophisticated technology. It is to deploy sophisticated technology deliberately.
A corporate procurement decision is no longer simply a hardware decision. It is a decision about the privacy of the people using the technology. It is a decision about the protection of the organization employing them.
And increasingly:
It is a decision about what, and whom, a corporation is willing to invite inside its walls.
Sources
Miller, M. R. et al., Scientific Reports 10, 17404 (2020).Personal identifiability of user tracking data during observation of 360-degree VR video. Study of 511 participants showing high identifiability from VR tracking data and examining the reduced but still measurable identifiability of rotational-only tracking. (Nature)
Nair, V. et al., 32nd USENIX Security Symposium (2023), pp. 895–910.Unique Identification of 50,000+ Virtual Reality Users from Head & Hand Motion Data. Study of 55,541 users showing 94.33% identification accuracy from 100 seconds of motion after training on five minutes per user. (USENIX)

