Comcast Router Motion Detection Feature Turns Home Wi‑Fi into Motion Sensors, Potentially Sharing Data with Law Enforcement
What Happened — Comcast has added an opt‑in “Wi‑Fi Motion” capability to its Xfinity Gateway routers. The feature monitors radio‑frequency changes between the gateway and connected devices to infer movement and pushes alerts to the Xfinity mobile app. A footnote in the rollout documentation states that law‑enforcement agencies could request access to the collected motion‑event data.
Why It Matters for Compliance & Audit Readiness
- The motion‑event logs constitute personal data under GDPR, CCPA and similar regimes; SOC 2 CC 5.2 (Privacy) requires documented consent and clear data‑retention policies.
- Organizations that rely on Comcast for connectivity must be able to demonstrate that any third‑party‑derived data (e.g., motion alerts) is handled in accordance with their own privacy controls and that they can produce audit‑ready evidence of consent and lawful basis.
- Verisq’s CookiePLUS capability helps you capture consent artifacts, map motion‑data flows, and generate the continuous evidence needed for a defensible SOC 2 privacy audit.
Who Is Affected — Residential broadband customers of Comcast; indirectly, any business that uses Comcast’s Xfinity Gateway as its primary internet connection (e.g., small‑office/home‑office environments).
Recommended Actions
- Review the Xfinity Shield terms and update your organization’s privacy policy to reflect any third‑party motion‑data collection.
- Implement a consent‑capture workflow for any employee devices that may be subject to the motion‑detection feature.
- Add the motion‑event log source to your continuous‑control monitoring platform and retain logs for the period required by your SOC 2 privacy controls.
- Conduct a Data Subject Access Request (DSAR) readiness test to ensure you can respond if a user asks for the motion‑data stored about them.
Source: ZDNet Security
Technical Notes
- Detection method: analysis of RF signal variance between the gateway and Wi‑Fi‑connected devices; no video or image capture.
- Data type: timestamped motion‑event metadata (e.g., “motion detected at 14:32 UTC”).
- No known CVE or vulnerability; the privacy impact stems from the feature’s design and the disclosed law‑enforcement access clause.
Source: ZDNet Security