Of these, the worst are the "embedded" ones: the IoT lightbulbs and the Razer devices. Nobody ever expected their lightbulbs to be processing personal data on behalf of third parties. The one that might be legitimate is the "cheap flights" one; after all, they require your consent for email marketing, and they can't offer you a discount flight without it.
If the definition of personal data includes IP addresses then I'd be surprised there are any internet-connected products that don't process personal data in some way.
Yes it does.
> I'd be surprised there are any internet-connected products that don't process personal data in some way.
Consent is one of six lawful grounds for processing personal data. Another ground is legitimate interests, described in Article 5 as follows:
"Processing shall be lawful if... processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child."
https://gdpr-info.eu/art-6-gdpr/
Recital 49 goes on to state:
"The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system to resist, at a given level of confidence, accidental events or unlawful or malicious actions that compromise the availability, authenticity, integrity and confidentiality of stored or transmitted personal data, and the security of the related services offered by, or accessible via, those networks and systems, by public authorities, by computer emergency response teams (CERTs), computer security incident response teams (CSIRTs), by providers of electronic communications networks and services and by providers of security technologies and services, constitutes a legitimate interest of the data controller concerned. This could, for example, include preventing unauthorised access to electronic communications networks and malicious code distribution and stopping ‘denial of service’ attacks and damage to computer and electronic communication systems."
Logging IPs for a reasonable period of time as part of your network security infrastructure is perfectly permissible under GDPR without consent. You can share your server logs with a third-party security company or pass data to a DDoS protection service if needed. If you use those IPs for any other purpose (ad tracking, analytics etc) then you'll need lawful grounds for those activities, which may or may not require consent.