PogoWasRight.org

Menu
  • About
  • Privacy
Menu

The Internet of Toys: Legal and Privacy Issues with Connected Toys

Posted on December 6, 2017June 25, 2025 by Dissent

Sara Jodka writes:

… Smart toys first sparked interest in 2015 when Hello Barbie a connected-smart doll was introduced. Hello Barbie came equipped with a microphone, voice recognition software and artificial intelligence that allowed a call-and-response function between the child user and the doll (think how Siri works). The backlash and hacking concerns loomed so large Hello Barbie got its own Twitter hashtag, #HellNoBarbie.

[…]

There are many reasons why these toys/wearables are problematic and the privacy issues for each are analyzed differently based on functionality. Some that function like the Amazon Echo, and unlike Smartphones, are always on, and blend into the background of their users’ daily lives. They also collect a significant amount of personal information, some of it legally-protected, especially in the context of information about children and/or from children. Many are so sophisticated they are able to adapt to a child user’s actions and process information from many sensors through the use of microphones, voice sensors, cameras, compasses, gyroscopes, radio transmitters, or Bluetooth. Connected toys connect to the Internet, which allows remote servers to collect data to power the toy’s intelligence functionality.

[…]

There are a number of issues to consider when discussing smart toys marketed to and used by children: the Children’s Online Privacy Protection Act (COPPA) and Federal Trade Commission (FTC) enforcement, the Family Educational Rights and Privacy Act (FERPA), the Health Information Portability and Accountability Act (HIPAA), state consent laws, constant connection, and, of course, privacy. Here is how it breaks down.

Read more on Dickinson Wright.

Related posts:

  • PSA: Internet-Connected Toys Could Present Privacy and Contact Concerns for Children
Category: BusinessFeatured NewsSurveillanceU.S.Youth & Schools

Post navigation

← Police in two states use hospitals to take motorists blood without a warrant
CIPPIC Granted Leave to Intervene in Data Case, BC v Philip Morris →

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • Slovenian officials weaponize data-privacy laws against investigative journalism
  • End-of-Year 2025 State and Federal Developments in Minors’ Privacy
  • Tool allows stealthy tracking of Signal and WhatsApp users through delivery receipts
  • Oh Great, Smart Glasses That Record Everything You Say
  • CBP Agents Held This U.S. Citizen for Hours Until He Agreed To Let Them Search His Electronic Devices
  • U.S. Plans to Scrutinize Foreign Tourists’ Social Media History
  • ANNOUNCEMENT: EFF Launches Age Verification Hub as Resource Against Misguided Laws

RSS Recent Posts at DataBreaches.net

  • ANNOUNCE: A new resource to help small and mid-sized HIPAA-regulated entities
  • Askul says 740,000 sets of data breached in cyberattack
  • Google and Apple roll out emergency security updates after zero-day attacks
  • Doxers Posing as Cops Are Tricking Big Tech Firms Into Sharing People’s Private Data
  • Virginia Urology Silent on Possible Data Breach as Purported Patient Data Begins to Leak
©2025 PogoWasRight.org. All rights reserved.