GDPR

Reminder: Smart toys are cute, cuddly, and full of security risks

Today, kids have the chance to interact with their stuffed animals, robots, or dolls in ways their parents were only able to dream of. These toys, usually referred to as “smart” or “connected,” have built-in motion sensors, speakers, and microphones that allow them to analyze what children say and respond within seconds by searching an…


Today, kids have the chance to interact with their stuffed animals, robots, or dolls in ways their parents were only able to dream of. These toys, usually referred to as “smart” or “connected,” have built-in motion sensors, speakers, and microphones that allow them to analyze what children say and respond within seconds by searching an online database or the internet at large for an appropriate response. They learn children’s preferences and interests over time, so their play can become personalized, which may improve communication skills and has been found to for children with intellectual disabilities. But these toys also open up the internet to children as young as three, creating  a new digital frontier that parents and caregivers need to research, understand, and patrol. 

While you might have firm rules about what you share on social media, it’s harder to perceive smart toys as a potential threat, says Sophie Linington, deputy CEO of Parent Zone, a social enterprise that helps families safely navigate the internet. “You get lulled into a false sense of security, thinking, ‘Oh, it’s a cute teddy bear.’ But if it connects to the internet then the same kind of thinking needs to be done before you hand one over as with a tablet or a phone.”

You should be prepared to keep track of any recall notices and security upgrades for the life of the toy.

Smart toys can be hacked into and parents should also be aware that any information they collect may not be private. If a smart toy or game communicates with a child — whether by text or by “speaking” to them — those messages or recordings will be transmitted to an external database so they can be analyzed and responded to, and they will likely be stored so

Read More

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

GDPR

Tech Tuesday: Data privacy and synthetic data generation tools

Data has become simultaneously the most valuable asset most organisations own and the most heavily regulated one. GDPR fines exceeded €4.5 billion cumulatively by early 2026. The EU AI Act’s classification of training data quality as a high-risk system requirement has made data provenance a legal obligation rather than a best practice…

Data has become simultaneously the most valuable asset most organisations own and the most heavily regulated one. GDPR fines exceeded €4.5 billion cumulatively by early 2026. The EU AI Act’s classification of training data quality as a high-risk system requirement has made data provenance a legal obligation rather than a best practice…
Read More

Continue Reading
GDPR

Researcher reveals official White House app is one command away from tracking your precise location every 4.5 minutes – app can also inject code to dodge cookie consent, GDPR banners, and paywalls

White House app contains code to hide cookie options, GDPR banners, and paywalls – and collects extensive user data…

White House app contains code to hide cookie options, GDPR banners, and paywalls – and collects extensive user data…
Read More

Continue Reading
GDPR

Viva la revolución: LinkedIn profile visitor lists belong to the people, says Noyb

GDPR Article 15 doesn’t care if you want to make money by selling users’ data back to them A LinkedIn feature the average non-paying user likely only glances past could end up setting a legal precedent in the EU regarding how companies treat customer data that they’ve processed. …

GDPR Article 15 doesn’t care if you want to make money by selling users’ data back to them A LinkedIn feature the average non-paying user likely only glances past could end up setting a legal precedent in the EU regarding how companies treat customer data that they’ve processed. …
Read More

Continue Reading
GDPR

Estonia is the rare EU country opposing bans on children’s social media use

In short: Estonia and Belgium are the only two EU member states to have declined the Jutland Declaration, an October 2025 pan-European commitment to restrict children’s access to social media. Estonia’s ministers argue that age-based bans are unenforceable, that children will find ways around them, and that the correct approach is to enforce the GDPR against

In short: Estonia and Belgium are the only two EU member states to have declined the Jutland Declaration, an October 2025 pan-European commitment to restrict children’s access to social media. Estonia’s ministers argue that age-based bans are unenforceable, that children will find ways around them, and that the correct approach is to enforce the GDPR against […]
This story continues at The Next Web…
Read More

Continue Reading