A connected toy is a small computer with a face. Before it can tell your child a story, it has to hear them, send what it heard somewhere, and bring an answer back. That is a data collection, and in the European Union a data collection involving a child is one of the most tightly regulated things a company can do. Most parents know the GDPR exists. Far fewer know that it hands them a specific, enforceable list of things they can demand from whoever made the toy sitting in their child's bedroom.
This article is about that list rather than the theory. What counts as personal data when a toy listens, who has to give consent, what you can ask for in writing, how long the company has to reply, and what to do when it does not. Everything below reflects the state of the rules on 11 September 2026, and each one is linked to its official text so you can check it rather than take our word for it.
What counts as a connected toy under the GDPR?
Any toy that collects information and sends it out of your home by Bluetooth, Wi-Fi or mobile data. France's data protection authority defines the category broadly and deliberately: dolls, robots, smartwatches, baby monitors and consoles all sit inside it, because what matters legally is the data leaving the house, not how cuddly the object is.
That definition is the reason a plush toy and a smart speaker are treated almost identically in law. The CNIL's guidance on securing connected toys warns that the reassuring shape is part of the problem: a teddy bear lowers a parent's guard in a way an identical microphone in a black plastic box would not. The legal test ignores the fur.
One practical consequence: a toy that works entirely offline, with no account and no server, falls largely outside this discussion. As soon as there is an app, an account or a cloud service, the GDPR applies to the company behind it, wherever that company is based, as long as it offers the product to people in the EU.
Is a child's voice personal data under the GDPR?
Yes, and this is the point everything else hangs on. A voice recording identifies the person who made it, so it is personal data in its own right, and the words inside it can contain far more: a first name, a school, an address, a family argument. The CNIL has stated plainly that voice is personal data and that the content of conversations held with a toy can reveal identifying information.
The European Data Protection Board went further for products of this kind. Its Guidelines 02/2021 on virtual voice assistants, adopted on 7 July 2021, conclude that a voice assistant service will very likely require a data protection impact assessment before launch, because it processes speech, often in a home, and often from people who never chose to be recorded. The UK regulator publishes a worked sample impact assessment for a connected toy, which is the closest thing to a public answer key for what a serious manufacturer should have written down before shipping.
Ask for that document. A company that has done the work can describe it in two sentences. If you want the wider picture first, we have written separately on what parents should know about AI toy safety and where a child's voice actually travels.
Who gives consent, the child or the parent?
For a child of primary school age, the parent. Article 8 of the GDPR sets sixteen as the default age at which a young person can consent on their own to an online service. Member States were allowed to lower it, never below thirteen, and France set it at fifteen. So for the three to twelve age range, consent has to come from the holder of parental responsibility, full stop.
In practice that means a real parent account. A tick box on the toy itself, or an age field a six year old can type anything into, does not satisfy the article. The Board's Statement 1/2025 on age assurance lists ten principles for doing this properly, and its core instruction is a balancing act: verify age with the least intrusive method that works, and protect whatever you collect in order to verify it.
Consent is also not the only thing worth checking. Companies sometimes rely on contract or legitimate interest instead. The privacy policy has to tell you which legal basis covers which processing, and if it does not, that omission is itself a compliance failure you can raise.
What can a parent actually demand from the manufacturer?
Six things, in writing, free of charge, and the company has one month to answer. These are not favours a good company grants. They are obligations, and the exercise of them is the most useful thing a parent can do with a privacy policy they do not have time to read.
| What you can ask for | GDPR article | What the company has to do |
|---|---|---|
| A copy of everything held about your child | Article 15 | Hand over the data and explain the purposes, the recipients and how long it is kept |
| Correction of anything wrong | Article 16 | Fix it without undue delay |
| Deletion | Article 17 | Erase the data, and pass the request on to anyone it was shared with |
| A portable copy | Article 20 | Provide it in a structured, machine readable format |
| A stop to a particular use | Article 21 | Stop, unless it can demonstrate compelling legitimate grounds |
| An answer, on the clock | Article 12(3) | Reply within one month, extendable by two more for genuinely complex requests, and say why |
Two more deadlines are worth memorising. If the company suffers a data breach, Article 33 gives it seventy two hours to notify the supervisory authority, and Article 34 requires it to tell affected families without undue delay when the risk to them is high. A manufacturer that cannot state its own breach notification process when asked has probably not written one.
If a request is ignored or refused, the next step is free and takes about ten minutes: file a complaint with your national authority. In France that is the CNIL. The threat of that complaint is usually more effective than the complaint itself. For what a product built around these obligations from the start looks like, we have described what privacy by design actually changes inside a product rather than in its marketing.
What happened when a toy maker got this wrong?
The clearest French case is nearly a decade old and still the best teaching example. In November 2017 the CNIL publicly ordered Genesis Industries Limited, maker of the My Friend Cayla doll and the i-Que robot, to fix the security of both toys, giving the company two months. The regulator made the notice public specifically because of the vulnerability of the people affected.
The technical finding is the part parents remember. Someone standing roughly nine metres away, outside the building, could pair a phone with the toy over Bluetooth without any authentication at all: no PIN, no button press on the toy. Anyone within range could listen through it, or speak through it. Germany's telecommunications regulator reached the same conclusion and banned the doll outright. The CNIL later closed the procedure against Genesis Industries once the problems were addressed.
Here is the honest limit of all this. Every rule above was written after a failure, not before it, and enforcement against a small manufacturer selling through a marketplace from outside the EU is slow. The GDPR gives a French parent real leverage against a company with a European presence. Against an anonymous seller with no address, it gives them a complaint form and patience. That asymmetry is a genuine reason to weigh who is selling a toy as heavily as what the toy does.
What changes with the EU's new toy safety rules?
A second layer arrives, slowly. Regulation (EU) 2025/2509 on the safety of toys entered into force on 1 January 2026 and becomes fully applicable on 1 August 2030. It covers every toy placed on the EU market for children under fourteen, connected ones included.
Two provisions matter to this discussion. Internet connected toys acquire explicit cybersecurity obligations, which turns the Cayla style pairing flaw from a scandal into a breach of product law. And every toy model gets a digital product passport, reachable from a QR code on the packaging, which replaces the paper declaration of conformity and has to stay available for ten years. In principle a parent will be able to scan a box and read the compliance file.
In principle, and in 2030. Until then the certifications a manufacturer lists are voluntary claims that you have to ask them to substantiate, which is exactly the situation described in our piece on the checklist a draft American law turns into parent questions. Meanwhile the European Data Protection Board has made children's data a strategic priority and is preparing dedicated guidelines on processing children's data, announced again in January 2026.
How do you check a toy before you buy it?
The CNIL publishes a short pre purchase list, and it is better than most commercial buying guides because it assumes nothing about the brand. It is reproduced below in the regulator's own logic, and it takes about five minutes against a product page.
The regulator's pre purchase questions
- Can just anyone connect to it? Pairing should require a physical button on the toy or a password. This is the exact flaw that got a doll banned.
- Is there a visible signal when it is listening or transmitting? A light, or something equivalent.
- Are the terms in your language, and readable? Is the data reused for other purposes or passed to partners?
- Where is the data hosted? Inside the EU, or in a country with weaker protection?
- Is there a contact address for exercising your rights? If you cannot find one, you cannot use any of the six rights above.
- Can you access and delete the data yourself? And can you switch off the functions you do not want?
The CNIL also suggests a habit that costs nothing: create a dedicated email address for your child's toys, use a nickname rather than a real first name, and give only the minimum at sign up.
We built Ted to answer that list without needing a phone call. There is no camera, only a microphone and a speaker, which removes an entire category of data from the conversation. Setup runs through a parent account in the Ted&Co app, where the parent sets the Wi-Fi, the language, the topics, the limits, the tone and the choice between push to talk and automatic listening. Language switching is manual and stays in the parent's app: Ted never changes language by itself mid conversation. It is a one off purchase at 129 euros with no subscription, so nothing in the business model depends on how long a child keeps talking. The certification list, including GDPR and COPPA alignment, is on our security page, and what we store is set out in the FAQ. Run the six questions against those pages rather than against this paragraph.
One last piece of honesty. Child safety organisations that have tested this category report serious failures across it, and none of them endorses any product, ours included. Their position is that the category as a whole is not ready. Ours is that nearly every failure they document is a design decision rather than a property of the technology, and that a parent armed with the six questions above can tell the two apart faster than any regulator can.
Frequently asked questions
Does the GDPR apply to a toy made outside Europe?
Yes, if the company offers the product to people in the European Union. Territorial scope follows the customer, not the head office. In practice, enforcement is much slower against a company with no European entity and no published address, which is a good reason to check that a contact address for data requests exists before you buy.
How do I get a company to delete my child's recordings?
Send a written request citing Article 17 of the GDPR to the contact address in the privacy policy, state that the person concerned is a minor in your care, and ask for written confirmation once done. The company has one month to reply. If it does not, file a complaint with your national data protection authority, which is free.
At what age can a child consent on their own in France?
Fifteen. The GDPR sets the default at sixteen and lets Member States lower it to no less than thirteen, and France chose fifteen. For a child aged three to twelve, consent must come from a parent or legal guardian, which is why any serious product in this category requires a parent account rather than a setting on the toy itself.
Should the toy work without an internet connection?
It depends what you want from it. A toy that works fully offline sends nothing anywhere, which removes most of the questions in this article. A conversational toy needs a connection to answer, so the question becomes what happens to the audio at the other end, how long it is kept, and whether you can delete it. Both designs can be defensible. Only one of them requires you to read a privacy policy.
What does the digital product passport change for parents?
From 2030, every toy model sold in the EU will carry a data carrier, typically a QR code, linking to its compliance file in the relevant language, kept available for ten years. It replaces the paper declaration of conformity. Before then, certification claims remain claims, and asking a manufacturer to produce the underlying documents is still the only way to test them.
Sources
- Regulation (EU) 2016/679, the General Data Protection Regulation, official consolidated text
- CNIL, connected toys: advice on securing them
- CNIL, closure of the formal notice procedure served on Genesis Industries Limited
- European Data Protection Board, Guidelines 02/2021 on virtual voice assistants, adopted 7 July 2021
- European Data Protection Board, Statement 1/2025 on age assurance
- European Data Protection Board, Data Protection Day 2026, keeping children's personal data safe online
- Regulation (EU) 2025/2509 on the safety of toys
- Information Commissioner's Office, sample data protection impact assessment for a connected toy
Legal state of play described in this article verified on 11 September 2026.