Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

FTC Focusing on Privacy Risks of Interconnected Toys

By Stephanie Crawford on July 24, 2017
Email this postTweet this postLike this postShare this post on LinkedIn
© Getty Images

Fuzzy talking toys are no longer the annoying, yet benign Christmas gifts they used to be. Many of today’s toys, like refrigerators, cars, and televisions, are “smart,” and may come gift-wrapped with all of the emerging cybersecurity risks the internet has to offer. And as various government agencies grapple with the regulation and enforcement of smart products, the Federal Trade Commission (“FTC”) may be narrowing in on smart toy manufacturers as a potential target. The FBI and FTC issued separate alerts last week highlighting potential threats posed by cuddly friends that collect children’s voices and other identifying information and putting manufacturers on notice of potential enforcement actions for failure to comply with the Children’s Online Privacy Protection Act (“COPPA”), respectively.

The FTC issued COPPA guidance on July 21 – on the heels of the FBI’s internet-connected toys threats warning and mitigation recommendations issued July 17. While the FBI notice alerted consumers to the protections afforded by COPPA, the FTC has updated its step-by-step COPPA compliance guidance for smart toy manufacturers, specifically including “connected toys or other Internet of Things devices” in its definition of “website or online services” which must comply with COPPA. COPPA requires operators of websites and online services directed to children under the age of 13 or who are collecting personal information online from children under 13 to take certain disclosure, parental consent, and security precautions. Personal information includes, but is not limited to, full names, addresses, user or screen names, and photos and audio files of a child or a child’s voice.

Manufacturers that market their inter-connected toy products to children under the age of 13 or whose products are known to be used by children under 13 should be taking the following actions in accordance with FTC guidance:

  1. Determine whether their products are collecting “personal information” of children;
  2. Provide a sufficient privacy policy;
  3. Notify parent’s directly about the company’s information practices before collecting a child’s personal information;
  4. Obtain verifiable parental consent before collecting a child’s personal information;
  5. Honor parents’ ongoing decisions to revoke consent, refuse further use of a child’s information, or delete a child’s personal information; and
  6. Establish reasonable data confidentiality, security, and integrity procedures including holding information only for so long as it is needed for the reason it was collected, disposing of information, and disposing of information securely.

The flurry of legislative, regulatory and enforcement activity surrounding smart toys and the protection of children’s information – including Senator Mark Warner’s letter to the FTC expressing smart toy privacy concerns, consumer advocate pressure, and the FTC and FBI responses – indicates that a government enforcement effort in this area may be on its way.

Photo of Stephanie Crawford Stephanie Crawford

Stephanie Crawford is a trusted counselor to a broad range of industries facing reorganizations, transactions, national security issues, and questions of supply chain management. Stephanie provides related mergers and acquisitions, counseling, litigation, international arbitration, and investigations services to clients in the aerospace and

…

Stephanie Crawford is a trusted counselor to a broad range of industries facing reorganizations, transactions, national security issues, and questions of supply chain management. Stephanie provides related mergers and acquisitions, counseling, litigation, international arbitration, and investigations services to clients in the aerospace and defense, communications, energy, information technology, and consumer products sectors.

Stephanie has substantial experience with both buy-side and sell-side transactions. She has led government contracts diligence for numerous private equity entities and defense contractors. She assists clients with navigating post-closing government requirements, including unique license transfers and approvals; novation and change of name regulations; and Defense Counterintelligence and Security Agency communications and foreign ownership, control, and influence (FOCI) mitigation.

Stephanie counsels clients on supply chain, sourcing, and national security regulations and requirements. Such counseling includes compliance with the Defense Production Act, including priority orders, ratings and associated regulations; the Public Readiness and Emergency Preparedness Act; and National Industrial Security Program Operating Manual (NISPOM) regulations. She is also known for her ability to solve immediate and business-threatening System for Award Management (SAM) and Defense Logistics Agency (DLA) CAGE Code problems.

Stephanie defends government contractors facing potential tort litigation with a nexus to their government contracts and facing supply chain and national security-related investigations, litigation, and arbitrations.

Stephanie’s pro bono practice focuses on a broad range of veterans’ issues, including disability ratings and discharge upgrades

Read more about Stephanie CrawfordEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Retail & Consumer Products Law Observer
  • Organization:
    Crowell & Moring LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo