
The play
Some connected toys are built around a screen-based app; others, like a talking teddy bear with a hidden microphone, are not screen-based at all once set up. The UK Information Commissioner's Office addresses both in standard 14 of its Children's code, a statutory code of practice on how UK data protection law applies to online services likely to be accessed by children. The code defines a connected toy or device as a physical product whose functionality depends on an internet connection, giving the example of a talking teddy bear with a microphone that records what a child is saying and sends that data back to the provider's servers.
What the evidence says
The code's own text, retrieved 16 September 2026, sets out specific expectations. It says a provider should give clear information that a product processes personal data at the point of sale, ideally through packaging or an icon, and should let a buyer read the privacy terms online before purchase rather than after opening the box. On recording, it states that a provider should provide features that make it clear to the child or a parent when personal data is being collected, such as a light that activates during recording, and that where a toy uses a standby or listening mode, it should give a clear indication that listening mode is active and, in the code's own words, should not collect personal data in listening mode. The code's introduction frames all 15 standards, including this one, as flexible expectations built on UK data protection law rather than a product certification scheme.
Age fit and safety
The code does not assign an age range to connected toys as a category; its standards apply to any service likely to be accessed by children, with a separate annex addressing age and developmental stages generally. For this standard specifically, the safety signal is behavioral rather than age-banded: a conforming design should make listening visible and give a way to disconnect, regardless of the child's age.
What to look for
This is an editorial checklist drawn from the standard's own wording, not a compliance audit of any product. A caregiver cannot verify code conformance from a shelf; only a manufacturer's own privacy documentation, read against the standard's language, can suggest whether a given toy meets it.
- Does the toy or its packaging disclose, before purchase, that it connects to the internet and processes personal data?
- Is there a visible or audible signal when the toy is actively listening or recording?
- Can the toy's connectivity or listening mode be switched off and still leave a usable, non-connected toy?
None of this substitutes for reading a specific product's own privacy policy against these standards; the code sets the expectation, not the verification.
Sources & reading trail
States the code's own expectations for point-of-sale privacy disclosure, listening-mode indicators, and connectivity controls for connected toys.
Source published: Not established · Retrieved: 16 September 2026
Describes the code as a statutory code of practice of 15 flexible standards covering apps, games, connected toys, and websites likely to be accessed by children.
Source published: Not established · Retrieved: 16 September 2026
Standards, recall notices, studies and records establish the entry; the what-to-look-for reading is Toy Almanac editorial analysis. This retrospective draft does not imply the site published on the event date.