Connected Toys: Toy, Radio Product, Cyber Product or Several at Once?
A connected toy can sit under toy safety, radio and cybersecurity rules at once. See what the 2030 Toy DPP does and what it does not replace.
Navigate this page
- Overview
- Why "connected toy" is a boundary problem
- Which facts decide the route?
- Which regimes can apply?
- Does a connected toy have a DPP?
- Why the single-passport rule matters
- Which data belongs to which layer?
- Five boundary examples
- Ask these questions before deciding
- What is settled
- What remains product-specific
- What would change this page
- Where this connects
- Sources / legal basis
A connected toy can be a toy, radio product and product with digital elements at the same time. Those labels answer different legal questions. One does not automatically cancel the others. The toy layer now has an unusually clear future Digital Product Passport position. Regulation (EU) 2025/2509 requires manufacturers to create a DPP for an in-scope toy before placing it on the market once the Regulation applies from 1 August 2030. Connectivity adds separate questions. A toy using Bluetooth, Wi-Fi or another intentional radio function can fall within the Radio Equipment Directive. Cybersecurity-related RED requirements already apply to specified radio toys and internet-connected radio equipment. The Cyber Resilience Act adds a separate product-with-digital-elements framework, with Article 14 applying from 11 September 2026 and the Regulation generally applying from 11 December 2027. So the useful answer is:
The Toy DPP is the toy's passport layer. It does not replace the need to classify the toy's radio, software, cyber, battery or other regulated layers.
For the complete toy passport requirements, use Toy Digital Product Passport Requirements. This page owns the narrower question of what changes when the toy is connected.
Why "connected toy" is a boundary problem
A commercial label such as "smart toy" can describe products with very different functions:
- a battery-powered toy with no connectivity
- a Bluetooth toy controlled by a phone
- an internet-connected doll that speaks to a child
- a toy with a camera or microphone
- a toy with location tracking
- a connected construction kit with programmable hardware
- a toy with an AI-enabled function.
The fact that all of them are sold as toys does not tell you whether every technical layer has the same legal treatment.
The new Toy Safety Regulation itself makes this separation explicit. Its recitals say radio toys are to comply with relevant radio/privacy requirements, toys with digital elements are to comply with the Cyber Resilience Act and toys with relevant AI systems are to comply with the AI Act. The toy law therefore does not pretend to absorb every connected-product rule into one instrument.
It does, however, create a DPP architecture designed to interact with those other rules. That is the point to understand.
Which facts decide the route?
1. Is it legally a toy?
Start with toy scope, intended use, target users and exclusions.
Do not assume that a children's electronic product is automatically a toy. Equally, do not assume that adding connectivity removes a product from toy law.
The Toy DPP page is the canonical owner for the adopted toy passport requirements once toy scope is established.
2. Does it intentionally use radio?
Bluetooth, Wi-Fi, cellular and other intentional radio functions can bring the Radio Equipment Directive into the map.
For specified radio equipment, Commission Delegated Regulation (EU) 2022/30 applies cybersecurity-related RED essential requirements. After amendment, that Regulation has applied from 1 August 2025.
Its personal-data/privacy limb expressly includes radio equipment covered by the Toy Safety Directive where the stated data-processing condition is met. Its network-protection limb applies to internet-connected radio equipment generally.
3. Does it connect to the public internet?
This matters for both the current RED cybersecurity layer and the CRA classification.
Commission Implementing Regulation (EU) 2025/2392 describes a specific category of internet-connected toys that are covered by toy law, communicate on the public internet and have either:
- social interactive features, such as speaking or filming, or
- location-tracking features.
Where the stated conditions are met, those products are classified as important products with digital elements under the CRA framework.
That does not mean every Bluetooth toy is in that specific class. The exact connectivity and feature set matter.
4. What software and cloud functions exist?
Record:
- embedded firmware
- companion app
- cloud service
- remote commands
- software updates
- microphones/cameras
- account or authentication functions
- location tracking
- whether the product can communicate directly or indirectly over the internet.
Those facts can change the cyber and data architecture even when the physical toy model is unchanged.
5. Does it contain a battery?
The battery needs its own classification.
A rechargeable toy does not automatically need a Battery Passport. The passport applies from 18 February 2027 only to the categories identified in Article 77 of the Battery Regulation. Many ordinary portable batteries inside toys are outside that passport scope even though other battery obligations apply.
Use Battery Digital Product Passport Requirements rather than importing the full battery rulebook into the toy classification.
6. Does it use AI in a way that creates a separate regulatory layer?
The Toy Safety Regulation expressly recognises that toys incorporating AI can also have AI Act obligations.
This page does not classify a toy's AI system. The point is narrower: the Toy DPP does not prove that every other connected-product classification has been completed.
Which regimes can apply?
| Product fact or layer | Possible regime | When it applies | What it changes |
|---|---|---|---|
| Toy host | Regulation (EU) 2025/2509 | Product is an in-scope toy | Toy safety, conformity and an adopted model-level DPP architecture from 1 August 2030 |
| Intentional radio | Radio Equipment Directive | Toy intentionally emits/receives radio waves within RED scope | Radio conformity and technical-documentation obligations |
| Internet-connected radio | RED Delegated Regulation 2022/30, as amended | Relevant radio equipment can communicate over the internet | Current network-protection essential requirement, subject to scope |
| Radio toy processing specified personal/traffic/location data | RED Delegated Regulation 2022/30, as amended | Toy-radio equipment meets the stated data condition | Current privacy/data-protection-related RED essential requirement |
| Product with digital elements | Cyber Resilience Act | Connected hardware/software falls within CRA scope | Cybersecurity lifecycle and reporting obligations on the CRA timetable |
| Internet-connected toy with social interactive or location-tracking features | CRA Implementing Regulation 2025/2392 | All stated criteria are met | Specific important-product classification under CRA |
| Battery | Battery Regulation | Battery category and host-product design | Battery-specific product/design/information duties; passport only for specified battery categories |
| Electronic equipment | RoHS/WEEE where scope is met | Toy/electronic layer meets EEE definitions | Substance, conformity and end-of-life evidence/data |
| AI function | AI Act where its scope/classification is met | Depends on the AI system and its role | Separate AI compliance layer, not replaced by the toy DPP |
Does a connected toy have a DPP?
Toy host: ADOPTED, APPLIES LATER
Yes, for in-scope toys under Regulation (EU) 2025/2509 once that Regulation applies from 1 August 2030.
Article 19 requires the manufacturer to create a DPP before placing the toy on the market. The passport corresponds by default to a specific toy model and contains at least the data set in Annex VI.
The detailed toy dataset, access and implementation belong in Toy Digital Product Passport Requirements. This page does not duplicate them.
Connected/cyber layer: REQUIRED UNDER OTHER LAW WHERE TRIGGERED
The connected-product obligations are separate from the fact that a toy DPP exists.
For relevant radio toys, some RED cybersecurity requirements are already in application. Under the CRA, Article 14 begins applying on 11 September 2026 and general application is 11 December 2027.
Battery: COMPONENT-ONLY POSSIBILITY
The battery inside the toy has its own status. A Battery Passport is not created by the toy's 2030 DPP and is not automatic for an ordinary portable battery.
Future overlap: ONE PASSPORT CAN CARRY MULTIPLE LEGAL DATA SETS
The Toy Safety Regulation anticipates overlap with other Union law.
It says that where other Union law requires a DPP for toys, a single DPP is to contain the information required by the Toy Safety Regulation and that other law. It also allows the toy DPP to contain the information needed for declarations of conformity under other listed legislation, including the CRA, RoHS and RED.
That is an interoperability rule. It does not mean the Toy Safety Regulation replaces those laws.
Why the single-passport rule matters
Businesses can make two opposite mistakes.
Mistake 1: "The Toy DPP covers everything"
It does not.
The DPP can become the digital container through which information from several legal regimes is made available. The underlying duties still come from the laws that apply to the toy and its connected layers.
Mistake 2: "Every regime needs a separate passport"
The Toy Safety Regulation deliberately tries to avoid that outcome. Where another Union law requires a DPP for the toy, the Regulation says a single DPP should combine the required information.
The architecture is therefore many rulebooks, one interoperable passport where the legislation requires it.
That distinction is more useful than treating the DPP as either a universal compliance certificate or a separate website for every law.
Which data belongs to which layer?
| Layer | Facts worth governing | Evidence behind them |
|---|---|---|
| Toy host | model, manufacturer/operator, age/target user, product identity, toy safety status | safety assessment, technical documentation, conformity evidence |
| Toy DPP | adopted Annex VI data at the required model level | governed sources defined by toy law and later implementation |
| Radio | radio technologies, hardware configuration, conformity status | RED technical documentation and declaration evidence |
| Software | firmware/app version, supported features, update relationship | software release records and technical evidence |
| Cyber | support period, vulnerabilities/incidents, security configuration | cyber risk and vulnerability-management evidence |
| Battery | category, chemistry/capacity, removability/replaceability facts | battery supplier and design evidence |
| Cloud/data | account, microphone/camera/location features and service relationships | service architecture, privacy/security documentation |
| AI, where relevant | model/system purpose and role in toy safety/function | AI-specific technical evidence where required |
Once those layers are clear, use Which System Should Own Each Product Fact? to decide the authority and system of record for each fact.
Five boundary examples
1. Battery-powered toy with no radio
The product can be a toy and contain EEE/battery layers without being a connected toy.
The future Toy DPP applies from 1 August 2030 if the product is within the Toy Safety Regulation. The battery should be assessed under battery law. No radio obligation arises merely from being electronic.
2. Bluetooth toy controlled locally by a phone
Bluetooth creates a RED question.
Do not automatically call it an "internet-connected toy" in the specific CRA important-product category without checking whether the product meets the public-internet and feature criteria in Implementing Regulation 2025/2392.
3. Internet-connected talking doll
A toy that communicates on the public internet and has social interactive features such as speaking or filming can meet the CRA implementing description for the connected-toy category if the other criteria are met.
That creates a cyber classification in addition to toy and radio questions.
4. Toy with location tracking
Location tracking is specifically named in the CRA implementing description for the connected-toy category.
It also makes the data/privacy and RED cybersecurity analysis especially important where the radio equipment processes the data types specified by the RED delegated regulation.
5. AI-enabled connected construction toy
The host can remain a toy. Radio and CRA can apply depending on connectivity. AI can create a separate AI Act question depending on the system's classification and role.
The Toy DPP does not eliminate those separate scope tests.
Ask these questions before deciding
- Is the product within the legal definition of a toy?
- What age group and intended use are represented by the manufacturer?
- Does it intentionally use Bluetooth, Wi-Fi, cellular or another radio technology?
- Can it communicate over the public internet, directly or through another device?
- Does it speak, film, record or otherwise interact socially with the user?
- Does it track or infer the toy's or user's location?
- What personal, traffic or location data can it process?
- Which software, app and cloud services are required for the function?
- Does it contain AI functionality that needs a separate classification?
- What battery category is inside it?
- Which facts belong to the toy model and which belong to radio, software, battery or cloud layers?
- Are you asking about the adopted 2030 Toy DPP or a current connected-product obligation?
The last question prevents a common error: using the future passport date as the start date for obligations that already apply under another law.
What is settled
- Regulation (EU) 2025/2509 has adopted a Toy DPP architecture and applies from 1 August 2030.
- The Toy DPP does not make radio, cyber, EEE, battery or AI legislation disappear.
- The Toy Safety Regulation expressly anticipates interaction with the CRA, RED, RoHS and other Union law.
- Relevant RED cybersecurity requirements have applied from 1 August 2025.
- CRA Article 14 applies from 11 September 2026 and the CRA generally applies from 11 December 2027.
- Implementing Regulation (EU) 2025/2392 describes a specific important-product category for internet-connected toys with social interactive or location-tracking features where its criteria are met.
What remains product-specific
- Whether a particular product is a toy at all.
- Whether its radio function is in RED scope.
- Whether it communicates on the public internet.
- Whether its social, camera/microphone or location functions meet the CRA implementing category.
- Whether an AI function creates an AI Act classification.
- Which battery category is present.
- How future Toy DPP access rights, technical carrier details and implementation under Article 49 are completed before 2030.
A generic article cannot settle those points without the product facts.
What would change this page
Re-check when:
- CRA Article 14 begins applying on 11 September 2026
- CRA standards, implementing material or conformity pathways materially change the connected-toy classification route
- the Commission adopts Toy Safety Regulation Article 49 DPP delegated acts
- Toy DPP access rights, carrier or updating roles are materially specified
- Registry or customs implementation changes the operational Toy DPP route - that operational detail belongs to the Registry owner, not this page
- RED cybersecurity rules or harmonised standards materially change
- AI Act implementing material changes the toy examples.
Where this connects
- Toy Digital Product Passport Requirements - canonical toy DPP status and dataset owner
- Does My Product Category Need a Digital Product Passport? - broad product-category classification
- ICT and Electronics Digital Product Passport Requirements - canonical electronics DPP status
- Battery Digital Product Passport Requirements - battery passport scope
- Which System Should Own Each Product Fact? - data ownership after the layers are identified
- Your Technical File Holds Compliance Evidence. Which Parts Should Become Governed Product Data? - evidence-to-data architecture
Does this reach your products?
Give ActivateDigital one product and it works out which obligations apply from the product's own character, and says which it cannot decide.
Help someone else make sense of product passports.
Sources / legal basis
This is a regulatory information resource for business decision-making, not personalised legal advice. Product classification depends on the actual toy, functions, claims, connectivity and legal scope.