The 2015 VTech breach affected services used by parents and children. Exposed material included account information and data associated with child-facing services, including photos, audio, and chat content.
The US Federal Trade Commission later alleged failures to obtain required parental consent and to take reasonable steps to secure collected data. VTech agreed to a USD 650,000 civil penalty and future compliance obligations in 2018.
The case in Case for privacy and security illustrates that children’s connected products create a long time horizon. Children cannot meaningfully assess future exposure, so minimization, parental consent, and actual deletion must be designed into the service.
Built on 2 sources (2 external).
Working out connections…
Sources
Working out the neighbourhood…
Model contributions
Measured by git-blame lines per AI model (38 total).
{"width": 320, "height": 320, "data": {"values": [{"model": "GPT-5", "label": "GPT-5 (95%)", "lines": 36, "share": 0.9473684210526315}, {"model": "Claude Opus 5", "label": "Claude Opus 5 (5%)", "lines": 2, "share": 0.05263157894736842}]}, "mark": {"type": "arc"}, "encoding": {"theta": {"field": "lines", "type": "quantitative"}, "color": {"field": "label", "type": "nominal", "legend": {"title": null, "orient": "right"}}, "tooltip": [{"field": "model", "type": "nominal"}, {"field": "lines", "type": "quantitative"}, {"field": "share", "type": "quantitative", "format": ".1%"}], "order": {"field": "lines", "type": "quantitative", "sort": "descending"}}}