Cybersecurity

TikTok Agrees to $400 Million Settlement Over Children’s Privacy Allegations

By Parviz Nasirov
TikTok Agrees to $400M Settlement Over Children's Privacy Claims

TikTok and ByteDance have agreed to a $400 million settlement with the U.S. Department of Justice to resolve allegations that the platform violated children's privacy protections under COPPA. TikTok will pay $300 million immediately and another $100 million if a previous consent decree involving its predecessor, Musical.ly, is vacated.

TikTok and ByteDance have reached a $400 million settlement with the U.S. Department of Justice (DOJ) to resolve litigation alleging violations of U.S. children's online privacy laws.

The settlement follows a lawsuit filed in 2024 over allegations that TikTok failed to adequately protect the personal information of children under the age of 13.

The case centered on compliance with the Children's Online Privacy Protection Act (COPPA) and its implementing regulations.

Under the agreement, TikTok will pay:

  • $300 million immediately
  • An additional $100 million if a court vacates an earlier consent decree involving TikTok's predecessor, Musical.ly

The Justice Department described the agreement as one of the largest recoveries ever obtained in a COPPA case.

What Was TikTok Accused Of?

The U.S. government alleged that TikTok and ByteDance knowingly allowed children under 13 to create accounts and use the platform while collecting and retaining their personal information without obtaining the required parental consent.

COPPA imposes specific obligations on online services that collect personal information from children under 13.

Depending on the circumstances, companies may be required to:

  • Notify parents about data collection practices
  • Obtain verifiable parental consent
  • Limit unnecessary collection of children's data
  • Protect collected information
  • Allow parents to request deletion of children's data
  • Delete information when it is no longer required

The government alleged that TikTok failed to meet several of these requirements.

The Case Dates Back to Musical.ly

The controversy is connected to TikTok's predecessor, Musical.ly.

In 2019, the U.S. Federal Trade Commission reached a settlement with Musical.ly over allegations that the company illegally collected personal information from children.

At the time, Musical.ly agreed to pay approximately $5.7 million, which was then the largest civil penalty obtained by the FTC in a children's privacy case.

The company also became subject to a consent decree requiring stronger COPPA compliance.

The new 2026 settlement provides for TikTok to pay an additional $100 million if that earlier consent decree is formally vacated.

TikTok Will Pay $300 Million Immediately

The largest part of the settlement — $300 million — will be paid immediately.

The remaining $100 million is conditional on the earlier Musical.ly consent decree being vacated.

Combined, the agreement has a potential value of $400 million.

The DOJ characterized the settlement as a major enforcement action intended to reinforce companies' obligations when processing children's personal data.

TikTok Has Changed Its Privacy Practices

The Justice Department acknowledged that TikTok has made significant changes since the lawsuit was filed in 2024.

According to the DOJ, those changes include improvements involving:

  • Corporate ownership and management
  • Compliance programs
  • Privacy practices
  • Age-related controls
  • Parental oversight
  • Safeguards for younger users

TikTok has also said that it uses age-assurance and moderation systems designed to identify users under 13 who may have provided false ages during registration.

The company reportedly employs hundreds of personnel involved in underage-user moderation and removes large numbers of accounts believed to belong to children under the platform's minimum age.

No Determination of Liability

An important legal distinction is that the settlement resolves the government's allegations without a judicial determination that TikTok or ByteDance was liable for the alleged violations.

The DOJ explicitly noted that the claims covered by the settlement remain allegations only.

This means the $400 million agreement should not be interpreted as a court ruling establishing that every allegation made in the lawsuit was proven.

Children's Data Is Becoming a Major Regulatory Issue

The TikTok case forms part of a broader regulatory trend involving social media platforms and children's privacy.

Authorities around the world are placing increasing scrutiny on how technology companies:

  • Determine users' ages
  • Collect children's data
  • Personalize content
  • Build recommendation profiles
  • Handle parental consent
  • Retain user information
  • Protect minors from inappropriate interactions

Age verification presents a particularly difficult technical challenge.

Platforms need reliable mechanisms for identifying children, but those same mechanisms can themselves require the collection of additional personal information.

This creates a security and privacy tradeoff.

Weak age controls can allow children to bypass restrictions, while overly intrusive verification systems may require sensitive identification documents, facial analysis, or other personal data.

Analysis and context

The TikTok settlement is significant not simply because of its $400 million value, but because it demonstrates that children's privacy is becoming a major compliance risk for large technology platforms.

For social media companies, determining whether a user is actually over 13 is technically difficult.

A simple date-of-birth field is easy to bypass.

However, stronger age-verification mechanisms can introduce new privacy risks of their own.

For example, determining a user's age may involve:

  • Government-issued identity documents
  • Facial age estimation
  • Payment information
  • Device intelligence
  • Behavioral analysis
  • Third-party identity providers

Each additional source of information increases the amount of sensitive data that organizations may need to secure.

Data Minimization Is Critical

One of the most important security lessons from children's privacy regulation is the principle of data minimization.

Organizations should ask:

Do we actually need to collect this information?

Personal information that is never collected cannot later be exposed through:

  • Data breaches
  • Insider threats
  • Misconfigured databases
  • Credential theft
  • Third-party integrations
  • Supply-chain attacks

This principle is especially important when dealing with minors.

Privacy Must Be Designed Into the Platform

Privacy controls should not simply be added after a product has already reached millions of users.

A stronger approach is Privacy by Design.

This can include:

Age-aware onboarding
Different account experiences and permissions depending on age.

Private-by-default accounts
Profiles belonging to younger users should have more restrictive default settings.

Data minimization
Collect only information required to provide the service.

Parental controls
Provide transparent mechanisms for parents or guardians to manage younger users' accounts where legally required.

Retention limits
Automatically delete information that no longer serves a legitimate purpose.

Access controls
Limit internal access to children's personal information.

Audit logging
Record access to sensitive information and monitor unusual activity.

Deletion workflows
Ensure that account deletion also removes related information from relevant backend systems.

Privacy Is Also a Cybersecurity Issue

Privacy and cybersecurity are often discussed separately, but they are closely related.

A privacy policy defines what information an organization should collect and how it should use that information.

Cybersecurity determines how effectively that data is protected from unauthorized access.

Even perfect parental consent mechanisms provide limited protection if the underlying data is later exposed through a security breach.

For platforms handling information belonging to children, privacy compliance therefore needs to work together with:

  • Encryption
  • Identity and access management
  • Secure application development
  • Logging and monitoring
  • Data classification
  • Incident response
  • Third-party risk management

Regulatory Risk Is Becoming a Technical Requirement

The TikTok case also shows that privacy compliance is no longer simply a legal department responsibility.

Modern privacy laws increasingly affect software architecture.

Engineering teams may need to build systems capable of:

  • Identifying age categories
  • Recording consent
  • Restricting features
  • Enforcing retention periods
  • Responding to deletion requests
  • Separating data belonging to minors
  • Demonstrating compliance through audit trails

Failure to implement these requirements can become a major financial and reputational risk.

The $400 million TikTok settlement therefore reinforces a broader lesson for technology companies:

Protecting children's personal information must be treated as a core product, privacy and cybersecurity requirement rather than an optional compliance feature.