Skip to content

Product6 publishersReports disagree3 min readPublished Updated

TikTok's $400mn settlement prices the second offence at about 70 times the first

Musical.ly paid $5.7mn in 2019 over the same statute. The DOJ's complaint treats registration-flow design as the violation, which makes age-gating a documented enforcement target.

The Product Desk

How we use AISend a correction

Photograph accompanying TikTok's $400mn settlement prices the second offence at about 70 times the first
Photo: thenextweb.com

What happened

  • TikTok and ByteDance will pay $400mn to settle the Justice Department's COPPA case over millions of under-13 users and their data.
  • Predecessor Musical.ly paid $5.7mn in 2019 and undertook to stop under-13s creating accounts.
  • The deal also obliges stronger age controls, extra safeguards for children and better parental oversight tools.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • precedent Repeat offending in children's privacy now carries a published multiple, so any platform arguing its age checks have improved is arguing against a comparator that starts at $400mn.
  • constraint An age assurance scheme a regulator can measure needs more identity data, which narrows the ways a product team can satisfy both duties without picking one to fail.
  • exposure Sign-up flow revisions and internal warnings about underage users are the material these cases turn on, which pulls growth and product decisions into discovery alongside the privacy team.
  • contradiction The BBC has the settlement covering only TikTok's China-based operations while the DOJ credits improvements at the divested US business, so which balance sheet is being disciplined is not clear...

The allegation doing the work in the 2024 complaint is not simply that under-13s were present. It is design. The Justice Department said TikTok changed aspects of its registration policies in ways that made it harder to determine whether users were old enough to join [11], and that the company kept and used children's information, including data usable for ad targeting, after employees had raised concerns about young users on the platform [12]. Both of those are artefacts rather than impressions. A registration flow has versions. An internal concern has a sender and a date.

That is what makes the arithmetic worth doing. Musical.ly paid $5.7mn in 2019 and committed to preventing under-13s from creating accounts [7], and the DOJ's case was that the terms of that earlier FTC settlement were violated, along with data collection in "Kids Mode" and frequent failures to honour parental deletion requests [8]. The second visit costs roughly seventy times the first [22]. For scale, Google paid $170mn in 2019 and Epic Games $275mn in 2022 for COPPA violations [16], so $400mn lands about $125mn above the previous high mark without reaching the two of them added together [23]. The DOJ calls it one of the largest recoveries ever obtained under the statute [9].

The payment structure is the tell about what the government still wants. Three hundred million is due immediately and the last $100mn only once the 2019 FTC consent decree is vacated [2], which parks a quarter of the money [14] on the disposal of the old order. Nobody was found liable: the agreement requires no admission of wrongdoing [5], and the DOJ's announcement states the resolved claims are allegations only with no determination of liability [6]. So what is on the record is a theory of the case with a price attached, which is exactly what a compliance function has to plan against.

The terms a regulator can come back and measure are the age-related controls, the additional safeguards for children and the parental oversight tools [24]. The DOJ notes the company has already changed ownership, management, compliance functions and privacy practices [4], and assistant Attorney General Brett Shumate said children and parents are better protected today than when the case began [15].

Europe reached a comparable number earlier and by a different route. Ireland's Data Protection Commission fined TikTok 345mn euros in September 2023 over its handling of children's accounts [13], in a bloc where a third of fines against social platforms concern children [26], and the Commission has separately charged TikTok under the Digital Services Act over failures to protect minors [17]. Legislation is following: the EU says its age verification app is ready, Ursula von der Leyen is pushing bloc-wide protections, and Norway plans to ban social media for under-16s with liability sitting on platforms [18]. All of it hits the same obstacle, which is that establishing a user is a child means collecting the data the privacy regime exists to restrict [19].

Meanwhile the scrutiny has not paused. Days before the settlement, Bloomberg reported that TikTok had deliberately disabled an algorithmic safeguard for roughly 10% of US users as an experiment, a safeguard meant to reduce the chance of users being overwhelmed by harmful content [20], prompting a letter to CEO Shou Chew and US business head Adam Presser from Senators Marsha Blackburn and Richard Blumenthal [21]. The registration flow was a product decision that a federal docket now describes line by line. The next one will be read the same way.

What to watch

  • Whether the 2019 FTC consent decree is actually vacated, which is what releases the outstanding $100mn.
  • How the Commission's Digital Services Act charges over minors resolve, since those penalties run separately from the US settlement.
  • Whether the Blackburn and Blumenthal letter over the disabled safeguard becomes a hearing or a second enforcement track.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories