Is Your Child’s Personal Information Really Safe on TikTok?
What TikTok’s $400 Million Privacy Settlement Means for Parents
TikTok has agreed to pay US$400 million to settle a US Department of Justice lawsuit concerning children’s privacy; one of the largest settlements ever reached in a case involving the Children’s Online Privacy Protection Act (COPPA).
But beyond the size of the settlement, this case raises a much bigger question:
Who should carry the responsibility for protecting children’s personal information online?
What happened?
The US Department of Justice filed its lawsuit against TikTok and ByteDance (unfortunately named and unrelated to Byte, The Digital Safety Guide) in 2024, alleging that TikTok violated COPPA (Children's Online Privacy Protection Act), which requires online services directed at children to obtain parental consent before collecting certain personal information from children under 13.
Among the allegations were claims that TikTok knowingly allowed children under 13 to create accounts, collected and retained their personal information without appropriate parental consent, and failed in some instances to delete children's accounts and information when requested by parents.
TikTok has now agreed to pay $300 million immediately, with a further $100 million payable following the removal of an earlier consent decree involving its predecessor, Musical.ly.
The Department of Justice has also acknowledged that TikTok has made significant changes to its ownership, management, compliance functions and privacy practices since the case began, including measures intended to strengthen safeguards for younger users, age controls and parental oversight.
Why this matters beyond TikTok
For parents, this isn't simply a story about one social media platform.
Children are growing up in digital environments where information can be collected from the moment they create an account, watch a video, search for something, interact with content or engage with other users. It is important that children and parents understand the concept of Digital Footprints and the potential consequences of these.
And children aren't necessarily equipped to understand what is happening behind those interactions.
A child may understand that sharing their home address publicly isn't a good idea. They are far less likely to understand what information a platform is collecting about them, how that information might be used, how long it might be retained or what can be inferred about them from their activity.
That creates an important distinction between keeping children safe online and protecting children's privacy online.
We need to do both.
Parents can't carry the responsibility alone
There is understandably a growing focus on what parents can do to keep children safe online: parental controls, privacy settings, age restrictions, conversations about appropriate sharing and monitoring children's use of technology.
These are important.
But parents cannot reasonably be expected to understand or control every data practice occurring behind the services their children use.
Nor should children be expected to protect themselves against data practices they cannot see or understand.
Digital services used by children need to be designed with children's privacy in mind from the outset.
That means considering what information actually needs to be collected, providing age-appropriate privacy protections, making children's accounts private by default where appropriate, limiting unnecessary data collection and ensuring parents and children can meaningfully exercise their privacy rights.
Privacy by design becomes particularly important when the person whose information is being collected is a child.
But regulation isn't enough either
At the same time, regulation and platform safeguards can't be the only line of defence.
A compliant platform does not automatically create a digitally capable child.
Children still need to learn how to recognise personal information, understand why certain information should remain private, think critically before sharing, recognise unsafe or unusual requests and know what to do when something doesn't feel right.
Parents need the knowledge and confidence to have those conversations too.
The strongest approach is therefore not choosing between regulation, platforms, parents or education.
It is creating layers of protection.
Platforms should build safer and more privacy-protective environments.
Regulators should establish and enforce appropriate protections for children.
Parents should remain actively involved in their children's digital lives.
And children should be given the skills to navigate those environments safely.
Children's privacy should not depend on children understanding privacy law
Perhaps the most important lesson from cases like this is that children shouldn't need to understand complex data practices in order to be protected from them.
We wouldn't expect a 10-year-old to understand a privacy policy, assess whether a collection practice is proportionate or determine whether consent has been validly obtained. The systems around them need to provide that protection. But we can teach that same 10-year-old something incredibly valuable:
Your personal information matters. Think carefully about who you share it with, and ask a trusted adult when you're unsure.
That combination of stronger protections and better digital literacyis where I believe we have the greatest opportunity to make children's online experiences safer.
The details above are supported by the DOJ's August 21 announcement and contemporaneous reporting. The DOJ says the case concerned compliance with COPPA, confirms the $300 million + $100 million settlement structure, and specifically notes changes TikTok has made to safeguards for younger users. (Department of Justice)