Skip to main content
Abstract mobile social platform protected by layered child privacy controls

TikTok agrees to $400 million settlement in US child privacy case

TikTok and ByteDance will pay $400 million to resolve US allegations under COPPA, while the settlement makes no determination of liability.

Published

23 Aug 2026

Reading Time

4 min read

Share this article:

Contents

TikTok and ByteDance have agreed to pay $400 million to resolve a US government lawsuit over children's privacy, closing a major case brought under the Children's Online Privacy Protection Act, or COPPA. The settlement is large, but its legal wording matters: the government says the case concerned alleged violations, and the agreement does not amount to a court finding of liability.

The original report by The Next Web, published on August 22, 2026, framed the US deal alongside earlier European enforcement. The official Justice Department announcement, released one day earlier, provides the clearest account of the payment and the status of the litigation.

What the settlement requires

Under the agreement described by the Justice Department, TikTok, ByteDance and affiliated entities will pay $300 million immediately. A further $100 million becomes payable when a court enters an order vacating a previous consent decree against Musical.ly, TikTok's predecessor. The department described the total as one of the largest recoveries obtained in a COPPA case.

The Justice Department also said TikTok had made changes since the lawsuit began in 2024, including changes to ownership, management, compliance functions, privacy practices, age-related controls and parental oversight. Its announcement does not provide a technical audit of those measures or a product-by-product list of new obligations. That distinction is important: a financial settlement and a description of compliance work do not, by themselves, show how reliably protections operate for every young user.

The lawsuit was filed in the US District Court for the Central District of California after a referral from the Federal Trade Commission. The settlement resolves the federal government's claims without a determination of liability.

What the government had alleged

COPPA generally requires covered online services to notify parents and obtain verifiable parental consent before collecting personal information from children under 13. It also gives parents rights concerning information collected from their children, including deletion in relevant circumstances.

In its 2024 complaint, the Justice Department alleged that TikTok and ByteDance knowingly allowed children under 13 to create regular accounts, collected and retained their personal information without the required parental consent, and failed to honor some parental deletion requests. The complaint also alleged violations of a 2019 court order involving Musical.ly. These were the government's allegations; the new settlement does not convert them into adjudicated facts.

For technology platforms, the case highlights why age gates alone are not the whole compliance problem. Account defaults, data retention, parental tools, deletion workflows and the way services identify likely underage users all affect whether privacy safeguards work in practice. Stronger age assurance can also require additional data, so platforms need to minimize collection and explain their methods clearly rather than treating age checks as an isolated feature.

The European comparison is related, but separate

The US agreement follows a major European decision, although the two actions rest on different laws and examined different conduct. Ireland's Data Protection Commission imposed administrative fines totaling €345 million in September 2023 after an inquiry into TikTok's processing of children's data during part of 2020.

That GDPR inquiry focused on issues including public-by-default settings, Family Pairing, age verification and the transparency information presented to child users. The Irish regulator also issued a reprimand and ordered remedial action. COPPA, by contrast, centers the US case on data practices involving children under 13 and parental notice and consent. The similar headline amounts should not obscure those different legal tests.

What users and regulators should watch

The practical question after the payment is whether privacy controls are understandable, consistently enforced and easy for families to use. Parents should be able to find account and deletion controls without navigating ambiguous interfaces. Young users should receive settings appropriate to their age, with clear explanations of what is collected and who can see their activity.

Regulators, meanwhile, will need evidence about how safeguards behave in real use, not only policy descriptions. Useful signals include whether underage accounts are detected, whether deletion requests are completed, whether restrictive defaults remain enabled and whether product changes are independently reviewable.

The settlement removes the uncertainty of prolonged litigation and attaches a substantial financial cost to the dispute. It does not end the broader technical challenge: building social platforms that can recognize age-related risk while collecting as little additional personal data as possible.

Tags:

#TikTok #ByteDance #COPPA #children's privacy #data protection #social media #regulation

34

views

0

shares

0

likes

Related Articles