TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly

Author: Published 6 min de lectura 1 reading

The images in this article were generated with artificial intelligence. How we publish

The U.S. Department of Justice. United States announced payment of $400 million by TikTok to resolve a 2024 lawsuit that accused the platform - owned by ByteDance - of violating the United States child privacy law (COPPA). According to the resolution, TikTok will disburse $300 million immediately and others 100 million additional will be subject to a court order the annulment of a previous decree related to the old Musical.lyapplication.

Confirmed facts: the action was presented in August 2024 by the Department of Justice together with the Federal Trade Commission (FTC), and claimed that TikTok allowed them to create accounts and that data were collected from those who used the application in their "Kids Mode," in addition to not meeting parents' requests to remove accounts and information. DoJ himself described the result as one of the biggest recoveries linked to the implementation of COPPA. It is also public that, in recent years, TikTok has received regulatory sanctions in Europe for the processing of child data.

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
Image generated with IA.

What the law says and how these charges are applied. COPPA prohibits the collection of personal information of children under 13 years of age without the verifiable consent of parents and requires platforms to allow the deletion and access to such data. In technical terms, government investigations tend to focus on whether a app collects persistent identifiers (such as device ID), use data, location or content that will enable the profiling or advertising of minors, and whether mechanisms for obtaining parental consent are robust and verifiable. The complaint against TikTok is precisely a failure in these controls and in the elimination processes requested by the parents; the company has argued that many of the charges relate to past practices and corrections already implemented.

Practical implications and regulatory context. On the one hand, economic sanctions and any additional compliance obligations strengthen the position of regulatory agencies and create an operational precedent: other platforms that have not developed specific age and consent controls may expect more aggressive scrutiny. On the other hand, the payment does not remove legal uncertainties: the 100 million conditioned depend on the annulment of a decree against Musical.ly, and it is not guaranteed that this procedure will be resolved in a favourable way or within what time. In addition, although the fine is important, TikTok had already adopted multiple changes in its policies and tools for minors in response to previous regulatory actions - including a significant fine in the EU in 2023 for the processing of child data - so the immediate operational impact could focus more on continuous compliance reviews than on radical product changes.

Those who are affected. First, users under 13 years of age and their families: the resolution seeks to strengthen guarantees on what data can be collected and how parental applications are met. Second, product and compliance managers in technology companies: the expectation of verifiable age controls and solid data erasing processes is intensified. Third, investors and the market: although 400 million is a remarkable sum, for a platform of the TikTok scale it is a significant but non-existential cost; its impact on the valuation or ongoing business will depend on additional obligations imposed by the agreement and the cost of maintaining compliance in multiple jurisdictions.

What remains to be confirmed. It is not clear, with available public information, what exactly were the specific categories of data claimed in demand (for example, whether there was use of biometrics or profiles intended for targeted advertising) or the detail of the specific technical measures TikTok has implemented following the charges. Nor is it certain that the court will empty the decree against Musical.ly: this decision is taken by different judicial bodies and can be extended. In addition, the resolution may include operational conditions - audits, external supervision, changes in data flow to servers outside the US. United States - which have not yet been published or detailed by the authorities.

Technical and legal interpretation. In current regulatory practice, the difference between an infringement and compliance depends on both the existence of technical controls (e.g. age verification, limitation of the collection of identifiers) and the documentation and evidence of policies and their implementation. Authorities often demand evidence of evidence that user interfaces do not facilitate the registration of minors, that removal mechanisms really work and that data collected are justified by functionality (minimization principle). If the DoJ's accusations were successful, it was because, according to demand, the controls and management of parental applications presented systemic failures.

Practical recommendations for users and parents. Update the app: recent versions introduce age and mode controls with restrictions; keeping the application up-to-date reduces the risk that they operate old functions. Review and activate parental controls: use the platform's monitoring tools (e.g. the Family Pairing function TikTok offers) and set time and visibility limits. Check age and account: if you suspect that a minor has an account, request removal through the configuration and document the application; keep confirmations. Request and limit data: request access to the child's data and its deletion and, if the company does not respond, consider filing a complaint with the FTC or the relevant data protection authority. To understand basic legal rights and obligations, the FTC guide on COPPA should be consulted: https: / / www.ftc.gov /... / childrens-online-privacy-protection-rule-coppa.

TikTok will pay 400 million for COPPA; 100 M subject to annulment of decree Musical.ly
Image generated with IA.

What technology companies should do. In addition to implementing technical controls on age verification and data minimization, companies must document compliance processes, regularly audit privacy practices and establish clear and verifiable procedures for the removal of accounts and information at the request of parents. Obligations do not end with a fine: sustained and transparent operational performance is often the condition for avoiding recurrent sanctions and for recovering public confidence.

In perspective, the 2024 TikTok sanction is part of a global regulatory trend towards greater protection of child data: authorities in the EU and the US. The United States is raising demands and fines (for example, the punishment in Europe for data on minors in 2023 was relevant in this regard). For users and product managers, the lesson is clear: the design of services that can attract minors must incorporate privacy controls from conception and continuous tests that demonstrate their effectiveness. For more context on international attention to child data protection, it is useful to review press and regulatory reports on previous sanctions: a useful coverage of the fine in Europe is available in international press Here..

In short, the 400 million agreement marks an important economic resolution and strengthens regulatory surveillance on the privacy of minors, but leaves open the issue of precise operational obligations and the medium-term impact on the product architecture and data management practices of large platforms.

Coverage

Related

More news on the same subject.