$400 million for child data: What companies can learn from the TikTok case

Jonas Buchholz
by Jonas Buchholz · 09.09.2026
Data Protection

The comparison in the USA shows why the protection of underage users should begin as early as the design of digital offerings.

400 million US dollars: This amount has been agreed upon by TikTok, ByteDance and the US Department of Justice in a case to protect the personal data of children. Although the case concerns US data protection law, the questions involved are also relevant for European companies:

Are our offerings used by minors? Do we know how old our users actually are? And do our processes take into account that personal data from children deserves special protection?

What happened on TikTok?

The US Department of Justice had already sued TikTok and ByteDance in 2024. The accusation: TikTok had enabled children under 13 to create regular accounts and collected and stored personal data without properly informing the parents and obtaining their consent.

According to the DOJ, this affected millions of children. Accounts in the so-called „Kids Mode“ were also reportedly processed, among other things, email addresses, IP addresses, device identifiers, and other information. Furthermore, the DOJ accused TikTok of lacking processes for identifying and deleting child accounts. (Source: U.S. Department of Justice, lawsuit of August 2, 2024).

In August 2026, the proceedings were now concluded through a settlement. TikTok will pay $300 million immediately and an additional $100 million once the earlier consent decree against TikTok’s predecessor, Musical.ly, is lifted. The DOJ describes the settlement as one of the largest payments ever obtained in a proceeding under the U.S. Children’s Online Privacy Protection Act (COPPA).

Important for a proper classification: This is not a judgment and it is not a legally determined data privacy violation. The settlement resolves the allegations; the DOJ explicitly states that no liability has been established.

The real problem: Children do not always give their correct age

A particularly interesting aspect of the original lawsuit concerns the determination of age.

According to the DOJ’s allegations, TikTok employees knew that children were providing false information when age verification was performed. At the same time, TikTok is said to have had access to additional technical capabilities to assess users’ age based on their behavior. However, these were not properly used to identify children under 13 on the regular platform and remove their accounts.

This is where the case becomes interesting outside the USA as well. A simple question like „How old are you?“ This does not necessarily solve the problem of child data protection. Companies must instead address the question of who is actually using their offering and what protective measures are appropriate given the specific offering.

What applies in Europe?

The GDPR also places special importance on the protection of children.

Article 8 of the GDPR is particularly relevant when an information society service is offered directly to a child and the processing of personal data is based on consent pursuant to Article 6(1)(a) of the GDPR.

Basically, the GDPR sets an age limit of 16 years for this. The member states can lower this limit to up to 13 years. In Germany, the age limit of 16 years has been maintained.

If the child is younger, processing based on consent is only lawful if and insofar as it has been granted or approved by the holder of parental responsibility.

And the GDPR goes one step further: The controller must, taking into account the available technology, make reasonable efforts to verify that the consent has actually been given or approved by the person with parental responsibility.

Thus, the practical question arises here as well:

How reliable is our age and consent process?

Child data protection does not start with the checkbox

The TikTok case therefore highlights a fundamental problem. It is not always sufficient to query a birth date in a registration process and then assume that minors are excluded or that necessary consents have been obtained. Companies should, instead, take into account the following when designing a digital offering:

  • Is the offer directed explicitly or in fact also at minors?
  • What personal data are collected in this process?
  • On what legal basis is the processing carried out?
  • What role does age play for this legal basis?
  • How are cases of clearly false age claims handled?
  • How do deletion and rights of the affected parties work for underage users?
  • Are the information about data processing also understandable for the age group concerned?

Especially in the case of offers that are attractive to children and young people due to their design or content, the answer should not be sought until complaints have been received.

What companies can learn from the TikTok case

The comparison cannot be applied to European companies in a strictly equivalent way from a legal perspective. COPPA and GDPR are different regulations.
The practical message, however, goes beyond the specific US case:

Anyone who has to realistically expect minors to be users of their offering should understand child data protection as part of the product and process design – and not just as a question for the privacy policy.

These include a deliberate decision regarding the target audience, appropriate age mechanisms, appropriate legal frameworks, and processes for handling the data of underage users. The TikTok case vividly demonstrates the extent to which this issue can be addressed if these questions are not asked until years later.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

Has TikTok received a $400 million data protection fine?


What was TikTok accused of?


Is there a fixed age limit in Germany for data protection consent forms?

Is a query of the date of birth sufficient?


What do companies need to consider when dealing with the personal data of minors?


What can companies learn from the TikTok case?