Aug 25, 2026 · 8 min read
TikTok Pays $400M to Settle US Child Privacy Case
The Justice Department announced the settlement with TikTok, ByteDance and affiliated entities on Friday, August 21, 2026, closing a COPPA case filed two years earlier.
Three hundred million dollars changed hands the moment the paperwork was signed. The other hundred million is waiting on a judge. That structure, more than the headline number, is the part worth your attention.
Key Takeaways
- The Department of Justice announced a $400 million COPPA settlement with TikTok, ByteDance and affiliated entities on Friday, August 21, 2026.
- TikTok pays $300 million immediately and $100 million more only upon entry of an order vacating the consent decree against its predecessor, Musical.ly.
- The 2024 complaint alleged TikTok knowingly let under 13s onto the regular app, kept Kids Mode data without verifiable parental consent, and ignored parents' deletion requests.
- The figure is roughly 70 times the $5.7 million Musical.ly paid the FTC in 2019 over the same category of conduct.
- DOJ credited remediation TikTok made after being sued, signaling that fixing a defect mid litigation still shapes the outcome.
What Did TikTok Agree to Pay?
TikTok agreed to $400 million: $300 million immediately, plus $100 million upon entry of an order vacating a prior consent decree entered against Musical.ly. The Justice Department's announcement calls it "one of the largest recoveries ever obtained in a COPPA case." Associate Attorney General Stanley E. Woodward Jr. called it "a major victory for American children and parents." Assistant Attorney General Brett A. Shumate was blunter: "Companies that collect children's personal information must comply with the law."
The suit was filed in the U.S. District Court for the Central District of California, handled by the Civil Division on referral from the FTC. The department was also explicit that the resolved claims "are allegations only, and there has been no determination of liability." No court found TikTok violated COPPA. It paid to end the case.
Why Is $100 Million Riding on a 2019 Consent Decree?
Because TikTok has been under a standing federal court order on children's privacy since 2019, and the final tranche is the price of escaping it. In February 2019 the operators of Musical.ly, by then renamed TikTok, paid $5.7 million over FTC allegations that they illegally collected children's data. The FTC called it the largest civil penalty ever obtained in a children's privacy case at the time.
Same lineage, same statute, same conduct, seven years apart: $5.7 million became $400 million, a seventyfold escalation. File the structure away too. A consent decree is durable supervision, and vacatur removes both court oversight and contempt exposure. Treating that release as something a defendant can buy is a precedent worth watching.
What Did the 2024 Complaint Allege?
Filed August 2, 2024 after an FTC investigation and referral, the complaint described what the government called massive scale invasions of children's privacy. Four allegations carried it:
- TikTok knowingly let children under 13 create regular accounts on the main platform, outside the restricted Kids Mode.
- TikTok collected and retained personal information from Kids Mode users without verifiable parental consent.
- TikTok failed to honor parents' requests to delete their children's accounts and information.
- TikTok's systems for finding and removing known underage accounts were inadequate.
The government sought civil penalties of up to $51,744 per violation per day from January 10, 2024. Against millions of alleged child users, that dwarfs $400 million. Most coverage calls this an enormous penalty; against the ceiling the government itself invoked, it reads more like a negotiated discount.
Why "We Have a Kids Mode" Is Not a Defense
Because the government charged the general product and the children's product separately, and Kids Mode did not insulate the main app. A walled garden only helps if the general service keeps children out. The complaint alleged the opposite, then alleged the walled garden itself retained data without verifiable parental consent. Two failures, two theories of liability. Your children's experience and your age gate are separate compliance surfaces; a well built one does not cure a broken one.
The deletion allegation was pleaded as a violation in its own right, not an aggravating detail. Under the FTC's amended COPPA Rule that reached full compliance in April 2026, retention limits and written deletion policies are explicit obligations. A pipeline that quietly drops requests is now enforceable on its own terms.
What Does This Signal About COPPA Enforcement in 2026?
Children's privacy cases now arrive as federal civil litigation carrying nine figure exposure, not as administrative settlements. The FTC investigated and referred; the DOJ Civil Division litigated. The counterparty is a litigating arm of the government, not a regulator negotiating a consent order.
The second signal cuts the other way. The department said that since the 2024 complaint TikTok has strengthened safeguards for younger users, improved age related controls, and enhanced parental oversight, developments that "materially advanced the public interests underlying the Department's litigation." Remediation begun after you are sued still counts.
The third is convergence. TikTok has absorbed children's data penalties on two continents in seven years: $5.7 million from the FTC in 2019, €345 million from Ireland's Data Protection Commission in September 2023 under GDPR, and now $400 million from the DOJ. Age assurance sits at the center of it, and is reshaping how the FTC approaches age verification and COPPA together.
What Compliance Teams Should Check This Week
Map each allegation to a control you can evidence. The FTC's COPPA compliance guidance is the reference text. The short list this settlement points at:
- Age screen design. Is it neutral, or does it telegraph the answer that grants access? One users can retry until they pass is not a screen.
- Verifiable parental consent. Document the mechanism and when it fires. A checkbox is not verification.
- Retention limits. Write down what you hold on children, why, and the deletion trigger.
- A deletion pipeline with an SLA. Requests must reach analytics, backups and vendor copies inside a stated window.
- Audit trails. Without evidence a request was fulfilled on a given date, you cannot rebut what TikTok faced.
- Known underage accounts. When a moderation flag says a user is under 13, what fires automatically? Actual knowledge starts the clock.
One item is easy to miss: this settlement lands on a company that changed hands mid case, after the US joint venture closed in January 2026 with Oracle, Silver Lake and MGX taking stakes from ByteDance. The liability followed the asset.
What This Means for Email and Marketing Teams
Email addresses are personal information under COPPA, and marketing systems are where deletion requests go to die. The FTC's 2019 Musical.ly case named email addresses explicitly among the data collected from users under 13 without parental consent. If a child's address entered your platform, it almost certainly entered your email service provider and CRM too.
That is the practical shape of the third allegation. A parent's request hits the product database, gets marked resolved, and never reaches the marketing stack. Months later a campaign sends to an address that should be gone. Under the amended rule that gap is a policy failure and a retention failure at once, a pattern visible in the FTC's action against Disney over children's data and ad targeting. Ask your ESP whether it can produce a deletion receipt for a named address on a named date.
What Happens Next
Watch the vacatur. The final $100 million moves only when a court dissolves the Musical.ly consent decree, so completion runs through a judicial decision that has not happened. If it issues, TikTok exits federal court supervision on children's privacy for the first time since 2019.
The broader lesson is a shift in what enforcement rewards: the government took a negotiated figure and said in writing that remediation was part of the reason. Build the pipeline, keep the audit trail, document the date you fixed it.