The Justice Department announced on 21 August that TikTok and its parent company ByteDance have agreed to pay $400 million to resolve the children’s privacy lawsuit the government filed against them in 2024. It is one of the largest recoveries ever obtained under the Children’s Online Privacy Protection Act, and by the standard measure of privacy enforcement — the size of the cheque — it is a landmark.
By the other standard measure — what it costs the defendant — it is about six days of revenue.
Both facts are true at once, and the gap between them is the entire story of children’s privacy enforcement in the United States.
What TikTok Was Accused Of
The complaint, filed in the Central District of California in August 2024, alleged that TikTok violated COPPA and the FTC’s 2019 consent order against Musical.ly — the app TikTok absorbed — in three distinct ways.
It let children in and knew it. COPPA requires verifiable parental consent before collecting personal information from a child under 13. The government alleged that TikTok knowingly permitted millions of children under 13 to create regular accounts, collecting their personal information — including data used to build advertising and recommendation profiles — without ever obtaining that consent.
Its age gate was a formality with a workaround. TikTok operated a restricted experience, “TikTok for Younger Users,” for accounts identified as belonging to under-13s. The government alleged that a child who was blocked could simply try again with a different birthdate, or sign up through a third-party login where no age was requested at all. The gate existed. It was documented. It did not gate.
It did not honour deletion requests. When parents wrote in asking that their child’s account and data be deleted — the specific right COPPA gives them — the government alleged TikTok imposed conditions the statute does not permit, routed requests into processes that terminated without action, and retained data it had been asked to erase.
That third allegation is the one that should carry the most weight, and it is the one that will be quoted least. The first two are about a company failing to build a wall. The third is about a company being told, in writing, by a named parent, about a named child, and not acting.
The Structure of the Payment
The $400 million is not a single cheque. $300 million is payable immediately. The remaining $100 million is contingent — it becomes payable upon entry of an order vacating the prior consent decree entered against Musical.ly.
Read that again, because it is unusual. A quarter of the penalty is conditioned on the government agreeing to lift the enforcement instrument that made this case possible. The 2019 Musical.ly order was the standing obligation TikTok was accused of breaching; retiring it converts a company under an existing decree into a company under a new settlement with a fresh clock.
Whether that is a good trade depends entirely on whether the new obligations are stronger than the old ones. The government’s position is that they are: the settlement requires strengthened age-assurance controls, additional safeguards specific to younger users, and expanded parental oversight of a child’s activity and personal information.
The old order also required things. That is why there was a lawsuit.
Why $400 Million Is and Is Not a Lot of Money
Under COPPA, civil penalties can reach $53,088 per violation — and each child whose data was collected without consent is a violation. With “millions” of under-13 accounts alleged, the theoretical statutory maximum runs into the tens of billions. Settlements always land far below the maximum; that is what settlements are. But the distance here is instructive.
Set it against the two reference points that matter:
- Against other COPPA cases, $400 million is enormous. Google/YouTube paid $170 million in 2019. Epic Games paid $275 million in 2022. Musical.ly itself paid $5.7 million. This is the largest of them.
- Against TikTok’s business, $400 million is roughly 1.7% of an estimated $23 billion in annual revenue — the cost of running the platform for about six days.
A penalty that is historic in its category and immaterial to its target is a penalty that will be paid, absorbed, and disclosed in a footnote. It changes behaviour only to the extent that the non-monetary terms change behaviour, which is why the injunctive relief is the part worth watching.
The Part That Actually Matters
Three provisions in a settlement like this determine whether anything changes:
Age assurance that is actually assured. “Stronger age-related controls” is doing heavy lifting in the announcement. The failure mode in the original complaint was retry-after-rejection and third-party-login bypass. If the new controls do not close both, they close nothing. And every stronger age check imports the problem we covered earlier this month: documents are now trivially forgeable, and age inference — the alternative — means classifying every user, adults included, in order to find the minors. There is no version of this that does not expand data collection somewhere.
Deletion that completes. The right that failed was the simplest one in the statute. A parent asks; the company deletes. Any remedy that does not produce an auditable, time-bound, verifiable deletion pipeline — with a receipt the parent can hold — has not fixed the thing that broke.
Monitoring with teeth. The 2019 order was a compliance obligation without an effective observer. Whether this one comes with independent assessment, reporting cadence, and a credible consequence for the next lapse is the difference between a settlement and a subscription fee.
The Wider Pattern
This lands in the same month as the New Jersey Kids Code Act, which took the opposite approach: rather than relying on a federal regulator to bring one enormous case every few years, it hands parents a $5,000-per-violation private right of action. The two models are being tested against each other in real time.
Federal enforcement produces headlines and consolidated remedies, slowly, on the government’s calendar, subject to the government’s appetite. Private rights of action produce thousands of small, distributed, unglamorous suits that companies cannot absorb as a line item. Industry lobbies furiously against the second and settles comfortably with the first, which tells you which one it believes is expensive.
TikTok’s $400 million is a real number and a genuine achievement for the lawyers who obtained it. It is also a reminder that when the largest children’s privacy recovery in American history costs the defendant less than a week of trading, the deterrent is not the money.
What To Do
-
If your child has or had a TikTok account, request deletion in writing and keep the record. Under COPPA, a parent’s request for deletion of a under-13’s data is a legal right, not a courtesy. Send it through the app’s privacy request form and by email so there is a timestamped trail.
-
Check what a “younger users” account actually restricts. On any platform, the restricted-mode experience is usually about content, not data. Ask specifically what is collected and whether it feeds advertising or recommendation models.
-
Turn off personalised ads in TikTok. Profile → Settings and privacy → Ads → Ads personalisation. It does not stop collection but it cuts the most direct commercial use.
-
Do not let an age check become an ID upload without asking what happens to the document. Retention period, storage location, and whether a third-party verification vendor keeps a copy. If those three answers are not published, the check is a data collection event wearing a safety costume.
-
Watch for the claims process. Large settlements of this type sometimes generate a consumer distribution. If one is announced, it will be posted by the Justice Department — not by anyone who emails you first.



