Jessica Entwistle
August 24 2026
The BBC reports that TikTok has agreed to pay $400 million to settle a 2024 lawsuit brought by the US Department of Justice, which accused the company and its parent ByteDance of violating child privacy laws by collecting "vast amounts of data" on millions of users under the age of 13. Under the terms of the settlement, TikTok will pay $300 million immediately, with an additional $100 million contingent on the vacating of a prior consent decree. The lawsuit alleged that TikTok knowingly allowed children to create accounts, collected their personal information without parental consent, and failed to implement adequate age verification or data protection measures. The settlement is one of the largest child privacy enforcement actions in US history and reflects growing regulatory pressure on digital platforms to protect children online.
While this is a US-focused enforcement action, it has broader implications for UK organisations operating digital platforms or services that may attract child users. The UK has its own robust child safety framework under the Age Appropriate Design Code and the Online Safety Act, and regulators including the Information Commissioner's Office have made clear that protecting children online is a priority. This settlement demonstrates the financial and reputational consequences of failing to implement effective age assurance, parental consent mechanisms and data minimisation practices. For UK businesses, it serves as a reminder that child safety and privacy are areas of intense regulatory scrutiny, and that enforcement actions can result in significant penalties even for well-known global platforms. The case also highlights the operational challenge of implementing age verification in a way that is both effective and privacy-preserving, a balance that many organisations struggle to achieve. The UK's Online Safety Act places legal duties on platforms to prevent children from accessing harmful content and to implement proportionate systems and processes to protect child users, making this a live compliance issue for many organisations.
UK businesses operating platforms, apps or services that may be accessed by children should review age verification processes, data collection practices, and compliance with the Age Appropriate Design Code and Online Safety Act. Consider whether your organisation has clear policies on how to handle child users and whether those policies are being consistently applied across all products and services. Review whether your organisation collects, processes or shares data about children, and if so, whether appropriate safeguards are in place, including parental consent mechanisms, data minimisation and retention limits. Ensure that your organisation has conducted a Data Protection Impact Assessment for any services that may be accessed by children, and that privacy by design principles have been embedded into product development. Consider whether your organisation has implemented effective age assurance measures that are proportionate to the risk, and whether those measures are regularly tested and reviewed. Finally, review whether your organisation has clear governance and accountability structures in place for child safety, including senior leadership ownership and regular reporting to the board on compliance with child protection obligations.
Source: BBC