TikTok’s $400M Fine Is a Checklist for Your Own Child Data Compliance

by Rebecca Sutton

TikTok’s $400 million settlement with the US Department of Justice, announced on 21 August 2026, was built on a handful of specific failures. Parental consent went unverified. A “kids” account mode collected more data than it should. Deletion requests went unactioned. None of that is unique to a video app with a billion users. A UK business of any size can carry the same gaps for years without noticing, because child data compliance rarely gets tested the way a firewall rule or a login page does. Here is what the case should prompt any business to check.

A professional reviewing paperwork at a desk, representing a child data compliance review

What the settlement covered

The $400 million breaks down into two parts. TikTok pays $300 million right away. A further $100 million is due once a court vacates an earlier consent decree. That decree ties to Musical.ly, the app ByteDance bought in 2017 and merged into TikTok. It traces back to a 2019 COPPA case against Musical.ly itself, so TikTok was already meant to be under closer watch when the newer violations were alleged. The Department of Justice filed the case in August 2024, after a referral from the Federal Trade Commission. It called the settlement one of the biggest COPPA payouts on record.

TikTok disputes parts of the complaint. The firm says much of what prosecutors described is old news, either wrong or long since fixed. Either way, the size of the number is what gets attention. The mechanics behind it, an unverified consent flow and a deletion process that didn’t finish the job, are the part worth studying.

Work out if you hold children’s data

Start with the honest question: could someone under 13 reasonably use your website, app or online form? Under UK GDPR, a child needs verifiable parental consent before their data can be processed lawfully, right up until they turn 13. That threshold catches more businesses than expect it. Retailers with loyalty schemes get caught out. So do schools’ suppliers and gyms with family memberships. Any service with an open sign-up form and no age verification is at risk too.

If you cannot answer that question with confidence, that is itself the finding. Run a quick audit of every form, account type and data collection point on your site. It should tell you whether age is asked at all, and what happens to the answer next.

Test your consent flow, don’t just document it

TikTok’s case turned partly on whether consent was genuinely verified rather than just requested. A checkbox that says “I am over 13” is not verification. It is a formality a child can tick in half a second. Walk through your own signup process as if you were an under-13 user. Does the system stop you, or does it just ask and move on?

Treat this as a functional test, run periodically, not a one-off design decision from years ago. Product changes creep in over time. A new signup flow, a third-party plugin, or an app update can quietly reopen a gap that was closed at launch.

Check that deletion requests actually delete

Prosecutors said TikTok failed to honour parents’ requests to remove their children’s data. That is a process failure as much as a technical one. A request comes in, gets logged, and then nothing downstream purges the record from every system it touched. Backups, analytics tools and marketing platforms are the usual places data survives after the primary database says it’s gone.

Ask whether your business could prove, today, that a deletion request from two years ago was completed everywhere the data went. If the honest answer is “probably,” close that gap now. Don’t wait for a regulator, or an angry parent, to ask the same question.

Know which rules apply where you operate

COPPA is US law, but UK businesses are not exempt from similar duties. The Information Commissioner’s Office enforces its own Children’s Code. It sets out 15 standards for services likely to be accessed by under-18s. These cover everything from default privacy settings to how much data gets collected in the first place. TikTok was separately fined €345 million in 2023 for children’s data handling under EU rules. This is not a single-regulator problem confined to Washington.

If your business operates across the UK and EU, map which rulebook applies to each product and market. Build child data compliance to the strictest applicable standard, since that is usually the safest baseline anyway.

Make child data compliance part of the security routine

The practical fix is straightforward. Fold child data compliance into whatever review process already covers access controls and data handling. Age verification, consent capture and deletion workflows behave like any other control. They can be checked, tested and shown to work, or shown to have quietly stopped working. A $400 million settlement is an expensive way to find out which one it was.

In practice, that means picking an owner for the check, not just the policy. Someone needs to attempt the under-13 signup. A colleague should trace a deletion request end to end. And somebody needs to confirm the age gate still blocks what it’s supposed to block after the last product update. None of that needs special tools, only a habit of testing the control instead of trusting the document that describes it.

What good child data compliance looks like

A business with this under control can usually answer three questions without hesitation. Does every form or sign-up flow that could reach an under-13 user verify age, not just ask for it? When a parent requests deletion, is there a record showing it reached every system that held a copy? That includes backups and any third-party marketing tools. And when was the age-verification and consent flow last tested by someone other than the person who built it?

A vague answer to any of those is the starting point, not a reason to worry. TikTok’s settlement is a costly example of what happens when the same three questions go unanswered for years. Most UK businesses can close the child data compliance gap with a modest, one-off review rather than a nine-figure lesson.

Subscribe to our newsletter

Honest updates, straight to your inbox. Unsubscribe any time.

You may also like