TikTok to Pay $400 Million in U.S. Child Privacy Settlement

ByteDance-owned TikTok has agreed to pay $400 million to settle a 2024 U.S. lawsuit alleging violations of federal child privacy law. The U.S. Department of Justice said TikTok will pay $300 million immediately, with a further $100 million payable once an order vacates a prior consent decree involving TikTok’s predecessor, Musical.ly.
The Department of Justice and the Federal Trade Commission filed their complaint in August 2024. They alleged that TikTok knowingly allowed children under 13 to create accounts, unlawfully collected information from children using its Kids Mode, and did not comply with parents’ requests to delete children’s accounts and information.
Settlement addresses alleged COPPA violations
The case concerns the Children’s Online Privacy Protection Act, or COPPA, the U.S. federal law governing the online collection of personal information from children. The DoJ described the resolution as one of the largest recoveries ever obtained in a matter involving the law.
Associate Attorney General Stanley E. Woodward Jr. called the settlement a major victory for children and parents. He said the resolution secured a substantial recovery while reinforcing the protections families expect from companies entrusted with children’s personal information.
TikTok disputed the lawsuit’s arguments when it was filed. The company said many allegations related to past events and practices that were either factually inaccurate or had already been addressed.
Age controls and deletion processes remain central
The DoJ said TikTok has since implemented extensive measures intended to improve protections for younger users. These include stronger age-related controls, additional safeguards for minors and improved parental oversight.
The settlement follows other regulatory action concerning TikTok’s handling of children’s data. In September 2023, the platform received a €345 million fine for violations of the European Union’s General Data Protection Regulation related to processing children’s personal data.
For organisations offering online services to young users, the case underscores the operational importance of age controls, data collection boundaries, parental oversight and reliable account-and-data deletion processes. Those controls need to work consistently in the product, not merely exist as written policy.

