← Back to the full issueComing soon visits
$400m announced

TikTok: the conditional $100 million inside the 400

The settlement announced by the Department of Justice provides for $300 million, plus $100 million if a court vacates the earlier Musical.ly injunction. It resolves allegations without a finding of liability.

Areas of law
Keywords

Case statusUS settlement announced · $300m + conditional $100m · no finding of liability

Smartphone screen displaying the TikTok app icon.
Image and licence. Adapted from “TikTok app” by Solen Feyissa, CC BY-SA 2.0, via Wikimedia Commons. Changes: crop and Law Right optimisation. Wikimedia Commons ↗ · Licence ↗

01

What the settlement actually says

On 21 August, the Department of Justice announced a settlement with TikTok and ByteDance over allegations involving data of children under 13 and compliance with COPPA.

The structure is precise: $300 million is payable; a further $100 million would follow if the court grants TikTok’s request to vacate the earlier Musical.ly injunction. Writing only “$400 million fine” would erase that condition.

The release also describes controls TikTok says it has already improved. They should not be recast as new undertakings imposed by the settlement. There is no determination of liability.

The payment structure belongs ahead of the headline: $300 million is immediately payable. The remaining $100 million becomes payable only when a court vacates the earlier injunction against Musical.ly.

The complaint alleged that children could create regular accounts, data was collected or retained without adequate notice and parental consent, and some deletion requests were mishandled. TikTok disputed the claims; settlement avoids a judicial determination.

02

Why Europe should watch

COPPA is US law. The design problem is not. The GDPR gives children special protection; the Digital Services Act adds safety duties and restricts, among other things, certain profiling-based advertising to minors.

Age assurance must be proportionate: strong enough to protect and restrained enough not to build a fresh surveillance database.

A date-of-birth field is not a barrier; it is a door with a sign on it. Age assurance should match the risk without becoming a reason to collect everyone’s identity.

The EDPB emphasises necessity, proportionality, data minimisation, purpose limitation, security and effective redress. Protecting minors does not justify building a new database about every user.

03

Your useful move for Monday

  1. Separate what the settlement imposes from what the company says it already does.
  2. Test how users can bypass the age-check flow in practice.
  3. Minimise data used to estimate or verify age.
  4. Write for a young reader, then ask that reader to test the words.
  5. Separate proof of age, civil identity and public profile wherever possible.
  6. Document errors and redress: false age, family account, challenge and deletion.

The $400 million, without the shortcut

  1. $300m immediately payable
  2. $100m conditional
  3. No finding of liability

Child protection is architecture: cautious defaults, minimal data, short explanations and an easy exit.

Sources and verificationOpen the sources +
Read the full issue

Your network may not share an email address

Secure sign-in will become active once the app has been approved by the network. For this first issue, enter your email below. Your network choice is recorded only as the source; nothing is posted to your account.

LexiTalk to Lexi