TikTok Reaches $400 Million Settlement With US Justice Department Over Children’s Privacy
TikTok agrees to a $400 million settlement with the US Justice Department over children's privacy violations.
Summary
TikTok has agreed to pay $400 million to the U.S. Justice Department to settle a lawsuit alleging violations of federal children's privacy laws. The settlement includes an immediate payment of $300 million and an additional $100 million pending the vacation of an earlier consent decree against its predecessor, Musical.ly. The lawsuit focused on allegations that TikTok and ByteDance illegally collected personal information from children under 13 without parental consent and failed to delete accounts upon request.
Full text
TikTok has reached a $400 million settlement with the U.S. Department of Justice, ending a 2024 lawsuit alleging the company violated federal children’s privacy laws. The DOJ said Friday that TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. “This settlement is a major victory for American children and parents,” said U.S. Associate Attorney General Stanley E. Woodward Jr. in a statement. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.” Since the DOJ’s lawsuit in 2024, TikTok has undergone major changes, most notably in the ownership structure of its U.S. arm. In January, the social video platform company signed agreements with major investors including Oracle, Silver Lake and the Emirati investment firm MGX to form the new TikTok U.S. joint venture. Representatives for TikTok did not immediately respond to a message for comment Friday. The latest lawsuit focused on allegations that TikTok and its China-based parent company ByteDance violated a federal law that requires kid-oriented apps and websites to get parental consent before collecting personal information of children under 13. It also says the companies failed to honor requests from parents who wanted their children’s accounts deleted, and chose not to delete accounts even when the firms knew they belonged to kids under 13.Advertisement. Scroll to continue reading. The settlement comes as social media companies face an avalanche of lawsuits over children’s safety and privacy and a growing number of countries are banning young kids and teens from social media apps. Instagram’s parent company, Meta Platforms, is currently on trial in federal court in Oakland, California, over allegations it violated the 1998 Children’s Online Privacy Protection Act, or COPPA, along with various state statutes. Related: Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind Related: Timeless Compliance: Why Better Questions Beat Bigger Frameworks Written By Associated Press Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Associated Press AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian HackingCyberattack Hits Liechtenstein’s Register of People Behind Companies and FoundationsCyberattacks on Minnesota Water Systems Investigated as Officials Warn About Iranian HackersEU to Crack Down on AI Deepfakes, Illicit Imagery and Hacking With New Team in BrusselsUS Bans Foreign-Made Humanoid Robots, Targeting China Over National SecurityFor Some, So-Called ‘Skynet Day’ Came too Close to Sci-Fi After a Rogue Agent Hacked Into a StartupEU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying CampaignTrump Administration Lifts Restrictions on Anthropic’s Claude Models After Cybersecurity Alarm Latest News Rethinking Application Security for the AI EraIran-Linked Hackers Shut Down UK Power Plant for Four DaysAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightFormer NSA Director Paul Nakasone Launches National Security Advisory FirmIn Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused BugEncrypted Prompts Bypass AI Safety Guardrails in Grok and GeminiNew Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveVensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.WISeKey has appointed Alexander Hirsch as Group Chief Marketing Officer.UltraViolet Cyber has named Andrew Park Chief Information Security Officer.More People On The MoveExpert Insights Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email