INTELLIGENCE BRIEF
firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session firm for AML Failings FATF grey-lists three new jurisdictions ahead of plenary session New EU AMLD6 implementation deadline configuration FATF grey-lists three new jurisdictions ahead of plenary session
vol VII . ISSUE 24 . 24 JUN 2026
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Case
Breaking . AML

TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Case

Insight . Intelligence . Accountability

32 Views
0 Comments
News & Analysis 02 Sep, 2026

A new wave of professionals is transforming Governance, Risk, and Compliance from a rigid framework into a dynamic force for trust, innovation, and resilience. Governance, Risk, and Compliance (GRC) has long been associated with boardrooms and bureaucracy—a domain reserved for executives and auditors. But that image is changing fast.

TikTok and its parent company ByteDance have agreed to pay $400 million to settle a U.S. government lawsuit alleging the platform collected personal information from millions of children without their parents' consent, according to BBC reporting, closing a case that began two years ago and adding another substantial figure to the growing cost of getting children's privacy wrong.

The settlement resolves a Justice Department lawsuit filed in 2024 under the Biden administration. The government accused TikTok and ByteDance of collecting "vast amounts of data" from users under 13 in violation of the Children's Online Privacy Protection Act, or COPPA, which restricts the collection of personal information from children and generally requires parental consent.

TikTok and ByteDance will pay $300 million to the Justice Department immediately. The remaining $100 million will be paid when the government vacates a 2019 consent decree with the Federal Trade Commission involving Musical.ly, the short-form video platform that became TikTok.

The numbers are unusually large for a COPPA case. YouTube paid $170 million in 2019 to settle allegations brought by the FTC and New York attorney general. Epic Games agreed to a $275 million penalty in 2022 over alleged COPPA violations involving Fortnite. Musical.ly's own settlement in 2019 cost $5.7 million.

"Children and parents are better protected today than they were when this case began," Assistant Attorney General Brett Shumate said, according to the BBC.

The U.S. case is no longer ByteDance's only recent encounter with a regulator over the data of young people.

Four days after the U.S. settlement was reported, Brazil's National Data Protection Authority, or ANPD, fined ByteDance $29.81 million (153.8 million reais) for allegedly violating the country's General Data Protection Law, Reuters reported. The regulator said ByteDance's Brazilian unit had processed personal data belonging to teenagers between 13 and 18 without a valid legal basis.

The Brazilian case is different in law and scope from the U.S. action. It is also difficult to miss the resemblance in the underlying problem. ANPD estimated that TikTok may have processed data belonging to at least 8 million children during the period it examined. The regulator pointed to shortcomings in TikTok's age-verification system, according to Reuters.

One feature drew particular attention. TikTok's "logged-out feed" allows people to browse content without creating an account, something ANPD said enabled widespread use by children and teenagers in Brazil without effective age checks. The regulator said the feature is available in Brazil but not in the U.S. or Europe, where users must register to gain access. It also found that TikTok lacked adequate safeguards for the risks created by processing children's and teenagers' data on such a large scale.

TikTok disputed the relevance of some of those findings to its current practices. The company told Reuters that the Brazilian penalty concerned conduct dating to 2021 and did not take into account a compliance plan approved by ANPD in 2025 or safeguards introduced since then. TikTok said its measures comply with Brazilian data protection law and that it would continue working with the regulator while considering possible legal steps.
Brazil's regulator did not stop at a fine. ByteDance must delete personal data belonging to teenagers registered on TikTok when the necessary parent, guardian or other legal arrangements are not provided and documented within 60 days. Failure to meet the deletion, reporting or notification requirements can bring additional daily penalties.

The U.S. lawsuit reached further back into TikTok's history. Musical.ly agreed in 2019 to pay $5.7 million to resolve FTC allegations that it illegally collected children's personal information. The resulting consent decree required the company to obtain parental consent before collecting personal information from users under 13. Five years later, federal prosecutors alleged that the problem persisted on a far larger platform.

When the Justice Department sued TikTok and ByteDance in 2024, government attorneys said TikTok was "directed to children" but did not effectively determine the ages of its users or obtain parental consent for children under 13. The government alleged that millions of young users were affected.

The Justice Department did not announce additional action against TikTok beyond the financial settlement, the BBC reported. It did note that TikTok had "undergone significant changes" since the case began, including changes to its ownership, privacy practices and platform controls for young users.

Ownership is no small footnote here. The lawsuit was filed during Washington's prolonged fight over ByteDance's control of TikTok, when then-President Joe Biden backed legislation that threatened the platform with a U.S. ban unless its American operations were divested. President Donald Trump later supported divestment, which took place last year.

TikTok's U.S. operations are now 81% owned by a consortium of investors, while ByteDance retains a 19% stake, according to the BBC. The settlement concerns TikTok's China-based operations rather than the newly separated U.S. business. ByteDance remains privately held and was most recently valued by investors at $550 billion, the BBC reported.

The corporate structure has changed. The regulatory question that produced the lawsuit has not disappeared. COPPA was enacted in 2000, long before TikTok could place an endless stream of algorithmically selected videos in a child's hand. Its central requirement is that companies covered by the law generally need verifiable parental consent before collecting personal information from children under 13.

Knowing when that requirement applies means knowing who is using the service. That is where age verification moves from a product feature to a compliance control, and where the American and Brazilian cases begin to look more closely related despite resting on different laws.

The consequences are spreading beyond ByteDance. Meta is defending a separate case brought by attorneys general from 29 states alleging COPPA violations involving Facebook and Instagram. A jury trial began during the week of Aug. 17, according to the BBC, with the states accusing Meta of targeting children and profiting from their use of its platforms. Potential penalties could reach into the hundreds of billions of dollars.

Those allegations remain unresolved. They nevertheless arrive alongside an enforcement record that has become progressively harder for large platforms to dismiss as a manageable cost of doing business.

Musical.ly's $5.7 million settlement came in 2019. YouTube paid $170 million later that year. Epic Games agreed to a $275 million COPPA penalty in 2022. TikTok and ByteDance have now agreed to pay $400 million in the U.S., while ByteDance faces another $29.81 million penalty and corrective measures in Brazil over separate allegations involving teenagers' data.

For privacy and compliance teams, the more useful comparison is not between the dollar amounts. It is between the controls regulators keep examining. Can a platform reliably distinguish children from adults? Does it have a lawful basis for collecting their data? Can it demonstrate parental consent when the law requires it? And when a user never creates an account at all, does the machinery still work?

Those are implementation questions, which is precisely why they are becoming expensive ones. TikTok did not respond to the BBC's request for comment on the U.S. settlement.

Leave a comment

Your email address will not be published. Required fields are marked with *

Similar Articles
A network that laundered more than four million euros from scams by sending the money to Nigeria falls

A network that laundered more than four million euros from scams by sending the money to Nigeria falls

Spanish Police Bust €4 Million International Money Laundering Ring Bound for Nigeria. The Spanish Civil Guard has dismantled a criminal network responsible for laundering over €4 million generated through cyber fraud, CEO scams, and identity theft across Europe. The organization utilized "smurfing"—splitting large illicit funds into more than 9,200 small-wire transfers using falsified passports and stolen identities—to bypass anti-money laundering controls and funnel cash into Nigeria. The two-phase operation led to 20 arrests, investigations into 11 others, and raids targeting key leaders in Bilbao as well as several complicit money transfer agencies.

Read Full Brief
07 Aug 2026
U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

U.S. Regulators Hit UBS With $173 Million in Coordinated AML Enforcement Action

Eight years after promising regulators it would fix persistent weaknesses in its anti-money laundering controls, UBS is paying for what those regulators say it failed to finish.

Read Full Brief
04 Aug 2026
FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

FATF's June Plenary Trims the Grey List — Africa's Compliance Burden Isn't Going Away

The Financial Action Task Force closed its June 2026 plenary by removing Algeria and Namibia from its list of jurisdictions under increased monitoring, while adding Bosnia and Herzegovina and Iraq. For African compliance functions, the headline delisting matters less than what it confirms about the direction of travel.

Read Full Brief
04 Aug 2026
RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

RegTech Won't Save You From a Bad Governance Model. It Will Just Automate It Faster.

Every compliance leader I meet is being asked, in some form, what their AI strategy is. Almost none of them are being asked the more important question first: what is your governance model for the AI you already have?

Read Full Brief
04 Aug 2026
The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

The EU AI Act's August Deadline Arrives — Just Not the One Everyone Expected

High-risk AI obligations for financial services have been pushed back sixteen months. Transparency rules for chatbots and synthetic media have not moved at all — and enforcement power against general-purpose AI providers switches on this week.

Read Full Brief
04 Aug 2026
Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Third-Party Risk Is a Board Issue Now, Not a Procurement Checklist

Outsourcing does not outsource accountability. Regulators have said this for years. Boards are only now starting to act as though they believe it.

Read Full Brief
04 Aug 2026
Recommended Articles
See all

No recommended articles found.