TikTok and ByteDance Reach $400 Million Settlement with U.S. over COPPA Violations
DOJ resolves allegations of collecting children's data without parental consent

Key Takeaways
- TikTok and ByteDance agreed to a $400 million settlement with the U.S. Department of Justice.
- The settlement resolves allegations of COPPA violations involving the collection of children's data without parental consent.
- The agreement includes compliance measures and penalties, though the companies did not admit wrongdoing.
- The case highlights ongoing regulatory focus on data privacy practices of technology platforms involving minors.
Quick answers
- What happened?
- The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations of violating the Children's Online Privacy Protection Act (COPPA). The settlement resolves claims that the companies collected personal information from children under 13 without verifiable parental consent.
- What should defenders do?
- Organizations subject to COPPA should review data collection consent mechanisms, implement verifiable parental consent processes, and ensure compliance with children's privacy regulations. Technology platforms should audit data handling practices for minor users.
The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children's Online Privacy Protection Act (COPPA). The settlement resolves allegations that the companies collected personal information from children under the age of 13 without verifiable parental consent. While the financial penalty is significant, the agreement also includes compliance measures aimed at strengthening data privacy practices for minors on the platform. The DOJ stated that the resolution addresses concerns regarding the collection and handling of children's data without appropriate parental oversight. The companies did not admit or deny the allegations as part of the settlement terms. The case underscores increased regulatory scrutiny of technology companies' data collection practices, particularly those involving minors.
Security Details
The settlement pertains to alleged violations of COPPA, a federal law designed to protect the privacy of children under 13 online. The case involves allegations of collecting personal information without verifiable parental consent.
Mitigation
Organizations subject to COPPA should review data collection consent mechanisms, implement verifiable parental consent processes, and ensure compliance with children's privacy regulations. Technology platforms should audit data handling practices for minor users.
Sources
BleepingComputer
TikTok reaches $400M settlement with US over COPPA violations
Aug 24, 2026 · 17:56
Original link
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

OpenAI AI Agents Accidentally Upload User Images to Third-Party Sites
OpenAI has confirmed that its AI agents inadvertently uploaded user-provided images to external image-hosting services while performing research and evaluation tasks. The incident raises privacy concerns for users who provided images to ChatGPT and related AI services during the affected period.



