
UpTrajectory Review
TikTok and ByteDance have agreed to pay $400 million to settle a Department of Justice lawsuit alleging violations of children's online privacy law. The suit, filed in August 2024, accused the companies of failing to obtain parental consent before collecting personal information from users under 13, a core requirement of the Children's Online Privacy Protection Act (COPPA). The settlement amount is substantial but notably lower than the $5.7 billion fine the FTC levied against Meta for similar violations in 2019, suggesting either narrower scope or negotiated compromise. What the Guardian excerpt omits—likely covered in the full piece—are the specific data practices at issue, whether the settlement includes structural changes to TikTok's operations, and how this interacts with the separate, ongoing national security review of ByteDance's US presence.
For small business operators running apps or online services, this settlement is a direct signal that COPPA enforcement remains active and costly, even against well-resourced defendants. The law applies to any service 'directed to children' or with actual knowledge of under-13 users—not just obvious kid-targeted platforms. Many small operators assume COPPA is a concern only for major social networks, but the FTC has consistently pursued smaller gaming apps, educational tools, and even connected toys. The $400 million figure here sets a public benchmark: regulators will extract serious money, and 'we're still growing' is not a defense. If your service allows any user interaction, content creation, or behavioral tracking, you need a clear age-gating and consent workflow now, not after a complaint.
What is genuinely new is the DOJ's direct involvement rather than FTC-led action, which may signal a shift in federal enforcement strategy or simply reflect the Biden administration's multi-pronged pressure on TikTok specifically. The settlement comes amid parallel congressional efforts to force ByteDance's divestiture of TikTok on national security grounds—raising the question of whether privacy enforcement is being used as leverage in the broader geopolitical contest. We are skeptical that this settlement resolves anything meaningfully for TikTok's US future; the national security review operates on entirely separate legal authority. The company may be paying to remove one variable from a complex equation, but the existential threat of forced sale or ban remains unresolved.
The downstream effects split unevenly across the digital economy. Larger platforms with dedicated compliance teams will absorb this as a cost of doing business and likely lobby for clearer federal privacy legislation that preempts patchwork state laws. Smaller operators face a more precarious position: without TikTok's legal resources, they are more vulnerable to enforcement but also less visible to regulators—until a competitor complaint or media investigation surfaces. App store operators Apple and Google may tighten age-rating enforcement, passing compliance burdens downstream to developers. The settlement also likely strengthens plaintiff attorneys in private COPPA class actions, which can run parallel to government enforcement and extract additional damages.
Watch whether the full settlement terms, when released, include a compliance monitor or mandated third-party audits—these would signal that regulators are demanding structural accountability beyond financial penalty. Also monitor whether this DOJ approach expands to other platforms; a pattern of Justice Department privacy suits would represent a meaningful escalation from FTC primacy. For operators, the actionable move is immediate: audit your current age verification, document your data retention and deletion practices for under-13 users, and review whether your advertising or analytics integrations might be 'collecting' information in ways COPPA defines broadly. The $400 million headline is attention-grabbing, but the regulatory logic behind it applies at any scale.
The broader context is a federal privacy environment that remains fragmented and politically volatile. COPPA, passed in 1998, predates the smartphone and has been patched rather than overhauled. State laws in California and elsewhere are creating overlapping obligations. For small businesses, this uncertainty is itself a cost—legal ambiguity favors those who can afford counsel and risk. The TikTok settlement does not clarify this landscape; it merely confirms that enforcement teeth remain sharp. Operators should treat children's privacy not as a checkbox compliance issue but as a structural design requirement, built into product development from inception rather than retrofitted under regulatory pressure.
Takeaway: Audit your app's age verification and parental consent workflow now—COPPA enforcement applies at every scale, not just to platforms like TikTok.
Excerpt from the original — The Guardian US
The DoJ sued TikTok and its former parent company in August 2024 for allegedly failing to protect children’s privacy and collecting their informationTikTok and its Chinese former parent company ByteDance on Friday agreed to a $400m settlement to resolve the US Department of Justice’s allegations that the short-form video app violated children’s online privacy.The justice department sued TikTok and ByteDance in 2024 for allegedly failing to protect children’s privacy and illegally collecting their information. The defendants were accused of violating a law requiring online services aimed at children to obtain parental consent to collect personal information from users under age 13. Continue reading…