Site navigation

TikTok Handed €345M Fine for Handling of Children’s Data

Elizabeth Greenberg

,

tiktok fine
The social media firm has faced fines previously for its handling of children’s data in the UK. 

The Irish Data Protection Commission (DPC) has announced a fine of €345M (£296.92m) for the social media company TikTok, after finding their handling of children’s data to not be compliant with GDPR.

In this case, which was originally brought up in 2021, users questioned if TikTok was in violation of GDPR for having users under the age of 13 on the platform despite what was deemed to be insufficient age-verification methods.

While TikTok has a minimum user age of 13, the DPC was made aware of and found instances of children under 13 using the social media platform.

Further, the company came under fire for making underaged user’s profiled public-by-default, meaning that anyone could automatically see the profiles, videos, and comments posted by underaged users, unless users changed their settings to private.

Their “family pairing” feature also came under scrutiny in the case, which allowed an adult’s TikTok profile to be paired with a child’s with no verification of their familial relationship. This made it possible for adults to send direct messages to users over the age of 16.

After being viewed by the Irish DPC, the draft decision was sent to all Supervisory Authorities Concerned (CSAs) in September for further scrutiny and to determine the amount of the fine.

Contentions from the Italian and German regulatory bodies sent the case to the overriding European Data Protection Board (EUDPB), where the body ruled in favour of finding a new GDPR infringement over the principle of fairness in the use of “dark patterns” – where a platform users methods to trick users into harmful but not necessarily illegal practices like purchasing overpriced products or entering subscriptions with no easy method to cancel.


Recommended


The overriding decision was finalised in September, and TikTok was given three months to come under GDPR compliance.

The Chinese-owned social media company was previously fined for mishandling of child’s data in the UK, resulting in a £12.7m fine from the Information Commissioner’s Office.

The fine comes on the tails of the EU’s Digital Services Act coming into effect, which places certain expectations on social media giants like TikTok, Facebook, and X (formerly known as Twitter) for safety and data protection, with particular rules for the handling of children’s data.

Tags: ,

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data