# TikTok's $400 Million COPPA Bill Is a Record Fine That Still Won't Hurt Enough
The Department of Justice announced Thursday that TikTok, ByteDance, and affiliated entities have agreed to a $400 million settlement over systematic violations of the Children's Online Privacy Protection Act — the largest COPPA penalty in the law's 26-year history. That record should tell you something. Not about how seriously TikTok took children's privacy, but about how long COPPA's teeth have been missing.
## What They Actually Did
The core allegation is familiar to anyone who followed TikTok's 2019 run-in with regulators, back when the platform was still operating under the Musical.ly brand and paid a comparatively trivial $5.7 million to settle similar charges. ByteDance acquired Musical.ly in 2017, rebranded everything as TikTok in 2018, and apparently kept many of the same data collection habits — just at incomparably larger scale.
COPPA requires platforms that knowingly collect data from children under 13 to obtain verifiable parental consent first. TikTok's "younger users" experience was supposed to wall off under-13 accounts from standard data collection. According to the DOJ complaint, the wall had gaps. Children who started accounts as minors sometimes aged through to full-featured profiles without the required consent gates. The platform allegedly retained personal data — location, device identifiers, behavioral profiles — on users it knew or should have known were children.
This isn't a one-off compliance failure. It's the same company, the same structural problem, and now its second COPPA enforcement action in seven years. The dollar amounts just got bigger because the user base did.
## The Arithmetic of Deterrence
ByteDance generated an estimated $100 billion in revenue in 2024. Four hundred million dollars represents approximately 0.4% of that figure.
For context: if a company earning $100,000 a year committed fraud and was fined $400, the incentive structure would not change their behavior. That's the math regulators are working with here, and it's not unique to TikTok. Google and YouTube paid $170 million in 2019 over COPPA violations. YouTube's ad revenue in Q1 2019 alone was $3 billion. These settlements punish at a scale that legal departments can absorb as a line item.
The $400 million figure does break a record. But records are worth less when the underlying law hasn't been meaningfully updated since 1998 — before smartphones existed, before algorithmic recommendation systems existed, before children's media consumption moved almost entirely to platforms designed by attention engineers.
## The Injunctive Terms Are the Real Story
The fine is the headline. The behavioral relief baked into the settlement deserves more attention from the security community.
The settlement reportedly includes requirements that TikTok:
Auditing requirements are where enforcement either develops real teeth or quietly collapses. The FTC's 2012 settlement with Google included audit provisions; Google paid $22.5 million over search advertising violations in 2012 and was still fighting COPPA charges on YouTube seven years later. Auditing only works when auditors have meaningful access and regulators have appetite to act on what the audits surface.
The DOJ and FTC will need to demonstrate sustained attention to TikTok's compliance over the coming years, not just cite this settlement as a win in a press release and move on. Given the political history surrounding TikTok in the United States — the failed forced-sale legislation, the brief app store ban, the ongoing national security debates — "sustained regulatory attention" is not a phrase anyone should assume.
## Children's Data as a Systemic Problem
It would be convenient to frame this as a TikTok problem. It isn't.
Instagram (Meta) settled COPPA charges for $90 million in 2022. Twitch, Snapchat, and dozens of smaller platforms have faced FTC enforcement actions. The ad-tech ecosystem that funds most free consumer internet services is structurally dependent on behavioral profiling at scale, and children's data flows through that ecosystem with few reliable checkpoints.
Age verification online is genuinely hard — not impossibly hard, but hard enough that most platforms have historically preferred compliance theater over real investment. "Enter your birthday" remains the dominant gate. TikTok's younger users mode was a more deliberate attempt than that, but clearly not sufficient.
Several states have moved ahead of federal law. California's Age-Appropriate Design Code, the first such legislation modeled on the UK's equivalent, requires platforms to configure default settings to protect minors and to conduct data protection impact assessments before deploying features likely to be used by children. Courts have challenged pieces of it, but the legislative impulse is spreading. Utah, Arkansas, and Texas have passed their own social media minors legislation, with varying levels of legal durability.
Federal COPPA reform has been discussed in Congress for years without result. The version of the law that governs a $400 million settlement was written when most American households were connecting to the internet through a phone line at 56 kilobits per second.
---
## HackWire Analysis
The TikTok settlement is being reported primarily as a privacy story. For security practitioners, the more actionable lens is what it reveals about the economics of regulatory risk for platforms that collect children's data at scale.
ByteDance has demonstrated twice now that it will absorb COPPA liability and continue operating. The 2019 settlement didn't produce structural change. The 2025 settlement may or may not, depending entirely on the strength of the injunctive terms and the regulators' willingness to enforce them — neither of which is guaranteed.
What's missing from most coverage: the data that was collected and retained improperly doesn't disappear when a settlement is signed. The behavioral profiles, device identifiers, and location data collected from millions of children during TikTok's growth years exist somewhere in ByteDance's infrastructure. Deletion orders are part of this settlement, but auditing actual deletion at scale — across distributed data systems, third-party ad partners, and analytics pipelines — is technically and operationally brutal. History suggests that "we deleted it" is frequently aspirational.
For organizations in the education, edtech, or consumer app space: this settlement is a signal that COPPA enforcement is becoming materially expensive, and the FTC under current leadership has appetite to pursue large targets. If your platform's age verification relies on self-reported birthdays, you are operating on borrowed time. The audit requirement imposed on TikTok will establish precedent for what compliance actually looks like — watch those terms carefully, because they'll show up in future enforcement actions against smaller players.
The record fine is the least interesting part of this story. The question is whether anyone learned anything.
— HackWire Editorial
---
## Related Coverage