Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

TikTok Pays $400M Settlement Over COPPA Violations for Improper Collection of Children’s Data

TikTok, ByteDance and affiliates agreed to a $400 million settlement after the DOJ alleged the platform collected personal information from users under 13 without parental consent. The case underscores the importance of auditable consent‑management and DSAR processes for SOC 2 privacy compliance.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

TikTok Settles $400 Million Over COPPA Violations for Improper Collection of Children’s Data

What Happened — The U.S. Department of Justice announced a $400 million settlement with TikTok, its parent ByteDance, and affiliated entities for alleged violations of the Children’s Online Privacy Protection Act (COPPA). The lawsuit claimed TikTok allowed users under 13 to maintain regular accounts, collected and retained their personal information without parental consent, and failed to delete data when parents requested removal.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure to meet SOC 2 Privacy Principle 5 (Consent & Data‑Subject Rights) and highlights the need for documented, auditable consent‑management processes.
  • Continuous evidence of age‑verification controls, data‑retention policies, and DSAR (Data Subject Access Request) workflows is essential to demonstrate compliance with COPPA, GDPR, CCPA, and SOC 2 during audits.

Who Is Affected – Social‑media platforms, consumer‑facing SaaS applications, ad‑tech providers, and any organization that collects personal data from children under 13.

Recommended Actions –

  • Map your consent‑capture and age‑verification mechanisms to SOC 2 Privacy controls and record evidence in a centralized audit repository.
  • Conduct a privacy impact assessment (PIA) focused on minors’ data, update retention schedules, and test DSAR processes for timely deletion.
  • Deploy continuous monitoring of consent‑management workflows (e.g., Verisq CookiePLUS) to generate real‑time compliance evidence.

Source: BleepingComputer

Technical Notes – The DOJ alleges that TikTok’s “Kids Mode” was bypassed, allowing under‑13 accounts to exist in the standard product. Data types included names, email addresses, device identifiers, and usage analytics. No specific CVE is involved; the breach stems from inadequate policy enforcement and system design.

📰 Original Source
https://www.bleepingcomputer.com/news/legal/tiktok-reaches-400m-settlement-with-us-over-coppa-violations/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →