A $400 Million Settlement Over TikTok's Handling of Children's Data

The US Department of Justice announced on August 21, 2026, that TikTok and its parent company ByteDance will pay $400 million to settle litigation over how the platform handled children's privacy, resolving claims tied to the Children's Online Privacy Protection Act.

The Department of Justice's own press release, titled "Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children's Privacy Litigation," frames the case as one of the largest child-privacy enforcement settlements on record in the United States, and the figure was independently corroborated the same day by Bloomberg, Variety, TechCrunch and Fox Business, all reporting from the same DOJ release.

How the $400 Million Breaks Down

The settlement splits into two distinct payments rather than one lump sum: $300 million is due immediately, while the remaining $100 million is tied to vacating a consent decree that dates back to Musical.ly, the app TikTok absorbed and rebranded years before this case was filed.

Immediate payment$300 million
Tied to vacating the Musical.ly-era consent decree$100 million
Total settlement$400 million
EU DSA maximum fine, comparable mechanismup to 6 percent of a platform's global annual turnover

One Country, One Route: How the US Enforced This

The United States reached this outcome through a Department of Justice litigation settlement, a case-by-case mechanism that produces a negotiated dollar figure and a set of binding compliance terms rather than a standing fine schedule.

The European Union and the United Kingdom are building parallel but structurally different regimes for the same underlying problem: the DSA gives the European Commission and national Digital Services Coordinators the power to fine a platform up to 6 percent of its global annual turnover for systemic risks to minors, while the UK's Online Safety Act gives Ofcom enforcement powers over platforms with under-13 users, with the Information Commissioner's Office holding a parallel data-protection track.

Why a Litigation Settlement Doubles as a Benchmark Figure

A $400 million settlement is not a regulatory fine schedule, but it is now a real, citable number for what years of under-taking child-privacy risk around a known legacy product can cost once it is finally litigated, and that number travels well beyond the US case that produced it.

Any EU or UK company running a product with a mixed-age user base, whether a game, an ed-tech platform, a social feature, or simply a signup flow that does not reliably screen out under-13 users, now has a figure to weigh against the cost of building age-verification and data-minimization controls properly the first time.

Beyond the Settlement: What an EU or UK Owner Should Actually Do

The practical move is not to wait for a DSA risk-assessment request or an Ofcom inquiry before checking a signup flow, but to treat the $400 million figure as the opening number in a budget conversation about the cost of getting under-13 data handling wrong for years rather than months.

That means auditing whether a product's age-gate is cosmetic or functional, whether analytics and ad-targeting pipelines quietly retain data from users who self-identified as under 13, and whether a legacy feature inherited from an acquisition, in the way TikTok inherited Musical.ly, is still running under old assumptions nobody has revisited.

The Number Regulators on Both Sides of the Atlantic Will Now Cite

US enforcement and EU or UK enforcement are different systems, but both are now pointing at the same underlying failure mode, and the $400 million settlement gives every regulator and every platform a shared reference point for how expensive it becomes to treat children's privacy as an afterthought.