The Payment Structure Behind the Number
The Justice Department announced on Friday, August 21, 2026, that TikTok, ByteDance, and affiliated entities agreed to pay $400 million to resolve litigation over compliance with the Children's Online Privacy Protection Act, known as COPPA.
TikTok will pay $300 million immediately. The remaining $100 million becomes due once a court order vacates a prior consent decree that had been entered against Musical.ly, the platform TikTok absorbed and replaced. The Department of Justice called the settlement one of the largest recoveries ever obtained in a COPPA case.
The Allegations and Where the Case Was Filed
The Justice Department filed its original complaint in 2024 in the US District Court for the Central District of California, alleging that TikTok and ByteDance failed to meet COPPA's requirements around collecting and handling children's personal information. The Department's Civil Division Enforcement and Affirmative Litigation Branch handled the case after a referral from the Federal Trade Commission.
Associate Attorney General Stanley E. Woodward Jr. said the settlement is a major victory for American children and parents. "The Department's priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations," he said. "This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve."
Assistant Attorney General Brett A. Shumate, who leads the Civil Division, said, "Companies that collect children's personal information must comply with the law. This resolution secures a significant monetary recovery and reflects the Department's commitment to ensuring children receive the full protections that Congress mandated."
Remediation Came After the Complaint, Not Before
TikTok did not stand still after the 2024 complaint. The Justice Department's release notes that the company has since changed its ownership, management, and compliance functions, and has adopted measures to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight. The Department credits these changes with having materially advanced the public interests at stake in the litigation.
None of that changed the size of the check. The $400 million figure was negotiated and announced after the fixes were already underway, meaning the penalty tracked the violation itself rather than the state of the practice at settlement time.
The Same Enforcement Logic Is Reaching Europe
COPPA is a US statute and does not apply to operators outside the United States. But the mechanics of this case carry a lesson that travels: a children's-data violation became a standing liability from the moment it occurred, regardless of when TikTok fixed it or when regulators caught up. Fixing the practice after the fact did not make the $400 million disappear.
For any EU or UK operator running a consumer app or platform that reaches users under 13, or under 16 where GDPR-K and local age-of-consent rules apply, the honest reading is not that COPPA now governs them, because it does not. It is that regulators on both sides of the Atlantic are converging on the same enforcement logic: liability accrues from the moment of the violation, and proactive fixes made before a formal complaint, not after one, are the only way to avoid landing exactly where TikTok and ByteDance did.
Read next: 9th Circuit Clears Way for 3,000+ Addiction Suits | Nvidia H200 Chips Are Now Arriving Inside China



