TikTok Is Hit With $368 Million Fine Under Europe’s Strict Data Privacy Rules

European regulators slapped TikTok with a $368 million fine for failing to protect children’s privacy, the first time that the popular short video-sharing app has been punished for breaching Europe’s strict data privacy rules.

TikTok fined in Europe for data privacy

European regulators slapped TikTok with a $368 million fine on Friday for failing to protect children’s privacy, the first time that the popular short video-sharing app has been punished for breaching Europe’s strict data privacy rules.

Ireland’s Data Protection Commission, the lead privacy regulator for Big Tech companies whose European headquarters are largely in Dublin, said it was fining TikTok 345 million euros and reprimanding the platform for the violations dating to the second half of 2020.

The investigation found that the sign-up process for teen users resulted in settings that made their accounts public by default, allowing anyone to view and comment on their videos. Those default settings also posed a risk to children under 13 who gained access to the platform even though they’re not allowed.

Also, a “family pairing” feature designed for parents to manage settings wasn’t strict enough, allowing adults to turn on direct messaging for users aged 16 and 17 without their consent. And it nudged teen users into more “privacy intrusive” options when signing up and posting videos, the watchdog said.

TikTok said in a statement that it disagrees with the decision, “particularly the level of the fine imposed.”

The company pointed out that the regulator’s criticisms focused on features and settings dating back three years. TikTok said it had made changes well before the investigation began in September 2021, including making all accounts for teens under 16 private by default and disabling direct messaging for 13- to 15-year-olds.

“Most of the decision’s criticisms are no longer relevant as a result of measures we introduced at the start of 2021 — several months before the investigation began,” TikTok’s head of privacy for Europe, Elaine Fox, wrote in a blog post.

The Irish regulator has been criticized for not moving fast enough in its investigations into Big Tech companies since EU privacy laws took effect in 2018. For TikTok, German and Italian regulators disagreed with parts of a draft decision issued a year ago, delaying it further.

Advertisement. Scroll to continue reading.

To avoid new bottlenecks, the Brussels headquarters of the 27-nation bloc has been given the job of enforcing new regulations to foster digital competition and clean up social media content — rules aimed at maintaining its position as a global leader in tech regulation.

In response to initial German objections, Europe’s top panel of data regulators said TikTok nudged teen users with pop-up notices that failed to lay out their choices in a neutral and objective way.

“Social media companies have a responsibility to avoid presenting choices to users, especially children, in an unfair manner — particularly if that presentation can nudge people into making decisions that violate their privacy interests,” said Anu Talus, chair of the European Data Protection Board.

The Irish watchdog, meanwhile, also had examined TikTok’s measures to verify whether users are at least 13 but found they didn’t break any rules.

The regulator is still carrying out a second investigation into whether TikTok complied with the EU’s General Data Protection Regulation when it transferred users’ personal information to China, where its owner, ByteDance, is based.

TikTok has faced accusations it poses a security risk over fears that users’ sensitive information could end up in China. It has embarked on a project to localize European user data to address those concerns: opening a data center in Dublin this month, which will be the first of three on the continent.

Data privacy regulators in Britain, which left the EU in January 2020, fined TikTok 12.7 million pounds ($15.7 million) in April for misusing children’s data and violating other protections for young users’ personal information.

Instagram, WhatsApp and their owner Meta are among other tech giants that have been hit with big fines by the Irish regulator over the past year.

Related: TikTok fined €750,000 for Violating Children’s Privacy

Related: Executive Fired From TikTok’s Chinese Owner Says Beijing Had Access to App Data in Termination Suit

Related: TikTok’s Trials and Tribulations Continue With UK Data Protection Fine

Related Content

Privacy & Compliance

The House passed legislation that would ban TikTok if its China-based owner ByteDance doesn’t sell its stakes in the popular social media platform within...


Dutch regulators impose a 10 million euro ($10.8 million) fine on ride-hailing app Uber for lack of transparency in treating the personal data of...

Privacy & Compliance

France's data protection agency fines Amazon's French warehouses unit 32 million euros ($34.9 million) for "excessively intrusive" employee surveillance system.


France's data protection watchdog fines Yahoo 10 million euros for not respecting users' refusals of internet-tracking "cookies"

Data Breaches

A medical company has been fined $450,000 by the New York AG over a data breach that may have involved exploitation of a SonicWall...


European privacy officials have widened a ban on Meta’s “behavioral advertising” practices to most of Europe.

Cloud Security

Amazon is rolling out an independent cloud for Europe as it looks to address strict regulations that companies and those in the public sector...

Data Breaches

UK’s financial watchdog FCA imposes a £11 million (approximately $13.5 million) fine to Equifax over the 2017 data breach.

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version