TikTok: €345M European Union (Ireland) privacy settlement

The Irish DPC fined TikTok €345 million for child-account default settings that allowed under-13 content to be public, weak parental verification, and dark-pattern flows that nudged minors toward more permissive privacy choices.

  • GDPR
  • European Union (Ireland)
  • Last updated

Enforcement snapshot

Amount
€345M
Regulator
Irish Data Protection Commission
Sector
Short-form video
Published
September 2023

Technical failure modes

What failed

01. Public-by-default child accounts

Accounts for users under 16 defaulted to public visibility, exposing minors' content beyond their personal network.

02. Weak age verification

Age-gating relied on self-declaration without supplemental signals, allowing under-13 users onto the platform.

03. Dark-pattern privacy flows

UI nudged users — including minors — toward more permissive privacy and content settings during onboarding.

04. No DPIA-grade analysis

The risk assessment for child-facing features did not match what the Article 35 DPIA process expects.

Next step

Do not wait for a demand letter to find the gap

The TikTok decision is the children's privacy case for the AI era. Defaults must protect minors. Age verification has to actually work. Privacy UX cannot nudge children toward exposure. The decision lines up directly with COPPA-style rulemaking in the US and parallel work under the UK Age-Appropriate Design Code.

Get Started Free

Get started in less than 5 min