On August 21, 2026, the Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated entities — including the newly constituted TikTok USDS Joint Venture LLC — resolving the government’s litigation under the Children’s Online Privacy Protection Act. The Department called it one of the largest recoveries ever obtained in a COPPA case, and on the public record it is.

The headline number is not the interesting part. The payment structure is.

$300 million is payable immediately. The remaining $100 million is payable only upon entry of an order vacating a prior consent decree — the 2019 stipulated order entered against TikTok’s predecessor, Musical.ly, Inc., in the U.S. District Court for the Central District of California (No. 2:19-cv-1439). On the same day the settlement was announced, the government filed a consent motion asking Judge Otis D. Wright II to vacate that decree, with a hearing set for September 21, 2026.

Read that again in compliance terms. A company agreed to pay one hundred million dollars — a quarter of the total — not for a release of liability or a covenant not to sue, but simply to stop being subject to a children’s privacy consent order. There is no clearer market valuation of what living under a COPPA decree costs.

And there is no clearer illustration of the point every compliance function should take from this case: the 2019 decree was in force throughout the conduct alleged in the 2024 complaint. The order did not prevent the violations.

What the Government Alleged

The underlying suit was filed on August 2, 2024 by the Justice Department on referral from the Federal Trade Commission, in the Central District of California (No. 2:24-cv-06535), against TikTok Inc., ByteDance Ltd., and affiliated entities. It pleaded violations of COPPA, 15 U.S.C. §§ 6501–6506, and the COPPA Rule at 16 CFR Part 312, and described three distinct failure modes.

The age gate was defeatable. TikTok has operated a neutral age screen since March 2019. The complaint alleged that a user entering a disqualifying birthdate could simply restart account creation with a different one, and that third-party login pathways bypassed the screen entirely. An age gate that can be re-rolled is not an age gate; it is a formality that produces a defensible log entry.

“Kids Mode” itself was the problem. TikTok’s under-13 experience — a restricted, walled-garden version of the app — was the government’s strongest theory, and the part every product organization should study. The complaint alleged that TikTok collected personal information from Kids Mode accounts, including persistent identifiers, without verifiable parental consent, and shared information associated with those accounts with third parties including Facebook and AppsFlyer for marketing purposes.

Parental deletion requests went unhonored. The complaint alleged that parents faced a convoluted multi-step process, and that of roughly 1,700 deletion requests submitted between March 2019 and December 2020, approximately 500 — about 30 percent — corresponded to accounts still active as of November 1, 2021. It further alleged retention of application activity logs for as long as 18 months after deletion, and described fewer than two dozen full-time human moderators reviewing flagged accounts at roughly five to seven seconds each.

The complaint sought civil penalties of up to $51,744 per violation, per day, running from January 10, 2024, plus permanent injunctive relief.

TikTok’s position throughout was that the allegations “relate to past events and practices that are factually inaccurate or have been addressed.” The settlement contains no admission of wrongdoing.

The Kids Mode Trap: Building a Child Experience Creates Actual Knowledge

COPPA’s coverage trigger is the most misunderstood element of the statute, and Kids Mode is the textbook illustration of how a well-intentioned product decision moves an operator across the line.

The COPPA Rule applies to an operator of a service directed to children, and to an operator of a general-audience service that has actual knowledge it is collecting personal information from a child under 13. For a mixed-audience service, actual knowledge is the operative standard — and operators generally like it that way, because it is a high bar and constructive knowledge is not imputed in the abstract.

Building a dedicated child-directed mode collapses that distinction. The moment a service routes a self-identified under-13 user into a purpose-built experience, every data flow inside that experience is, by the operator’s own architecture, a flow of children’s personal information. There is no knowledge question left to litigate — the operator has stipulated to it in code.

This is the structural trap. The child-safe experience is built to reduce risk, and it does — behavioral, content, reputational. But it simultaneously converts the operator’s COPPA posture from conditional to absolute for that population, and every requirement of Part 312 attaches with full force inside the walled garden:

  • § 312.4 — direct notice to parents and an online notice describing what is collected, how it is used, and disclosure practices.
  • § 312.5verifiable parental consent obtained before any collection, use, or disclosure, using a method reasonably calculated to ensure the person giving consent is the parent.
  • § 312.6 — the parent’s right, on request, to review the personal information collected from the child, to refuse further collection or use, and to direct deletion.
  • § 312.8 — reasonable procedures to protect the confidentiality, security, and integrity of children’s personal information.
  • § 312.10 — retention only for as long as reasonably necessary to fulfil the purpose for which it was collected, and then deletion. Indefinite retention is prohibited.

Persistent identifiers deserve their own line. A persistent identifier is personal information under the Rule, and the narrow exception permitting its collection is limited to support for the internal operations of the service. Sharing identifiers from child accounts with advertising and attribution partners is precisely what that exception does not reach — which is why the Facebook and AppsFlyer allegations matter more than their technical banality suggests.

If your product has a kids mode, an under-13 experience, a school edition, or a family tier, you have already made the actual-knowledge decision. The only question left is whether your controls match.

The FTC announced the Musical.ly settlement on February 27, 2019 — then a record $5.7 million civil penalty, the largest the Commission had obtained in a children’s privacy case. The stipulated order entered in the Central District of California carried the standard architecture of federal privacy consent relief:

  • A permanent injunction against violating the COPPA Rule.
  • Deletion of personal information previously collected from children, and removal of videos made by under-13 users.
  • Ten years of sworn compliance reporting to the government.
  • Long-term recordkeeping obligations covering the documents needed to demonstrate compliance.
  • Compliance-monitoring provisions, including the government’s right to interview employees and affiliated persons who consent.
  • Third-party review of privacy training, with written verification.

Twenty-year terms with biennial independent assessments are the more common shape of modern FTC privacy orders; the Musical.ly decree was shorter but not lighter in kind. The burden is worth itemizing honestly, because most organizations under-price it:

Officer certifications. Someone signs, under penalty of perjury, that the company is complying — which converts every unresolved control gap into personal exposure for a named executive.

Reporting cadence and recordkeeping. Sworn reports on a fixed schedule mean the evidence must exist continuously rather than be assembled retroactively — a permanent operational cost, not a project. Order-mandated retention of complaints, consent records, training materials, and personnel files also sits in tension with the data minimization the same order demands elsewhere.

Assessment overhead. Independent third-party assessment cycles consume engineering and legal time on a rolling basis, and the findings become discoverable artifacts.

Contempt exposure. This is the real cost. Under a decree, a violation is not merely a new statutory violation to be proven from scratch — it is potential contempt of court, with a faster path to relief and a hostile procedural posture. The government’s vacatur motion says so explicitly: what survives vacatur is COPPA, the COPPA Rule, and the FTC Act, meaning future violations become new enforcement actions rather than contempt proceedings.

Strategic constraint. A live decree complicates acquisitions, restructurings, and joint ventures. Successors inherit it; counterparties diligence it.

At TikTok’s scale, $100 million to be released is not obviously irrational. It is a discounted cash-flow calculation on a decade of supervision, contempt risk, and transactional friction.

The Uncomfortable Part: The Decree Did Not Work

Here is the fact no press release foregrounds. The 2019 order was in effect throughout the conduct period alleged in the 2024 complaint. A permanent injunction against COPPA Rule violations, ten years of sworn compliance reporting, deletion obligations, and government monitoring rights were all live — and the government still alleged that under-13 accounts were created at scale, that Kids Mode data flowed to marketing partners, and that roughly thirty percent of a sample of parental deletion requests went unfulfilled.

The compliance conclusion generalizes far beyond TikTok. A consent decree is a floor, not a control. It specifies outcomes and reporting. It does not build the deletion pipeline, staff the moderation queue, enforce the retention schedule in the data warehouse, or stop an SDK from firing on a child account. A decree assumes a compliance operation exists that can deliver those things; where that operation is thin, the decree simply documents the gap in sworn filings.

The alleged failure here was not legal-interpretive. Nobody needed a memo to know that § 312.6 requires honoring a parent’s deletion request. The failure was operational: a deletion request arriving at a support queue with no owning system, no service-level target, no completion evidence, and no reconciliation against the account store. That is a workflow problem wearing a regulatory costume.

The government’s vacatur motion rests on changed circumstances — new ownership following the January 2026 formation of the U.S. joint venture, new management, new compliance operations, new privacy practices — invoking SEC v. Randolph, the institutional-reform vacatur factors, and Rule 60(b)(6). Note the logic: the argument for releasing the decree is that the compliance operation has changed. Even the government’s own theory concedes that the operation, not the order, does the work.

Penalty Math: Why COPPA Exposure Is Effectively Unbounded

COPPA violations are enforced as violations of a rule respecting unfair or deceptive acts or practices, carrying civil penalties under 15 U.S.C. § 45(m)(1)(A), adjusted annually for inflation. The current maximum is $53,088 per violation, effective January 17, 2025. Following OMB guidance issued April 17, 2026 cancelling the 2026 inflation adjustment, that figure remains the operative maximum in 2026. The 2024 TikTok complaint pleaded the then-current $51,744 figure, per violation, per day.

Now do the arithmetic that makes COPPA different from almost every other U.S. privacy regime. The unit of violation is not the incident; it is, in the government’s framing, per child, per day. A platform with one million affected under-13 accounts over a single year is theoretically exposed to a number with thirteen digits in it. No court will impose it and no company could pay it — which is exactly the point. The theoretical maximum is not a prediction; it is leverage, and it is why COPPA cases settle at nine figures when the affected population is large.

The practical implication: your COPPA risk is not proportional to the sensitivity of the data you hold. It is proportional to the number of child users multiplied by the number of days the defect persisted. Time-to-detection is therefore a first-order financial control, not a security metric. A misconfigured SDK firing on child accounts for eighteen months is a categorically different liability than the same SDK caught in eighteen days.

The Amended COPPA Rule: The Bar Moved in April 2026

The Rule the government would apply today is stricter than the one TikTok was charged under. The FTC finalized amendments in January 2025, published them in the Federal Register on April 22, 2025, effective June 23, 2025, with full compliance required by April 22, 2026. That deadline has passed; we covered the run-up in our analysis of the April 22 COPPA compliance deadline. The changes map directly onto the failure modes alleged in this case:

Separate verifiable parental consent for third-party disclosure. Consent to disclose children’s personal information to third parties must now be obtained separately from consent to collect it, unless the disclosure is integral to the service. Had this been in force, the alleged sharing of Kids Mode identifiers with marketing partners would have required its own distinct consent — the exact control gap the complaint describes.

A written data retention policy, published. Operators must maintain and publish a written retention policy for children’s personal information, specifying purposes, retention periods, and deletion practices. Retention “for as long as reasonably necessary” is now a documented, auditable commitment rather than a posture assembled after the fact — and it speaks directly to the alleged 18-month post-deletion log retention.

Expanded personal information. The definition now expressly includes biometric identifiers usable for automated or semi-automated recognition — fingerprints, retina and iris patterns, genetic data, voiceprints, gait patterns, facial templates and faceprints — along with government-issued identifiers. Any voice feature, avatar generator, or face-based effect in a child-accessible product inherited new obligations here.

A written children’s information security programme. A documented security program is now required, with designated responsible personnel, risk assessments, safeguards proportionate to sensitivity, and written assurances from third parties receiving children’s data.

If you have a kids mode and you have not re-papered consent flows, published a retention policy, and inventoried biometric-adjacent data collection against the amended definition, you are out of compliance today, not prospectively.

The State Layer: A Federal Settlement Resolves Federal Claims Only

A $400 million federal settlement does nothing about state exposure, and the state layer is now the faster-moving one. State age-appropriate design codes impose obligations COPPA does not: default-high privacy settings, impact assessments for features likely to be accessed by minors, restrictions on profiling and dark patterns, and — critically — coverage of minors under 18 rather than COPPA’s under-13 population. We walked the full map in Beyond COPPA: the legal maze of U.S. children’s data privacy.

The most consequential recent development is the New Jersey Kids Code Act, signed by Governor Sherrill on August 11, 2026 as part of a broader children’s online safety package. Effective September 1, 2027, it imposes privacy-by-default and safety-by-design obligations on services reasonably likely to be accessed by minors, restricts advertising to minors and the collection of their personal data, and requires default settings at the highest level of privacy and safety.

The provision that changes the risk calculus is the private right of action with $5,000 in statutory damages per violation, alongside Attorney General enforcement. Statutory damages plus a private right of action is the combination that converts a design-code obligation into class action exposure — and unlike a COPPA civil penalty, it is not subject to prosecutorial discretion or a government’s willingness to trade relief for a payment. State attorneys general have been equally active on the litigation track; the $375 million New Mexico child safety verdict against Meta demonstrated what a single state can do without any federal involvement at all.

None of this touches the international layer, where TikTok already faces separate children’s data findings — see our coverage of the €530 million Irish DPC fine and appeal.

The Audit: Where Actual Knowledge Attaches in Your Product

This is not a TikTok story. Any service with a child-directed mode, an age gate, or a mixed audience carries the identical structural exposure. Run the assessment in this order.

1. Map where actual knowledge attaches. Enumerate every point at which your systems learn or infer that a user is under 13: the age screen, a school roster integration, a parent-linked account, a parent’s support ticket, a trust-and-safety flag, an ad platform’s age signal, an app store age declaration. Each is a knowledge event. Document what the system does with each, and how fast.

2. Trace the deletion request end-to-end. Pick a real parental deletion request and follow it. Who receives it? What system of record opens? What is the service-level target? Which downstream stores are purged — primary database, analytics warehouse, event logs, backups, ML training corpora, third-party processors? Who verifies completion, and what artifact proves it? If you cannot produce a completion record for a request from six months ago, you have the defect the government alleged here.

3. Publish and enforce the retention schedule. The harder half of the amended Rule’s written-policy requirement is enforcement: an automated deletion job with monitoring and alerting, not a documented intention. Verify that logs, telemetry, and derived datasets are inside the schedule — the alleged 18-month post-deletion activity logs were exactly this class of overlooked data.

4. Inventory every SDK and tag firing in the child experience. Analytics, attribution, crash reporting, advertising, A/B testing. For each, determine whether it transmits a persistent identifier and whether its purpose fits within support for internal operations. This is a code-level question with a fifty-thousand-dollar-per-child-per-day answer.

5. Re-paper consent for third-party disclosure. Confirm your consent record captures which consent was given, by whom, when, by what verification method, and for what disclosure.

6. Test the age gate against a determined child. Re-roll the birthdate. Try third-party login. Delete and reinstall. If a nine-year-old can defeat the gate in under a minute, one will — and your logs will say a fifteen-year-old signed up.

7. Evidence it. Every item above must produce a dated artifact. In an enforcement posture, an undocumented control does not exist.

Conclusion

The $100 million contingency is the durable lesson of this case, and it cuts both ways.

It establishes, publicly and in dollars, that a children’s privacy consent decree is expensive to carry — expensive enough that a large platform will pay a nine-figure premium to be released from one. Every board that has treated consent-order risk as a reputational abstraction now has a number to anchor on.

But it also establishes the opposite, more important point. The 2019 decree existed. It carried a permanent injunction, sworn reporting, deletion obligations, and monitoring rights — and the government’s 2024 complaint alleges that children created accounts anyway, that their identifiers went to marketing partners anyway, and that their parents’ deletion requests went unfulfilled anyway. The order was not the control. It never is.

Organizations resolving to avoid consent decrees have taken the wrong lesson, because avoiding a decree is not something you can do directly. What you can do is build the thing a decree assumes you already have: a named owner for children’s data, a deletion pipeline that closes tickets with evidence, a retention schedule that executes itself, and an SDK inventory someone actually reads. Do that, and the decree question never arises.

Sources: DOJ — Justice Department Secures $400M Settlement with TikTok and ByteDance, DOJ — Justice Department Sues TikTok and Parent Company ByteDance (August 2, 2024), PPC Land — TikTok pays $400 million as DOJ moves to vacate its 2019 COPPA decree, The Hacker News — TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit, FTC — Video Social Networking App Musical.ly Agrees to Settle FTC Allegations That it Violated Children’s Privacy Law, Federal Register — Children’s Online Privacy Protection Rule (April 22, 2025), FTC — Inflation-Adjusted Civil Penalty Amounts, Hunton — New Jersey Enacts the Kids Code Act

This article is provided for informational purposes only and does not constitute legal advice.