Ireland's Data Protection Commission fined TikTok €345 million on September 15, 2023, for breaches of the General Data Protection Regulation in its processing of children's personal data, per the commission's published decision. The inquiry examined TikTok's settings for users under 18 between July 31 and December 31, 2020, and found public-by-default posting and a family-pairing feature that lacked adequate safeguards. The fine matters for platform design, not just finance: the order requires settings changes, which reaches product behavior in a way penalties alone do not.
Media News Watch covers the governance of information systems; this report states the decision and its documented context, per the named sources, and makes no legal judgment of its own.
What did the decision actually find?
The commission, acting as TikTok's lead GDPR supervisory authority in the European Union, examined eight data-processing issues across the settings review period, per its September 2023 statement. Two findings carried the enforcement: accounts of users aged 13 to 17 were set to public by default, and the family-pairing feature allowed an adult to pair with a child account without verification of that adult's identity. The commission also criticized transparency practices around child data.
TikTok's response, per the company's September 15, 2023 statement, was that it disagreed with aspects of the decision, noted that the findings predated changes it had already made — including private-by-default accounts for younger teens — and confirmed it had implemented the corrective measures. The company did not appeal at the time of the statement, per reporting by Reuters the same week.
Why does a design remedy matter more than the sum?
Because the order, unlike a pure penalty, specifies product defaults. The decision required TikTok to change settings for minor accounts and tighten the pairing feature, per the commission's statement — obligations that operate on every new account opened in the jurisdictions concerned. The €345 million figure, large as it is, was the third major GDPR fine of 2023 against a platform owned by a Chinese parent company, and the second-largest the Irish commission had issued to that point, after Meta's €1.2 billion data-transfer decision of May 2023.
The detail other coverage skipped: the inquiry was conducted under the GDPR's one-stop-shop mechanism, in which the lead authority drafts a decision that other EU regulators may object to before it becomes final. In this case the European Data Protection Board was consulted and the decision issued as the commission's own order, per the commission's procedural notes — a reminder that the EU's platform enforcement runs through a committee structure, not a single regulator, and the documented wrangling inside it is part of how the outcome is shaped.
For more context, read Reality TV better be ready for Debbie Wingham.
For more context, read sustainable.
For more context, read The Most Expensive reality show bids farewell to Marbella.
