TikTok has been fined £12.7 million (about $15.7 million) for breaching UK data protection law, including rules aimed at protecting children.
The Information Commissioner’s Office (ICO), a privacy watchdog, today announced that video-sharing sites have not taken adequate steps to review users using their platforms, and have “not taken sufficient steps to prevent minor children from using their services.” We have not taken sufficient steps to remove it.” .
According to the ICO, TikTok had an estimated 1.4 million underage UK users in the two years from May 2018 to July 2020. This is the focus of our research and violates our terms of service that the user must be 13 years of age or older.
The UK data protection regime limits the age at which children can consent to their data being processed to 13 years of age. This meant that TikTok had to obtain parental consent to lawfully process the data of these minors (which the company did not do).
“We have fined TikTok for providing services to UK children under the age of 13 and processing personal data without the consent or permission of their parents or caregivers. We expect to continue our efforts to conduct appropriate checks to remove it from the ICO,” said an ICO spokesperson.
Additionally, the ICO found that TikTok violated the transparency and fairness requirements of the UK’s General Data Protection Regulation (GDPR). This is due to our failure to provide users with relevant and understandable information regarding the collection, use and sharing of data.
“Without that information, users of the platform, especially children, would not have been able to make informed choices about whether and how to engage with it,” ICO said. pointed out in a press release announcing penalties for misusing children’s data.
In a statement, UK Information Commissioner John Edwards added:
Laws are in place to make sure children are as safe in the digital world as they are in the physical world. TikTok did not comply with these laws.
As a result, an estimated 1 million people under the age of 13 were improperly granted access to the platform, and TikTok collected and used their personal data. This means that your data is used for user tracking and profiling, and your next scroll may deliver harmful and inappropriate content.
TikTok should have known better. TikTok should have done better. His £12.7m fine for us reflects the severe consequences of their failure. They did not check who was using the platform or take sufficient steps to remove any underage children who were using the platform.
TikTok has been contacted for comment regarding the implementation of the ICO. The company said it is considering a decision to consider next steps.
In a statement, a TikTok spokesperson said:
TikTok is a platform for users over the age of 13. We have invested heavily in keeping less than 13 seconds off our platform and have a strong safety team of 40,000 working around the clock to keep our community’s platform safe. While we do not agree with the ICO’s decisions related to May 2018 to July 2020, we are pleased that the fines announced today have been reduced to less than half of what was proposed last year. We will continue to consider the decision and consider next steps.
TikTok claims it has taken a number of steps to address issues that resulted in fines today. (i.e., if you are underage, you can lie to avoid action).
However, this is complemented by hardening our systems and training our safety management team to look for signs that a child under the age of 13 may be using an account, and accounts may be flagged for review. It also responds promptly to requests from parents to delete minors’ accounts and uses other information provided by users, such as keywords and in-app reports. to reveal potential minor accounts.
TikTok also hints at improved transparency and accountability in this area — saying it regularly reports on the number of underage users removed from the platform (2022 In the last three months of the year, the figure said more than 17 million suspected minor accounts had been deleted); however, we do not report this data by country); Offers Family Pairing so the can monitor your child’s usage.
Social media platforms face double-digit penalties despite being found to have violated the UK’s GDPR for two years on the grounds of legality, transparency and fairness. , which is well below the maximum of 4% of the global annual total. sales) — so the settlement looks pretty generous for his TikTok.
It’s also worth noting that this figure is less than half the amount originally proposed by the ICO in September. The regulator released its preliminary findings in September and said it could impose fines of up to £27m ($29m) for a string of alleged breaches at the time. .
The reason for the significant reduction in the amount of the fine is that the regulator has decided not to seek an interim investigation into the illegal use of special categories of data in accordance with allegations made by TikTok.
Under the GDPR, special categories of data are those that are particularly sensitive, such as sexual orientation, religious beliefs, political affiliation, racial or ethnic origin, health data, and biometric data used for identification. It refers to the information of the high class of . personal data; where consent is the basis upon which to rely, there is a higher standard of explicit consent.
This means that last year the ICO suspected TikTok was processing this kind of information without a lawful basis. However, the company was able to persuade them to drop their concerns.
It is not clear exactly why the ICO removed the special category data rows in the survey. However, in response to a question from TechCrunch, a spokesperson for the regulator suggested a lack of resources was to blame, stating:
In light of TikTok’s allegations, we have decided not to pursue an interim ruling regarding unlawful use of special categories of data. This does not mean that the use of special category data by social media companies is not important for ICOs. But we need to think strategically about our resources, and in this case the Commissioner has exercised its discretion not to pursue interim accreditations related to the unlawful use of special categories of data. The possibility was not included in the final fine set at £12.7m. This was the main reason the interim fine was reduced to his £12.7m. The amount of this fine is set in accordance with our Regulatory Actions Policy.
The ICO has a history of inaction against systematic abuse by the behavioral advertising industry — and failure to clean up the ad tech industry of tracking and targeting has resulted in data-dependent tracking, profiling, and “free” services. Ad micro-targeting to monetize.
Children’s data protection is definitely an area of focus for UK watchdogs. In recent years, under pressure from campaign groups and UK MPs, we have set an age-appropriate design code in relation to GDPR compliance (thus risking fines for those who ignore recommended standards). Active enforcement of the Children’s Privacy and Safety Code began in September 2021. It’s safe to say that the tsunami of enforcement hasn’t happened yet, but the ICO is doing a lot of research.
As the UK is no longer a member of the European Union, ICO enforcement of the GDPR will only take place in the UK. It’s worth noting that the TikTok business remains under investigation in the EU over how it handles children’s data.
Ireland’s Data Protection Commission (DPC) launched an investigation into TikTok’s handling of children’s data in September 2021. An EU-wide investigation is ongoing and the European Data Protection Board is his DPA on Ireland’s draft decision, so the process could take several more months to come into effect. Also ongoing in the EU: an investigation by his DPC into TikTok’s data transfers to China, as the GDPR also governs data exports (of course, this is a very hot topic that TikTok is concerned about these days).
One point of comparison: Last year, rival social network Instagram was fined €405 million for misusing children’s data under the EU’s GDPR. In that case, however, the penalty reflects cross-border data processing activity across the 27-member-state block, whereas his TikTok enforcement by the ICO is on behalf of UK users only. There are some differences in the magnitude of the penalties imposed.