EnforcementFriday 13 September 2024via Data Protection Report

Ireland's Coimisiún na Meán fines TikTok €345 million for child data protection failures

Guardii Analysis

Ireland's Data Protection Commission has fined TikTok €345 million for violations of the EU General Data Protection Regulation related to the protection of children's data, finding that the platform failed to implement appropriate default privacy settings for child users and did not adequately restrict the processing of children's personal data between 2020 and 2022. The DPC investigation, conducted under the GDPR's one-stop-shop mechanism, concluded that TikTok's public-by-default account settings for users aged 13-17 and its failure to provide transparent, child-appropriate information about data processing exposed minors to undue privacy and safety risks, and the regulator has ordered the company to bring its processing into compliance within a specified timeframe.

Data-protection enforcement establishes that platforms must design for child safety by default, but compliance with privacy settings does not itself prevent a child from being targeted by a predator within the channels the platform permits. Real-time conversational detection addresses the residual risk: Guardii's grooming and sextortion modules, deployed across TikTok-adjacent platforms including Instagram, Snapchat, Discord and Roblox, analyse direct messages to identify sustained targeting, coercive escalation and age-inappropriate contact as they occur, flagging hostile patterns before a child is manipulated into sharing material or meeting an offender offline. The platform, backed by Startmate and operating as a Meta Business Partner, surfaces a child at risk to a parent or safeguarding professional without creating a surveillance feed of message content, offering a proportionate technical layer that complements regulatory mandates for privacy-by-design with active harm detection at the point of contact.

Related Articles