TikTok's $400M COPPA bill: audit your own age gate
DOJ settled with TikTok for $400M over children's privacy. If your store, quiz, or loyalty signup collects data from kids, COPPA is your problem too.
TikTok agreed to pay $400 million to settle the Justice Department's children's privacy case. That is a number only a platform pays. The rule behind it is not — COPPA applies to any operator that collects personal information from children under 13, which quietly includes a lot of small e-commerce stores, quizzes, and loyalty signups.
What actually happened
The Justice Department announced the settlement on August 21 with TikTok, ByteDance, and affiliated entities, resolving litigation over the Children's Online Privacy Protection Act. The payment splits: $300 million now, and $100 million on entry of an order vacating the earlier consent decree against TikTok's predecessor, Musical.ly. DOJ calls it one of the largest COPPA recoveries ever obtained.
The government sued in 2024. Per TechCrunch, the complaint alleged TikTok let millions of under-13 users on the platform and collected their personal information without the required parental consent, and failed to identify and remove those accounts — after Musical.ly had already settled COPPA claims for $5.7 million in 2019. The agreement requires stronger age controls, additional safeguards for children, and expanded parental oversight. TikTok admits no wrongdoing.
Read the arc, not the headline: $5.7 million the first time, $400 million the second. Enforcement prices repeat findings differently.
Why COPPA compliance matters for your business
"We don't target kids" is not the standard. COPPA turns on collecting personal information from children under 13 when you have actual knowledge of it, or when your service is directed to children. A toy store, a youth sports team store, a kids' apparel brand, a summer camp registration form — those are child-directed in practice even if nobody planned it that way.
Personal information is broader than a name and an email. Persistent identifiers count. That means the tracking pixel on your quiz page, the session cookie behind your wishlist, the device ID your analytics SDK collects. Most small stores have never audited which third-party scripts fire before a consent step, and that is where the exposure sits.
Your age gate is either a control or decoration. A birthday dropdown that lets someone re-submit after a rejection is not a control. If a date fails the gate, the session should end without writing anything, not bounce back to a form that remembers the last answer.
Do the boring audit. List every form that captures data. List every third-party script and when it loads. Note where a minor could plausibly be the person typing. Fix the defaults so nothing is collected before consent. That is a one-week job for a small store, and it is much cheaper than the alternative.
Key takeaways
- DOJ settled with TikTok and ByteDance for $400M on August 21 — $300M now, $100M on vacating the Musical.ly decree
- Allegations: under-13 users on the platform and personal data collected without required parental consent
- Musical.ly settled COPPA claims for $5.7M in 2019; the repeat case cost roughly 70x that
- COPPA covers persistent identifiers — pixels, cookies, device IDs — not just names and emails
- Child-directed is about who actually uses your site, not who your marketing targets
- Audit every form and third-party script, and make sure nothing fires before consent
Most compliance problems in small e-commerce are default settings nobody chose. We audit what your storefront actually collects — forms, pixels, SDKs, and the order they load in — then rebuild the consent path so the defaults are the safe ones. Ask us to look at your data collection, or see how we build commerce systems.
Sources: U.S. Department of Justice, TechCrunch, CNN Business.
- #coppa
- #privacy
- #compliance
- #ecommerce
- #data-collection
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Walmart adds Tap to Pay: your checkout follows the wallet
Walmart and Sam's Club start accepting Apple Pay and Google Pay on Aug 24 after a decade of refusing. What contactless payments mean for your checkout stack.
Read itApple Music adds 'Made With AI' labels: your feed declares it
Apple Music will show visible Made With AI labels later this year, sourced from tags suppliers put in the feed. Why self-declared provenance is spreading to catalogs.
Read it