Irish Regulator Fines TikTok 345 Million Euros
Time 2 Minute Read

On September 15, 2023, the Irish Data Protection Commission (the “DPC”) announced a fine of 345 million Euros against TikTok Technology Limited (“TikTok”) for non-compliance with GDPR rules regarding the processing of personal data of child users. This decision by the DPC reflects the binding decision of the European Data Protection Board (the “EDPB”) pursuant to Article 65 of the GDPR.

The DPC’s investigation focused on how TikTok processed the data of children between July 31, 2020 and December 31, 2020. In its decision, the DPC considered that TikTok:

  • infringed the principles of data minimization (Article 5(1)(c)) and data protection by design and by default (Article 25), and its obligations as a data controller (Article 24), by making child accounts public by default and not adequately considering the privacy risks that this posed for children;
  • infringed the principles of security and integrity (Article 5(1)(c)) and data protection by design and by default (Article 25), by setting up its “family pairing” option in a manner that allowed non-child users, who could not be verified as being the parent or guardian, to implement less privacy protective settings in the child user’s account;
  • failed to provide adequate information to child users, infringing the rules on transparency and provision of information in Articles 12 and 13 of the GDPR; and
  • used dark patterns to nudge child users into selecting more privacy-intrusive settings, infringing the principle of fairness (Article 5(1)(a)). It is important to note that this finding follows an objection raised by the Berlin DPA and upheld by the EDPB, and was not included in the DPC’s original findings.

In addition to the fine, the DPC also issued a reprimand and an order for TikTok to bring its processing into compliance within three months of the date on which it was notified of the decision.

Read the DPC’s decision and the EDPB’s Article 65 binding decision.  

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 6 Minute Read

On February 9, 2026, trade association NetChoice filed a lawsuit challenging South Carolina’s newly passed Age-Appropriate Code Design (“SC AACD”) on First and Fourteenth Amendment grounds. The SC AACD was signed into law on February 5, 2026, making South Carolina the fifth U.S. state to enact such a law, following California, Maryland, Nebraska and Vermont.

Time 2 Minute Read

Congress has extended the Cybersecurity Information Sharing Act of 2015 through September 30, 2026 as part of the Consolidated Appropriations Act, a government funding package enacted in early February 2026.

Time 4 Minute Read

On January 27, 2026, the Centre for Information Policy Leadership hosted a fireside chat with California Privacy Protection Agency General Counsel Phil Laird in honor of Data Privacy Day.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page