Refacto

Podcast episode

MadTech Daily: New Support for ASA Awareness Campaign; TikTok Settles Children’s Privacy Case for USD$400m

children-privacy privacy regulatory-enforcement

TikTok is paying $400 million to settle US government claims it collected data from children under 13 without parental consent, and breached a 2019 FTC settlement in the process. The UK's Advertising Standards Authority is running an awareness campaign with donated media from Netflix and Waitrose. TapTap Digital and Skyrise announced a European cookieless-targeting partnership. The TikTok item is the only one that matters.

Host Dot covers the settlement briskly, but the piece that operators should sit up for is the repeat-offender structure. TikTok already had a consent order on file from 2019 and got caught again anyway. The regulator proved a second violation, which is more legal work than a simple fine. That's intent signaling. The TapTap cookieless pitch is a vendor talking its own book with no independent methodology attached. Discount it accordingly.

The practical move is narrow but urgent: audit any audience segment that could sweep in under-13 users, and check whether your company inherited any FTC consent obligations through an acquisition. "We didn't know they were kids" is no longer a workable defense for a company that's already been warned.

Analysis

Showing the shorter version.

TikTok agreed to pay $400 million to settle US government claims it collected data from children under 13 without parental consent. Verify that figure against the actual DOJ or FTC filing before you build a compliance memo on it, but the direction is unambiguous.

The number is not the main event. The structure is. This was not a first-strike fine. TikTok had already signed a 2019 FTC settlement, and the government proved it violated that order too. Proving a second violation is extra work regulators only bother with when they intend to enforce consent decrees as a category going forward. That reframes every privacy settlement your company, or a company you acquired, signed in the last decade. Those signatures are live obligations with nine-figure teeth now.

What breaks for operators

If you run a DSP, SSP, data business, or publisher with any audience segment that could sweep in under-13 users, the repeat-offender framing matters directly. "We didn't know they were kids" stopped being a defense the moment TikTok got caught after already being warned. The first thing to audit: any segment built on inferred demographics near the teen boundary. The second thing to expect, roughly ninety days out: your data partners start asking for age-gating attestations you don't currently produce.

The exposure scales with your visibility and your paper trail. TikTok got hit because it's TikTok and because there was a signed order to breach. If your company is carrying an inherited consent obligation from an acquisition, that's the specific risk to surface now, not abstract COPPA exposure.

The other two items from this episode, a UK Advertising Standards Authority awareness campaign using donated Netflix and Waitrose inventory, and a cookieless-targeting tie-up between TapTap Digital and Skyrise, don't move any operator decisions. TapTap is pitching "target audiences without cookies or personal identifiers," which is the same sentence every identity vendor has shipped since 2020. No methodology, no scale, no independent measurement. File it.

Our call: By the FTC's spring 2027 enforcement cadence, US regulators will announce at least one additional children's-privacy or COPPA enforcement action above $50 million, explicitly citing breach of a prior consent order as an aggravating factor. The government spent the effort to prove TikTok's second violation, and that only makes sense if they plan to keep doing it. The companies to watch are anyone already operating under an old FTC privacy settlement.

Also covered this issue

Comments