IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

TikTok could be hit with £27m fine for failing to protect children's privacy

Social media firm issued with a notice from the ICO for potential violations of UK data protection laws

Social media firm TikTok could face a £27 million fine under UK data protection laws for failing to protect children's privacy on its platform.

The Information Commissioner's Office (ICO) has issued a notice of intent to TikTok and TikTok Information Technologies UK, following an investigation into the company's practices. 

The notice - which is a legal document that precedes a potential fine - explains the ICO's provisional view that TikTok breached UK data protection law between May 2018 and July 2020. 

It alleges that TikTok processed the data of children who were under the age of 13 without appropriate parental consent and that the company failed to provide proper information to its users in a concise, transparent and easily understandable way. The notice also accuses TikTok of processing special category data, such as personal information revealing ethnic origin or political opinions, without the legal grounds to do so. 

"While we respect the ICO's role in safeguarding privacy in the UK, we disagree with the preliminary views expressed and intend to formally respond to the ICO in due course," a TikTok spokesperson said. 

It is worth noting here that the Commissioner's findings are provisional and that no conclusions should be drawn at this stage. TikTok, in theory, could walk away without any penalty being imposed and a representative from the company will have the chance to argue its case to the ICO before a final decision is made.  

"We all want children to be able to learn and experience the digital world, but with proper data privacy protections," information commissioner, John Edwards, said. "Companies providing digital services have a legal duty to put those protections in place, but our provisional view is that TikTok fell short of meeting that requirement."

Related Resource

Cyber resiliency and end-user performance

Reduce risk and deliver greater business success with cyber-resilience capabilities

Whitepaper cover with title and text, and image of pyramid cyber-resilience modelFree Download

Edwards added that the regulator's work to better protect children online involves working with organisations, such as TikTok, but that it will also involve enforcement action "where necessary". 

In addition to this, Edwards said the ICO was currently looking into how over 50 different online services are conforming with the Children's code. He also revealed that the watchdog has six ongoing investigations looking into companies providing digital services. What's more, in its initial view, Edwards added that these companies hadn't taken their responsibilities around child safety seriously enough. Which suggests more notices could be coming. 

Featured Resources

2022 State of the multi-cloud report

What are the biggest multi-cloud motivations for decision-makers, and what are the leading challenges

Free Download

The Total Economic Impact™ of IBM robotic process automation

Cost savings and business benefits enabled by robotic process automation

Free Download

Multi-cloud data integration for data leaders

A holistic data-fabric approach to multi-cloud integration

Free Download

MLOps and trustworthy AI for data leaders

A data fabric approach to MLOps and trustworthy AI

Free Download

Most Popular

Empowering employees to truly work anywhere

Empowering employees to truly work anywhere

22 Nov 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

15 Nov 2022
The top 12 password-cracking techniques used by hackers

The top 12 password-cracking techniques used by hackers

14 Nov 2022