← All enforcement actions
GDPRAge-Appropriate DesignB2C Tech

TikTok€345M GDPR fine (2023)

Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations

Penalty
€345M
Regulator
Irish DPC
Jurisdiction
European Union

What happened

Ireland's DPC fined TikTok €345M for setting children's accounts to public by default, allowing adult 'family pairing' without proper verification, and providing inadequate age-appropriate transparency notices. The decision covered processing between July and December 2020.

Root cause

What every team should do

  1. Default minors' accounts private (Article 25 — data protection by default)
  2. Build verified-parent consent flow for any feature affecting child accounts
  3. Write age-appropriate privacy notices (UK Age-Appropriate Design Code is the gold standard)
Source: Irish DPC final decision (Sep 15, 2023).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GDPR controls you are missing — mapped to enforcement patterns like this one.

Run my GDPR audit Generate missing policies

Related enforcement actions

Meta Platforms
€1.2B
Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework
Amazon Europe Core
€746M
Largest GDPR fine at the time — behavioural ad targeting without valid consent
Meta / Instagram
€405M
Children's business-account email + phone exposed publicly
British Airways
£20M
Magecart-style skimmer on payment page — 429K records exposed