In a recent development that showcases the intensifying scrutiny of Big Tech’s handling of user data, Ireland’s data protection authority has landed a hefty €345 million fine on TikTok. The popular Chinese-owned social media platform faces this penalty over the alleged mishandling of children’s personal data. This significant fine holds the distinction of being the fifth-largest since the European Union (EU) implemented its stringent privacy regulations in 2018.

When and why did it all go wrong?

The origins of the breaches and the resulting fine can be traced back to an inquiry initiated by the Irish privacy watchdog. The probe focused on TikTok’s data processing of its minor users aged between 13 and 17, which took place between July and December 2020. The findings presented a concerning picture:

  1. Public by Default: Accounts of child users were set to public mode by default, which implied that their videos, too, were visible to all by default.
  2. Family Pairing Flaws: The ‘family pairing’ feature allowed child users’ accounts to be linked with an adult’s account. Shockingly, TikTok did not verify whether the paired adult user was indeed the child’s guardian or parent.

TikTok, under the umbrella of its parent company ByteDance, now has a three-month window to align its data processing practices with the EU’s General Data Protection Regulation (GDPR).

TikTok’s Defence

In response, a spokesperson from TikTok claimed that the controversial features were in place three years ago and had undergone changes even before the investigation commenced. Specifically, accounts of users under 16 were set to private by default. The spokesperson stated, “We respectfully disagree with the decision, particularly the level of the fine imposed.” In an official statement, TikTok emphasized the company’s proactive approach by being the “first major platform” to set accounts of users aged between 13 to 15 to private by default, as of January 2021.

The Bigger Picture: Ireland’s Data Protection Authority

The Irish Data Protection Authority has often been at the receiving end of criticism from privacy activists like Max Schrems and organizations such as the Irish Council for Civil Liberties. Accusations range from the watchdog being too passive and slow with its enforcement to its lack of resources.

 

Schrems, a vocal critic, pointed out the irony in an article on the online platform Law.com: “We’re talking about digital technology, but the procedures are run like in the 18th century.” He commented that many enforcement procedures, which could be automated, are still done manually. Schrems underscores the inefficiency, stating that in Ireland, a staggering “99.96% of cases don’t get a decision.”

Not the First and Not the Last

This is not TikTok’s first tryst with regulatory action. In April, the U.K.’s data protection authority fined TikTok £12.7 million over the unlawful use of underage users’ data. Earlier this year, the data privacy watchdog hit Meta with a monumental €1.2 billion fine for inadequate data protection across the Atlantic. 

Protecting our Future

As the digital era continues to advance, the tug-of-war between tech giants and regulatory bodies over data privacy will only intensify. Companies need to be more vigilant, transparent, and proactive in their data-handling practices. While tech platforms must innovate and offer novel features, the safety and privacy of their youngest users should remain paramount.

By Milan Schuster l Partner l Adams Law LLP | Dublin