TikTok and parent company ByteDance have agreed to pay $400 million to resolve U.S. Justice Department allegations that the short-video platform violated federal protections governing children’s online privacy. The government sued the companies in 2024, accusing them of collecting personal information from users under age 13 without obtaining required parental consent.

Under the settlement, TikTok will pay $300 million immediately and another $100 million if a previous Federal Trade Commission consent decree is vacated. That decree dates to 2019, when TikTok predecessor Musical.ly paid $5.7 million to settle allegations that it knowingly collected information from children without parental consent.

The case illustrates the potential severity of privacy and regulatory exposures for companies that collect consumer data. For insurance claims professionals, large privacy settlements can raise questions involving cyber liability coverage, regulatory proceedings, defense expenses and the treatment of fines, penalties or settlement payments under applicable policies. Coverage will depend on policy language, allegations and governing law.

The dispute also shows how a company’s compliance history can become important when evaluating later claims. Regulators cited changes TikTok has made to its ownership, management, compliance operations and privacy practices since the lawsuit was filed. TikTok also says it uses age-moderation systems and trained personnel to identify and remove accounts belonging to children under 13.

For cyber and liability adjusters, the settlement is another example of privacy claims extending beyond a single data breach. Claims can arise from how personal information is collected, whether legally required consent was obtained and whether an organization complied with earlier regulatory requirements.