TikTok has lost its appeal against a £12.7m penalty from the UK's data protection regulator, closing out a case centered on how the platform handled the personal data of more than 1.4 million children under the age of 13. The ruling upholds the original finding: TikTok illegally processed data belonging to users who should never have been on the platform in the first place, given its own minimum age requirements.
The outcome of this TikTok child data fine case is a reminder that regulators are increasingly willing to hold major platforms accountable for how they treat young users, and that appeals don't automatically undo those findings. For parents, it's also a prompt to look more closely at what's actually happening behind the sign-up screens their kids use every day.
What the £12.7m Ruling Found TikTok Did Wrong
At the heart of the case was a straightforward but serious problem: TikTok's own terms state that users must be at least 13 years old to create an account, yet the platform ended up processing data from well over a million children who were younger than that. The UK's data protection regulator determined that TikTok failed to do enough to identify and remove these underage accounts, meaning children's personal information, potentially including behavioral data used to power recommendation algorithms, was collected and used without the legal basis required under data protection law.
TikTok challenged the original penalty through an appeal, arguing against the regulator's findings. That appeal has now failed, meaning the £12.7m fine stands. For a company of TikTok's scale, the financial penalty is notable, but the bigger signal is that the underlying enforcement action, and the reasoning behind it, has been tested in a legal challenge and upheld.
How Under-13s' Data Was Collected Without Consent
The core issue isn't that TikTok set out to specifically target young children. It's that the systems meant to catch and remove underage users didn't work well enough, and once a child's account existed, the platform's standard data collection practices kicked in the same as they would for an adult. That means location signals, viewing habits, engagement patterns, and other data points could be gathered from a child user just as easily as from anyone else, without a parent or guardian ever having given informed consent.
This is a familiar failure point across the tech industry: consent mechanisms are often built for scale and simplicity rather than genuine transparency. The same dynamic shows up in seemingly unrelated corners of the web. A recent GDPR complaint over dict.cc's sprawling consent banner, which reportedly connects visitors to over 1,700 advertising partners through a single click, illustrates how consent interfaces can be technically present while doing very little to inform users about what's actually happening with their data. Age verification adds another layer of difficulty entirely, since a child can simply enter a false birth date and the platform has to decide how hard to work to catch that.
What This Means for You: Parents Managing Kids' App Privacy
The practical lesson from this case is that platform defaults cannot be trusted to protect a child's data on their own, even when a company's terms technically prohibit underage use. If a determined regulator can find that over 1.4 million children slipped through TikTok's age checks, it's safe to assume similar gaps exist elsewhere.
Parents don't need to become privacy experts to close many of these gaps. A few concrete steps go a long way: check the actual date of birth entered when an account was created, review the app's privacy and ad personalization settings rather than accepting whatever is selected by default, and periodically look at what permissions the app has been granted on the device itself, such as location, contacts, or microphone access. Many platforms also offer family pairing or supervised account features that restrict data collection and content exposure for younger users, but these typically have to be turned on manually.
The Wider Crackdown on Youth Data Practices
This ruling doesn't exist in isolation. Regulators across multiple jurisdictions have been paying closer attention to how platforms handle younger users, treating children's data as an area that deserves stricter scrutiny than general adult data processing. The fact that TikTok's appeal failed, rather than resulting in a reduced penalty or overturned findings, suggests regulators are prepared to have their enforcement decisions tested in court and are confident in the evidence behind them.
For an industry built on data-driven engagement, that's a meaningful signal. Age verification and consent processes that were once treated as a checkbox exercise are increasingly being examined as substantive legal obligations, and the consequences for getting it wrong are measured in the millions.
Takeaways for Readers
The TikTok child data fine being upheld on appeal is a useful checkpoint for any parent whose child uses social media. Don't assume an app's minimum age policy means your child's data is automatically protected: verify account details yourself, turn on any available parental supervision tools, and periodically review app permissions rather than relying on defaults. If you want a sense of how murky consent processes can look in practice, it's worth reading how a single consent banner can quietly route a user's data to well over a thousand partners. Taking twenty minutes to audit your child's app settings today is a far better use of time than waiting for the next regulatory ruling to explain what went wrong.




