Skip to main content

Musical.ly (Now TikTok) Agrees to Largest-Ever COPPA Settlement in Record FTC Proceeding



Today, February 27, 2019, the FTC issued the largest civil penalty ever obtained on a children’s privacy case. Musical.ly (now called TikTok) has agreed to pay $5.7 million to settle the Federal Trade Commission's (FTC’s) complaint that the company illegally collected personal information from children. Musical.ly also agreed to comply with Children Online Privacy Protection Act (COPPA) going forward and to take down all videos made by children under the age of 13.

Musical.ly’s platform allowed users to create and post short videos lip-syncing to music, as well as communicate with other users in the social network. All users were required to provide a first and last name, email address, phone number, profile picture, and biography to register for the app. The company had knowledge that a significant portion of its users were under 13 years old.

The FTC learned of the issues when CARU referred the matter to the FTC last spring. In its complaint, the FTC claimed that the company was aware of the fact that many children used its app, but failed to follow COPPA in notifying parents about the app’s collection and use of children’s personal information, obtaining parental consent for such collection, and deleting personal information at the request of parents. The settlement is a big win for child advocacy groups, and addresses the growing concern of children’s privacy protection in the age of Big Tech.

In a joint statement, FTC Commissioner Rohit Chopra and Commissioner Rebecca Kelly Slaughter note that the case was a major milestone for the COPPA enforcement program. The Commissioners noted the company's willingness to pursue growth at the expense of children and the belief that company executives should be held accountable for the disregard of the law. 

For more information about the Musical.ly decision, read the FTC's Press Release or the Commissioners joint statement.

Read CARU's Press Release about its referral of the Musical.ly case to the FTC.

See a quote from CARU's director, Dona Fraser in this Wired article.

Popular posts from this blog

20 Years Young: The History and Maturing of COPPA in a Privacy-Conscious Age

1998: A Concern for Children’s Privacy Was Born From the moment home computers had the capacity to connect to the Internet, children had the ability to use these technologies to access online websites and services. In the 1990s, concerns about children’s privacy and safety online arose amid fears of marketing practices around selling children’s personal information and exposing children’s information to predators. The Children’s Advertising Review Unit (CARU), founded in 1974, has always been on the forefront of safeguarding children’s privacy. CARU is the self-regulatory arm of the children’s advertising industry, tasked with promoting truth in children’s advertising by reviewing and evaluating child-directed ads in all media to ensure they are truthful, accurate and appropriate. CARU also monitors online privacy practices as they affect children. Before there was any legislation on the matter, CARU monitored a burgeoning Internet and observed how children’s privacy and sa...

After Review, CARU Finds Snapchat Compliant with COPPA

In a recent decision, CARU found Snap Inc.’s (Snap) Snapchat app to be compliant with both the CARU Guidelines and the Children's Online Privacy Protection Act (COPPA).  “The company goes beyond minimal procedures to prevent under-age use” CARU stated. CARU determined that Snapchat is an app directed to a general audience, not intended for use by children. In reaching this conclusion, CARU considered that Snap’s Terms of Service clearly prohibit users under 13 years of age and makes no effort to market the app to children or provide them with an appealing user experience.  With that understanding, Snapchat is permitted under the Guidelines and Children’s Online Privacy Protection Act (“COPPA”) to age-gate and block children under 13 from using its services, which it does. CARU then examined whether Snapchat does so effectively. CARU observed that Snapchat utilizes age-gates and many safeguards to ensure that if children manage to breach the existing age-...

i-Dressup Shuts Down in Wake of Privacy Breach and COPPA Violation

I-Dressup, a fashion-themed social website for teens, has completely shut down as part of a settlement with the New Jersey Department of Consumer Affairs, following a massive privacy breach and violations of the federal Children's Online Privacy Protection Act (COPPA) and New Jersey state law. In September 2016, a hacker sent 2.2 million i-Dressup account credentials to technology blog Arstechnica as well as to haveibeenpwned.com, a searchable online database of data breaches. Responding to the news, New Jersey investigators discovered that 2,519 of the compromised accounts belonged to New Jersey children below age 13. I-Dressup, allegedly aware that it had child users, had violated COPPA by failing to obtain verifiable parental consent prior to collecting and processing personal information from the children, including first and last names and email addresses. In a consent decree with the New Jersey Attorney General Gurbir Gerwal, parent company...