
The test
On 1 September 2023 Ireland's Data Protection Commission (DPC) adopted a decision closing its inquiry into TikTok Technology Limited, examining how the platform handled child users' accounts between 31 July and 31 December 2020. The DPC's own summary states the inquiry covered public-by-default account settings, the Family Pairing parental-linking feature, and age-verification checks at registration. The decision found breaches of eight GDPR provisions and imposed a reprimand, a three-month compliance order, and administrative fines. The DPC's 15 September 2023 announcement put the fines at 345 million euro.
What the evidence says
Both documents are the regulator's own record, not third-party analysis. They state that TikTok's platform set child accounts to public by default during the review period, that Family Pairing let a linked adult account enable direct messaging for a child's account without verifying the linked adult was actually a parent, and that TikTok did not give users clear enough information about these defaults. A late addition matters for how the finding should be read: the decision explains that the European Data Protection Board's binding decision directed Ireland to include a finding that the defaults also breached the general fairness principle, describing the design as a 'dark pattern.' That instruction came from the EU-wide board, not from Ireland's own initial draft, and the DPC's published decision presents its fairness finding as following the board's direction.
The sample and the variance
The inquiry's window is narrow and dated: five months of 2020, not TikTok's current settings or current age-verification process, neither of which this record describes. The 345 million euro figure is a disclosed regulatory fine tied to a finding of infringement, not a modelled estimate of harm to users, and it should not be read as a statement about TikTok's practices today. The order required compliance changes within three months of the 2023 decision, so the underlying defaults, if still in place at the time of the ruling, would have needed to change shortly afterward.
What to try next
A publisher or platform observer citing this case should specify the 2020 period and the two named features, rather than describing it as a general finding about TikTok's child-safety practices today. This is an editorial framing point, not a conclusion drawn by the DPC: the decision does not compare TikTok's 2020 defaults with its settings in any later year.
- Has TikTok published a compliance statement describing what it changed under the DPC's three-month order?
- Do TikTok's current default settings for child accounts differ from the ones described in the 2020 inquiry window?
- Which of the eight GDPR articles named in the decision relate to disclosure, and which relate to the underlying default itself?
A regulator's decision fixes facts to a period and a feature set; treating a 2020 finding as a description of today's product is a shortcut the decision itself does not support.
Sources & limits
- Inquiry into TikTok Technology Limited (September 2023) ↗
States the decision date, the GDPR articles found breached, and the corrective measures ordered.
Source · Source date: 2023-09-01 · Archive retrieval: 2026-09-16 - DPC announces €345 million fine of TikTok ↗
Confirms the fine amount and the EDPB's role in the fairness/dark-patterns finding.
Source · Source date: 2023-09-15 · Archive retrieval: 2026-09-16