Article content
In briefShow moreShow lessThe Irish Data Protection Commission has fined TikTok €345 million following a cross-border GDPR investigation into the treatment of users aged 13 to 17.
- The Irish Data Protection Commission has fined TikTok €345 million following a cross-border GDPR investigation into the treatment of users aged 13 to 17.
- The case concerned TikTok's processing between 31 July and 31 December 2020.
- The GDPR already applies in Norway through the EEA; the Irish lead authority decision concerns cross-border processing in the EEA and does not amend Norwegian law.
What happened
The Irish Data Protection Commission has fined TikTok €345 million following a cross-border GDPR investigation into the treatment of users aged 13 to 17. The final decision followed a binding decision by the European Data Protection Board (EDPB) and puts a sharp focus on how defaults, choices and interface design shape children's privacy.
The case concerned TikTok's processing between 31 July and 31 December 2020. The authority found infringements involving transparency, accountability, and data protection by design and by default. During part of the period, registered children's accounts were public by default. Their content could therefore be visible to anyone, including people without a TikTok account. The EDPB also examined two pop-up messages shown to children. It concluded that the options were not presented objectively and neutrally and could steer users towards choices offering less privacy.
What this means for organisations
The decision shows why information security and privacy cannot be reduced to access controls and legal notices. Product design is itself a control. A service may have strong technical safeguards and still breach the GDPR if its default configuration exposes information unnecessarily or its interface makes the privacy-preserving option harder to choose.
Organisations offering digital services to children should document the defaults applied to each age group, who can view profiles and content, and how every choice is presented. Risk assessments should test the real user journey from a child's perspective. Merely making a safer option available is insufficient; that option must be understandable and as easy to select.
The case did not change the GDPR. It enforced existing duties, including fairness, transparency, and privacy by default. As the GDPR applies in Norway through the EEA framework, the findings are relevant to Norwegian organisations processing children's personal data, even though the Irish authority acted as lead supervisory authority.
Sources
European Data Protection Board: “Following EDPB decision, TikTok ordered to eliminate unfair design practices concerning children,” 15 September 2023.
European Data Protection Board: “EDPB Binding Decision 2/2023,” 2 August 2023.
For discussion
Which decisions, defaults or supplier dependencies in our organisation should we examine first in light of this development?








