TikTok held accountable with £12.7m fine for misusing children’s data
After three years, TikTok has agreed to pay the £12.7 million fine in the UK for unlawfully processing children’s data. This case shows why the Age Appropriate Design Code must be given statutory force.

TikTok has withdrawn its appeal and agreed to pay the £12.7 million fine imposed by the Information Commissioner’s Office (ICO) in 2023 for breaches of data protection law relating to children’s personal data. The ICO found that TikTok had failed to use children’s data lawfully, failed to provide clear information about how children’s data was collected, used and shared, and failed to take adequate steps to identify and remove underage users.
We welcome the ICO’s action in holding one of the world’s largest technology companies to account. No company should be beyond regulatory scrutiny because of its size, influence or commercial power.
In August, the Upper Tribunal rejected TikTok’s argument that its processing of personal data fell within the “special purposes” provisions, including artistic purposes. This is an important legal precedent: companies should not be able to rely on broad interpretations of exemptions to avoid scrutiny of how they process children’s data.
While we welcome the conclusion of this case, it has taken three years to reach this point. This delay, however, underlines the need to give the Age Appropriate Design Code statutory force, turning its higher standards for protecting children into clear legal requirements rather than leaving companies to interpret how they should be applied.
Head of UK Affairs Colette Collins-Walsh said:
“Children’s data does not stop being protected because it is commercially valuable, makes a platform more engaging, or is central to how a service operates. The UK GDPR recognises that children need higher protection. The question is whether those protections are strong enough in practice. The Age Appropriate Design Code already tells companies what higher protection should look like. We now need those standards to have greater legal force, so that protecting children is a requirement of how digital services are designed, not something companies can choose how to interpret.”
