TikTok – Violation Found (Italy, 2021)
TikTok faced scrutiny from Italy's data protection authority for not properly limiting data processing for users under 13. The authority found that TikTok's age verification methods were not effective enough to protect young users. This matters because it highlights the responsibility of social media platforms to safeguard children's data.
What happened
TikTok was criticized for its inadequate age verification system for users under 13 years old.
Who was affected
Young users under the age of 13 who were using TikTok without proper data protection measures.
What the authority found
The authority determined that TikTok's methods did not sufficiently limit access for users under 13, violating data protection rules.
Why this matters
This case emphasizes the need for social media companies to implement stronger age verification measures. It serves as a warning that failure to protect minors' data can lead to regulatory action.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
On the 22nd of January 2021 the Garante issued a first decision imposing the limitation of TikTok's processing of personal data related to users under the age of 13. On the 11th of February 2021, the Garante issued a [https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9554603 second decision] renewing such limitation. In the decision, the Garante presents some findings of its report on the compliance of TikTok with the notification received from the Garante itself. First, according to the authority, the self-certification mechanism implemented by TikTok to verify the age of its users is not sufficient to “significantly limiting the number of users under the age of 13”. Secondly, the message delivered to the media by TikTok did not have the “necessary elements of urgency and alarm” to raise awareness concerning parental liability. Moreover, the additional measures adopted by the social network – such as implementing a new reporting system, increasing the number of Italian moderators and the monitoring of users activities – did not bring any result, according to the Italian DPA. The Garante was also not satisfied with the deposition presented by TikTok. According to the Supervisory Authority, “an agreement whereby a minor user consents to the processing of his or her personal data in connection with the use of an information society service cannot be considered, under Italian law on the validity of contracts, an "atto comune" (literally “common act”), with the result that the relevant contract cannot be considered validly concluded”. Moreover, the information provided as per Article 13 GDPR were not compliant with the requirements of Article 12 GDPR in light of the fact that TikTok services are factually intended for minors. Finally, the age verification mechanisms did not respect the privacy by design principle. According to the Garante, these findings confirm the unlawful nature of the data processing, and the persistence of the risks for
Outcome
Violation Found
The DPA found a violation but did not impose a fine.
Related Enforcement Actions (1)
Other enforcement actions involving TikTok in IT
Details
Decision Date
25 March 2021
Authority
Garante per la protezione dei dati personali
GDPRhub ID
gdprhub-3366About this data
Cite as: Cookie Fines. TikTok - Italy (2021). Retrieved from cookiefines.eu
Last updated: