TikTok – Violation Found (Italy, 2021)

Violation Found
Garante per la protezione dei dati personali25 March 2021Italy
final
ePrivacy
Violation Found

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

Italy's data protection authority found that TikTok was not doing enough to protect users under 13. This is important because it shows that platforms must take extra steps to safeguard young users' data.

What happened

TikTok's age verification process was deemed insufficient to prevent underage users from accessing the platform.

Who was affected

Users under the age of 13 who are using TikTok.

What the authority found

The Italian DPA ruled that TikTok failed to implement adequate measures to limit access for users under 13, violating GDPR requirements.

Why this matters

This ruling emphasizes the responsibility of social media platforms to protect young users and may lead to stricter regulations on age verification in the future.

GDPR Articles Cited

AI-verified

Art. 12(GDPR)
Art. 13(GDPR)
Art. 24(GDPR)
Art. 25(GDPR)
View original scraped data
Art. 12(GDPR)
Art. 13(GDPR)
Art. 24(GDPR)
Art. 25(GDPR)
Art. 58(2)(d) GDPR
Art. 58(2)(f) GDPR
Art. 66(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 11 April 2026
articles corrected
Full Legal Summary
Detailed

On the 22nd of January 2021 the Garante issued a first decision imposing the limitation of TikTok's processing of personal data related to users under the age of 13. On the 11th of February 2021, the Garante issued a [https://www.garanteprivacy.it/web/guest/home/docweb/-/docweb-display/docweb/9554603 second decision] renewing such limitation. In the decision, the Garante presents some findings of its report on the compliance of TikTok with the notification received from the Garante itself. First, according to the authority, the self-certification mechanism implemented by TikTok to verify the age of its users is not sufficient to “significantly limiting the number of users under the age of 13”. Secondly, the message delivered to the media by TikTok did not have the “necessary elements of urgency and alarm” to raise awareness concerning parental liability. Moreover, the additional measures adopted by the social network – such as implementing a new reporting system, increasing the number of Italian moderators and the monitoring of users activities – did not bring any result, according to the Italian DPA. The Garante was also not satisfied with the deposition presented by TikTok. According to the Supervisory Authority, “an agreement whereby a minor user consents to the processing of his or her personal data in connection with the use of an information society service cannot be considered, under Italian law on the validity of contracts, an "atto comune" (literally “common act”), with the result that the relevant contract cannot be considered validly concluded”. Moreover, the information provided as per Article 13 GDPR were not compliant with the requirements of Article 12 GDPR in light of the fact that TikTok services are factually intended for minors. Finally, the age verification mechanisms did not respect the privacy by design principle. According to the Garante, these findings confirm the unlawful nature of the data processing, and the persistence of the risks for

Outcome

Violation Found

The DPA found a violation but did not impose a fine.

Details

Decision Date

25 March 2021

Authority

Garante per la protezione dei dati personali

GDPRhub ID

gdprhub-3366

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. TikTok - Italy (2021). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: