The U.S. Department of Justice has announced a $400 million settlement with TikTok and ByteDance resolving children’s privacy litigation under the Children’s Online Privacy Protection Act. According to the government, the deal resolves a 2024 lawsuit alleging unlawful data practices involving minors and ranks among the largest recoveries ever obtained in a COPPA matter.

For companies operating consumer-facing digital platforms, the size of the settlement is the headline—but the broader takeaway is the government’s continued willingness to pursue major privacy penalties where minors are involved. COPPA has long been a core enforcement tool, but this resolution underscores that regulators are treating children’s data governance as a top-tier risk area, especially for high-scale platforms with substantial youth engagement.

Legally, the settlement is significant for several reasons. First, it reinforces that children’s privacy cases can produce nine-figure exposure, even outside the more familiar FTC consent-order context. Second, it shows DOJ’s role in converting privacy allegations into headline enforcement outcomes with substantial monetary consequences. Third, it adds to the growing body of tech-enforcement matters in which regulators focus not just on disclosure language, but on product design, data collection flows, age-gating, parental consent mechanisms, and internal compliance controls.

For litigators, the resolution offers another benchmark for evaluating enforcement risk, settlement posture, and damages exposure in privacy investigations involving minors. For in-house counsel, it is a reminder that youth-user issues cannot be siloed to trust-and-safety teams or product lawyers alone. Privacy representations, app design, onboarding flows, retention practices, and vendor relationships can all become central in a government case. And for compliance teams, the matter highlights the importance of documenting how age screening, parental notice, consent collection, and data minimization actually function in practice—not merely how policies describe them.

The settlement also arrives amid broader scrutiny of large technology platforms and their handling of sensitive user data. That makes this more than a one-off enforcement event. Companies likely to attract under-13 users—or even mixed-age audiences where age signals may be ambiguous—should expect closer examination of whether their systems are engineered to identify child users and limit collection accordingly.

From a risk-management standpoint, legal teams should view this case as a prompt to revisit COPPA compliance with fresh eyes. A platform’s youth-privacy exposure may turn less on formal policy language than on what its product architecture permits, what telemetry it captures, and what the company knew about actual user demographics. This settlement makes clear that when regulators believe children’s data was mishandled at scale, the financial and reputational stakes can be enormous.