When TikTok and ByteDance agreed to pay up to $400 million to settle Children's Online Privacy Protection Act allegations, it became one of the largest COPPA recoveries on record. The Justice Department alleged the platform collected data from children under 13 without parental consent and failed to honor deletion requests.
These violations didn't occur because TikTok's team was unaware of COPPA. They happened because the company operated on faulty assumptions about what compliance actually requires. The same myths that trapped TikTok are circulating in compliance teams right now.
Myth 1: Age Gates Are Sufficient Age Verification
The myth: Asking users to enter their birthdate during registration fulfills your age-verification obligation.
The reality: COPPA requires you to prevent children under 13 from creating accounts, not just ask them to leave. A self-reported birthdate isn't verification; it's an honor system that children routinely circumvent.
The TikTok settlement highlights this gap. The Justice Department alleged the platform allowed children under 13 to create accounts despite collecting birthdates. After the lawsuit, TikTok implemented systems to identify users who misrepresent their age and trained employees in underage moderation.
Your age-assurance mechanism must detect and block underage users who lie about their age. This means using behavioral signals, device fingerprinting, or third-party age-estimation tools. If your current approach is "we asked and they said they're 14," you don't have age verification.
Myth 2: Parental Consent Means Sending an Email
The myth: You can obtain valid parental consent by emailing a parent and waiting for a reply.
The reality: COPPA defines specific methods for verifiable parental consent, and a simple email exchange isn't one of them. The regulation requires a method that reasonably ensures the person providing consent is actually the child's parent.
Acceptable methods include requiring a credit card or other payment method in the parent's name, submitting a government-issued ID, using video-conferencing to verify identity, or checking a government-issued ID against a database. Email confirmation alone doesn't meet this standard because you can't verify who's on the other end.
The allegations against TikTok included collecting personal information without required parental consent. Your consent mechanism must include identity verification, not just contact confirmation.
Myth 3: You Only Need to Delete the Account
The myth: When a parent requests account deletion, removing the profile satisfies your obligation.
The reality: COPPA requires you to delete the child's personal information, not just deactivate the account. This means purging data from active databases, backup systems, analytics platforms, and any third-party processors who received it.
The Justice Department alleged TikTok failed to honor some parents' deletion requests. This failure pattern is common because teams confuse account removal with data purging. Your account-deletion workflow might mark a profile as inactive while leaving email addresses, device identifiers, location history, and behavioral data in retention.
Build a deletion process that traces data through your entire processing chain. Document which systems hold children's data, map the retention periods for each, and create automated purging workflows that execute across all of them. If your data-discovery tools can't identify where a specific child's information lives, you can't delete it on request.
Myth 4: COPPA Only Applies If You Target Children
The myth: If your platform isn't specifically designed for children, COPPA doesn't apply to you.
The reality: COPPA applies to operators of websites or online services directed to children, and to operators with actual knowledge that they're collecting information from children. "Actual knowledge" includes willful ignorance; you can't avoid COPPA by deliberately not checking user ages.
If your platform attracts a significant child audience, implements features that appeal to children, or uses child-oriented advertising, regulators will likely consider you directed to children regardless of your stated target demographic. The Musical.ly settlement in 2019 involved a $5.7 million penalty for knowingly allowing young children to use the service without parental consent.
Review your user analytics. If a meaningful percentage of your active users are under 13, you need COPPA compliance mechanisms even if your terms of service prohibit child accounts. Stating "our service is for ages 13+" doesn't exempt you when you have actual knowledge of underage users.
Myth 5: Third-Party Processors Handle Their Own COPPA Compliance
The myth: If you share children's data with analytics vendors, advertising networks, or cloud infrastructure providers, those processors are responsible for their own COPPA compliance.
The reality: You remain liable for COPPA violations even when third parties process the data. Your processor agreements must explicitly prohibit further use or disclosure of children's information, and you must monitor compliance.
This means auditing every vendor who touches data from your platform. Your analytics provider can't use children's behavioral data to build advertising profiles. Your customer-support platform can't retain chat transcripts beyond your stated retention period. Your email vendor can't append children's addresses to marketing lists.
Include COPPA-specific terms in your processor agreements: restrictions on data use, requirements for secure deletion, prohibitions on further disclosure, and audit rights. If you can't verify that a processor maintains COPPA-compliant practices, don't send them children's data.
What to Do Instead
Start with a complete data inventory that identifies every system collecting, storing, or processing information from users under 13. Map the data flows from collection through deletion.
Implement age-assurance mechanisms that detect misrepresentation, not just self-reporting. Build verifiable parental consent workflows using one of COPPA's approved methods. Design deletion processes that purge data across your entire processing chain, including backups and third-party systems.
Document your compliance measures in writing. The settlement notes that TikTok made significant changes to its compliance operations and privacy practices after the lawsuit. Those changes should have happened before the $300 million civil penalty.
COPPA violations don't result from ignorance of the law. They result from assuming that minimal effort satisfies complex requirements. YouTube paid $170 million in 2019; Epic Games paid $275 million in 2022. The financial penalties are escalating, and the compliance expectations are becoming more specific.
Your age gate isn't verification. Your email isn't consent. Your account deactivation isn't deletion. Fix these gaps before a regulator does it for you.



