5 pillars of drop shipping contracts: Creating security in a fast-growth model
Drop shipping is growing fast. Find out how the right contracts can protect your margins, brand and legal position.
Read MoreThe ICO found that TikTok allowed up to 1.4 million UK children under the age of 13 to use its platform without obtaining parental consent, which breached article 8 of the UK GDPR.
13 April 2023
Insight
The ICO has issued the social media platform TikTok with a £12.7m fine for breaching the UK GDPR, including failing to process children’s data lawfully.
Children’s data requires specific protection as children may be less aware of the risks and their rights concerning their personal data.
Therefore, organisations should have in place technical and organisational measures to safeguard the rights of children.
Furthermore, article 8 of the UK GDPR states that when you are providing online services to a child under the age of 13, you need to get consent from whoever holds parental responsibility for the child.
The ICO estimated that TikTok allowed up to 1.4 million UK children under the age of 13 to use its platform, despite it having rules that do not allow children of this age to access the platform.
The ICO’s investigation found that TikTok failed to obtain parental consent for these children using its platform, and therefore the collection of their data was unlawful. Furthermore, the ICO found that TikTok did not take adequate checks to identify and remove underage children from its platform, despite concerns raised internally with senior employees.
A major concern of the ICO was that the data collected by TikTok could be used to track the underage children and possibly deliver harmful and/or inappropriate content to them.
Under the UK GDPR, an organisation can be fined up to the higher of £17.5m or 4% of the organisation’s global annual turnover.
The ICO initially issued TikTok with a notice of intent which could have seen TikTok facing a £27 million fine. However, after the ICO heard TikTok’s representations, it narrowed the scope of its pursual, particularly excluding its findings related to the misuse of special category data (which includes data such as ethnicity, health records and sexual orientation). TikTok was ultimately fined £12.7m for its non-compliance with the UK GDPR.
Following the ICOs investigation into TikTok, it has published the Children’s Code which gives further guidance on the measures that should be taken in relation to children’s data, which include (but are not limited to):
The purpose of the code is to ensure the safety of children whose prevalence in online services is ever increasing, and the ICO’s fine to TikTok serves as a stark reminder to organisations collecting children’s personal data that they must do so lawfully, or potentially face serious consequences.
Contact Us
If you have any questions about how your company can ensure its compliance with the UK GDPR or any other data protection and commercial legal issues, our highly experienced Commercial team will be happy to help. Please contact Haroon Younis on 01332 226 466 or fill in the form below to request a no-obligation discussion.
Related Services
Knowledge
Drop shipping is growing fast. Find out how the right contracts can protect your margins, brand and legal position.
Read MoreLearn about fiduciary duties, commission disclosure, and legal compliance after the Expert Tooling v Engie ruling.
Read MoreLearn how Rukhadze v Recovery Partners reinforces strict fiduciary duties and what it means for your business and governance.
Read MoreThe ICO and CMA's joint statement outlines new AI in finance regulations, focusing on data protection, competition, and consumer safeguards.
Read MoreA decade of progress – but the fight against modern slavery isn’t over, we highlight how businesses can meet stricter transparency rules.
Read MoreNavigate AI regulations in financial services. Key insights from the FCA & ICO on compliance, data protection, and innovation.
Read MoreExplore how to create an AI usage policy that mitigates risks and ensures responsible adoption for your business.
Read MoreEffective data safety and optimisation are key to business success, reducing risks and improving efficiency in a digital world.
Read MoreLandmark EU court ruling awards damages for unlawful data transfer. Learn what this means for GDPR compliance and safeguarding your business.
Read MoreProtect your SME from data breaches. Discover key tips for GDPR compliance and data security during Data Protection Week.
Read MoreBoost profitability with well-negotiated commercial contracts—learn essential terms to protect and grow your business.
Read MoreDiscover the key changes introduced by the Data (Use and Access) Bill and how organisations must adapt to meet compliance requirements.
Read MoreScroll to next section
Scroll back to the top


On Monday 29 September, Flint Bishop successfully completed the acquisition of the entire business of Lupton Fawcett LLP. You have been forwarded to the page most relevant to your visit.
Please feel free to explore our website and learn more about our legal services and professionals, including those who have recently joined us from Lupton Fawcett.
