Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

TikTok Data Privacy Settlement

TikTok-Data-Privacy-Settlement

Quick answer: TikTok’s $92 million settlement (MDL No. 2948, N.D. Illinois) resolved claims it collected biometric and video-viewing data without consent under Illinois’ BIPA. Final approval came July 28, 2022. Enterprises should document consent for biometric data, set retention limits, and control cross-border transfers before a regulator or plaintiff’s attorney finds the gap first.

  • What it was: a $92 million settlement resolving 21 consolidated federal lawsuits (MDL No. 2948) that alleged TikTok collected biometric identifiers and other personal data without consent.
  • Legal basis: primarily Illinois’ Biometric Information Privacy Act (BIPA), with related claims under the Video Privacy Protection Act (VPPA) and the Computer Fraud and Abuse Act (CFAA).
  • No admission of wrongdoing: TikTok denied the allegations but agreed to pay the settlement fund and change specific data practices.
  • Not the same case as: the separate $400 million COPPA settlement TikTok and ByteDance reached with the U.S. Department of Justice in August 2026, or the Irish Data Protection Commission’s GDPR fines against TikTok. These are distinct legal actions under different laws; this article covers the 2021 to 2022 BIPA class action specifically.
  • Why it matters for enterprises: the case shows how biometric data collection, cross-border data transfer, and undisclosed data sharing with third parties can turn into nine-figure litigation risk, even without a data breach.

Published: December 2022. Updated: August 2026. Reviewed by Encryption Consulting’s Compliance Advisory team.

What Was the TikTok Data Privacy Settlement?

The TikTok data privacy settlement refers to the $92 million agreement TikTok and its parent company ByteDance reached to resolve In re: TikTok, Inc., Consumer Privacy Litigation, a multidistrict litigation (MDL No. 2948) consolidated in the U.S. District Court for the Northern District of Illinois. The case combined 21 separate federal lawsuits, several filed on behalf of minors, alleging TikTok collected and shared personal data, including biometric identifiers, without proper consent. The class covered an estimated 89 million U.S. TikTok users.

TikTok denied every allegation in the complaints. In a statement issued when the deal was announced, the company said it preferred “to focus our efforts on creating a safe and pleasant experience for the TikTok community” rather than continue litigating. Denying wrongdoing while settling is standard practice in class-action privacy litigation and does not indicate the underlying claims were weak; it reflects a cost-and-risk calculation about prolonged discovery and trial exposure under BIPA’s statutory damages.

Primary-Source Timeline

  • 2020 to 2021: Individual and putative class-action lawsuits against TikTok and ByteDance are filed across multiple federal districts; the Judicial Panel on Multidistrict Litigation consolidates them into MDL No. 2948 in the Northern District of Illinois, case no. 1:20-cv-04699.
  • February 25, 2021: The parties announce a $92 million settlement agreement to resolve the consolidated claims.
  • 2021 to early 2022: The court grants preliminary approval; a notice program and claims website (tiktokdataprivacysettlement.com) launch so eligible class members can file claims or opt out.
  • July 28, 2022: U.S. District Judge John Z. Lee grants final approval of the $92 million settlement and enters final judgment.
  • August 2026: TikTok and ByteDance reach a separate $400 million settlement with the U.S. Department of Justice over unrelated Children’s Online Privacy Protection Act (COPPA) claims, a distinct case covered in the update log below.

Tailored Encryption Services

We assess, strategize & implement encryption strategies and solutions.

What Data and Technologies Did the Lawsuit Involve?

The complaints centered on TikTok’s collection and use of biometric identifiers and behavioral data through the app’s content and recommendation features. Plaintiffs alleged the following practices:

  • Facial and biometric scanning: plaintiffs alleged TikTok used facial recognition to derive attributes such as age, gender, and ethnicity from user videos to power its content recommendation engine, without the written consent BIPA requires for Illinois residents.
  • Draft and unposted content: the suit claimed the app captured and analyzed video drafts that users recorded but never published, meaning content people believed was private was allegedly still processed.
  • Third-party data sharing: plaintiffs alleged personal data was shared with outside companies, including Google and Facebook, without adequate disclosure or consent, implicating claims under the VPPA.
  • Device and clipboard access: allegations under the CFAA centered on the app collecting more device-level data than its own privacy policy disclosed, exceeding the access users had authorized.
  • Cross-border data storage: plaintiffs alleged U.S. user data was transmitted to and stored on servers outside the United States, raising the same category of cross-border transfer risk that shows up in GDPR enforcement, even though GDPR itself was not the legal basis for this U.S. case.

As part of the settlement, TikTok agreed to change several of these practices going forward: restrict storage or transmission of domestic users’ biometric and geolocation data outside the U.S., delete pre-uploaded draft content that was never saved or posted, run annual privacy training for employees and contractors, and submit to independent third-party privacy and security audits for three years.

What Was the Real-World Impact of the Settlement?

The $92 million settlement is one of the largest BIPA-related recoveries on record, and its impact went beyond the payout figure.

  • Financial: TikTok funded a $92 million common settlement fund. Individual payouts depended on the total number of valid claims filed; Illinois subclass members received additional distribution shares under the plan of allocation because BIPA carries statutory damages that other states’ residents cannot claim, while nationwide subclass members shared a smaller base allocation.
  • Reputational: the case became a widely cited reference point in the broader debate over TikTok’s data practices, alongside separate national-security review of the app under what is commonly called Project Texas, and it fed public scrutiny that continued through the app’s later COPPA litigation.
  • Regulatory and legal precedent: the settlement reinforced BIPA as one of the most consequential state biometric privacy statutes in the country, encouraging plaintiffs’ firms to bring similar biometric-data claims against other technology and retail companies operating in Illinois.
  • Operational: TikTok’s required changes, including limits on biometric data collection, cross-border storage restrictions, and recurring third-party audits, function as a compliance program a court effectively imposed through a consent-style settlement rather than a formal consent decree.

What Should Organizations Learn From the TikTok Settlement?

The direct lesson is narrow: BIPA applies to any organization that collects biometric identifiers, such as face geometry, fingerprints, or voiceprints, from Illinois residents without written consent and a public retention schedule, and it carries statutory damages of $1,000 to $5,000 per violation regardless of proven harm. The broader lesson applies well beyond Illinois and well beyond TikTok.

Most organizations that build recommendation engines, personalization features, or authentication tools now touch some combination of biometric signals, behavioral data, and cross-border data flows, often without a single team owning the compliance picture across all three. The TikTok case shows regulators and plaintiffs do not need a breach to bring a claim; a documented gap between what a privacy policy discloses and what the product actually collects is enough. Encryption and access controls reduce breach risk, but they do not substitute for consent management, data minimization, and retention discipline, which is where this case’s exposure actually originated.

How Can You Detect Similar Privacy Compliance Gaps in Your Organization?

Start with a direct comparison between what your product actually collects and what your privacy disclosures say it collects. Look for these specific signals:

  • Any feature that scans, matches, or derives attributes from a face, voice, fingerprint, or other biometric identifier without a documented, written consent flow.
  • Mobile SDKs or analytics tools that collect device, clipboard, or usage data beyond what your privacy policy specifically discloses.
  • Video, audio, or content data shared with advertising or analytics partners without a clear consent basis or data processing agreement.
  • User-generated content, including drafts or unpublished uploads, processed or analyzed before the user affirmatively publishes or shares it.
  • Personal data replicated, backed up, or processed in a country your privacy policy or data processing agreements do not disclose.
  • No documented retention or destruction schedule for biometric or other sensitive personal data categories.

A cryptographic and data inventory (mapping what data you hold, where it lives, and how it is protected) is usually the fastest way to surface these gaps, since most of them show up as a mismatch between the data map and the privacy policy rather than as a technical vulnerability.

Remediation Checklist: Reducing Your Organization’s Privacy Litigation Risk

  1. Inventory every system, feature, and SDK that touches biometric identifiers (face, voice, fingerprint, gait) or other sensitive personal data.
  2. Map each data flow against your published privacy policy and flag any collection or sharing practice the policy does not disclose.
  3. Build a written, verifiable consent flow for biometric data collection, including a public retention and destruction schedule, before launching or continuing any biometric feature.
  4. Review third-party data-sharing agreements (ad networks, analytics vendors, cloud providers) to confirm each has a documented legal basis and contractual data protection terms.
  5. Restrict and log cross-border data transfers; document the legal mechanism (standard contractual clauses, adequacy decision, or equivalent) for each transfer.
  6. Encrypt biometric and other sensitive personal data at rest and in transit, and manage the underlying keys through a centralized, auditable system rather than embedded application secrets.
  7. Run recurring, documented employee and contractor training on data privacy handling, matching the annual training TikTok agreed to under its settlement.
  8. Commission an independent third-party privacy and security audit on a recurring cycle, not only after a complaint or lawsuit triggers one.
  9. Assign a single accountable owner (privacy officer, compliance lead, or equivalent) for closing gaps the inventory and audit surface, with a tracked remediation timeline.

Which Privacy Framework Applies to Your Organization?

The TikTok BIPA case sits inside a wider set of privacy frameworks that commonly apply to the same underlying data practices. Use this table to see which requirements are relevant beyond the specific statute this settlement was decided under.

FrameworkWhat It RequiresRelevance to This CaseHow It Applies to Your Organization
BIPA (Illinois Biometric Information Privacy Act)Written consent before collecting biometric identifiers; a public retention and destruction schedule; a private right of action with statutory damagesThe core statute behind TikTok’s $92 million settlementAny biometric login, facial recognition feature, or voice authentication tool touching Illinois residents needs documented consent and a retention policy
VPPA (Video Privacy Protection Act)Bars disclosure of a person’s video-viewing history without consentCited alongside claims that TikTok shared video engagement data with third partiesAny platform logging and sharing video-viewing or engagement data needs a consent-based data-sharing agreement
CFAA (Computer Fraud and Abuse Act)Prohibits exceeding authorized access to a computer or deviceCited over allegations that TikTok’s SDK collected more device data than disclosedApp SDKs and mobile telemetry should collect only what the privacy policy and consent flow authorize
COPPA (Children’s Online Privacy Protection Act)Verifiable parental consent before collecting data from children under 13Not the legal basis of this $92 million case; the basis of TikTok’s separate $400 million DOJ settlement in August 2026Any platform with users who may be under 13 needs age-assurance controls and parental consent workflows, independent of BIPA obligations
GDPR (EU General Data Protection Regulation)Lawful basis for processing, data minimization, safeguards on cross-border transfersNot applicable to this U.S. case, but the Irish Data Protection Commission separately fined TikTok under GDPR for related data-handling practicesOrganizations operating in the EU need parallel biometric and cross-border transfer controls, even after resolving a U.S. claim

Limitations

This settlement resolved the BIPA, VPPA, and CFAA claims consolidated in MDL No. 2948; it did not include a factual finding that TikTok violated any of these laws, since TikTok settled without admitting liability. It does not cover TikTok’s other, separate privacy matters, including the 2026 DOJ COPPA settlement, the Irish Data Protection Commission’s GDPR enforcement actions, or later litigation over in-app browser tracking, each of which proceeds under different legal theories with its own facts and outcome. Individual payout amounts are not detailed here because they depended on the final claims rate and were administered directly through the settlement claims process; readers seeking a specific payment status should consult the official settlement administrator rather than this article. This piece also reflects publicly available court filings and legal reporting rather than access to sealed case materials.

What Would Encryption Consulting Recommend?

Cases like this one are rarely about a single failure. They are usually the result of biometric or behavioral data collection outrunning the consent, retention, and cross-border controls an organization has in place to govern it. Three moves close most of that gap.

  • Start with a Compliance Advisory engagement to map your actual data flows against your privacy disclosures and applicable frameworks (BIPA, COPPA, GDPR, and sector-specific rules), and to build the documentation a regulator or plaintiff’s attorney will ask for first.
  • Use Encryption Advisory to confirm biometric and other sensitive personal data is encrypted at rest and in transit with keys managed centrally, not left to default application-level protection.
  • Deploy PKI-as-a-Service to standardize certificate-based authentication and encryption for cross-border data transfers, so the technical controls match the contractual and consent controls your compliance program puts in place.

Encryption Consulting operates under ISO/IEC 27001:2022 and SOC 2 controls and works with GDPR-aligned data protection practices, the same categories of control a court effectively required TikTok to adopt after the fact. Building them in advance is materially cheaper than building them under a settlement deadline.

Update Log

DateChange
February 25, 2021TikTok and plaintiffs reach the $92 million settlement agreement in MDL No. 2948, N.D. Illinois.
2021 to early 2022Court grants preliminary approval; claims notice program launches for the class of roughly 89 million users.
July 28, 2022Judge John Z. Lee grants final approval and enters final judgment.
December 2022Original version of this article published.
August 21, 2026TikTok and ByteDance reach a separate $400 million settlement with the DOJ over COPPA claims, a distinct case noted here to prevent confusion with the BIPA settlement this article covers.
August 2026Article reviewed and refreshed by Encryption Consulting’s Compliance Advisory team: added the primary-source timeline, framework comparison table, detection and remediation guidance, FAQ, and this update log; verified all dates and figures against court filings and legal reporting.

Conclusion

TikTok’s $92 million settlement did not turn on a hack or a breach. It turned on the gap between what the app disclosed and what it actually collected, particularly around biometric data, unpublished drafts, and third-party sharing. That gap is exactly what BIPA, and increasingly other privacy frameworks, are written to catch. Enterprises that build recommendation systems, biometric authentication, or any feature touching sensitive personal data should treat this case as a checklist, not a headline: inventory the data, document the consent, control the transfers, and audit it on a schedule instead of waiting for a plaintiff’s attorney to do it first.

Frequently Asked Questions

What was the TikTok $92 million settlement actually about? It resolved 21 consolidated federal lawsuits (MDL No. 2948) alleging TikTok collected biometric data, mined unposted draft videos, and shared personal data with third parties like Google and Facebook without adequate consent. The court granted final approval on July 28, 2022.

Is this the same case as TikTok’s COPPA settlement with the DOJ? No. The $92 million settlement covered BIPA, VPPA, and CFAA claims from 2021 to 2022. TikTok and ByteDance reached a separate $400 million settlement with the U.S. Department of Justice in August 2026 over Children’s Online Privacy Protection Act (COPPA) violations, a distinct case with its own facts, court, and outcome.

What is BIPA and why did it apply to TikTok? The Illinois Biometric Information Privacy Act (BIPA) requires written consent before a company collects biometric identifiers, such as face geometry, from Illinois residents, and it allows individuals to sue directly for violations. Plaintiffs alleged TikTok used facial analysis to power content recommendations without that consent.

Did TikTok admit any wrongdoing in the settlement? No. TikTok denied all allegations in the underlying complaints. Settling without admitting liability is standard in class-action privacy litigation and reflects a cost and risk decision, not a factual finding against the company.

What should enterprises actually change after reading about this case? Inventory where biometric and behavioral data is collected, confirm written consent and retention schedules exist for it, review third-party data-sharing agreements, and control cross-border data transfers. The remediation checklist above walks through each step in order.

References

  • NPR, “TikTok To Pay $92 Million To Settle Class-Action Suit Over ‘Theft’ Of Personal Data” (February 25, 2021): npr.org
  • The National Law Review, “Tiktok’s $92 Million Settlement Receives Final Approval”: natlawreview.com
  • Privacy World, “TikTok Settlement Receives Final Court Approval” (August 2022): privacyworld.blog
  • MediaPost, “TikTok $92 Million Privacy Settlement Granted Approval” (July 28, 2022): mediapost.com
  • U.S. Department of Justice, “Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children’s Privacy Litigation” (August 21, 2026): justice.gov
  • Federal Trade Commission, “FTC Investigation Leads to Lawsuit Against TikTok and ByteDance for Flagrantly Violating Children’s Privacy Law” (August 2024): ftc.gov