Deleting the Account May Not Mean Deleting the Data

22 August 20267

Executive Summary

TikTok and ByteDance have agreed to pay $400 million to settle US government litigation concerning alleged violations of children’s privacy law.

The US Department of Justice announced the settlement yesterday, describing it as one of the largest recoveries ever obtained under the Children’s Online Privacy Protection Act.

TikTok will pay $300 million immediately, with a further $100 million payable following the required court order concerning an earlier consent decree. 

The underlying allegations included collecting personal information relating to children under 13 without the required parental consent and failing, in certain circumstances, to honour parental requests to delete children’s accounts and associated information. TikTok settled the case without the allegations proceeding to a final trial determination. 

There is a broader corporate lesson:

Having a privacy policy is not the same as being able to find, control and delete the data the policy covers.

UK Impact

The specific US COPPA legislation does not govern UK companies operating solely in Britain.

But the underlying data-governance problem absolutely does.

UK organisations processing personal information operate under UK GDPR and the Data Protection Act, with additional considerations where services are likely to be accessed by children.

Businesses increasingly hold customer information across:

  • CRM systems.
  • Marketing platforms.
  • Mobile apps.
  • Cloud storage.
  • Analytics tools.
  • Backups.
  • Third-party processors.
  • Archived databases.

A customer may appear deleted from the visible account system while copies remain elsewhere.

That creates a critical distinction between:

deleting the customer interface

and

deleting the customer’s data.

Global Impact

AP reports that the US litigation alleged TikTok did not always delete accounts even when it knew they belonged to children under 13 and failed in some instances to honour parental deletion requests. 

The settlement comes amid intensifying regulatory and legal scrutiny of children’s online safety and privacy internationally.

For businesses, this illustrates a much wider technical challenge.

Data can spread through an organisation into:

  • Backups.
  • Analytics.
  • Marketing systems.
  • Data warehouses.
  • Third-party applications.
  • Test environments.

The longer the data lifecycle, the harder complete deletion becomes.

Our View

Companies should periodically test whether their data-deletion procedures actually delete data rather than simply closing an account.

Businesses should ask:

  • Where is customer information physically stored?
  • Which third parties receive it?
  • Are backups included in deletion procedures?
  • Does deleting an account automatically remove marketing records?
  • Can data be found using one customer identifier?
  • How are children’s accounts identified?
  • What happens when a parent or customer requests deletion?
  • How quickly can the request be completed?
  • Can the business prove deletion occurred?
  • Do third-party processors confirm deletion?
  • Is data being retained simply because nobody has decided when to delete it?

Many privacy failures begin not because a company intends to misuse information, but because nobody knows everywhere the information has gone.

The safest data to protect from a future breach, regulatory investigation or misuse is sometimes the data the business no longer has any reason to retain.

Risk Indicator: ELEVATED

Does This Risk Affect Your Business?

Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.

From individual businesses to major international organisations, risk is our business.

TALK TO INVICTUS →

Scroll to Top