TikTok fined €345M for breaking EU data law on children’s accounts
theguardian.com
theguardian.com
How exactly are TikTok meant to be verify parents? Are other tech companies expected to verify parents? It seems like no one else is being fined for this?
https://techcrunch.com/2022/09/05/instagram-gdpr-fine-childr...
2. How do the regulators expect tech companies to verify the parents of child users?
3. Do regulators want tech companies to collect every child's birth certificate?
Or like, basically anything except pretending it’s not an issue and externalising the cost + issues onto everyone else while you reap fantastic profits?
In fact, it’s probably more likely these platforms don’t want anyone to know how much they already do know about familial relationships.
2. How do the regulators expect Airline companies to verify the parents of child users?
3. Do regulators want airlines to collect every child's birth certificate?
See how silly this sounds when you compare to any other industry?
Oh but tech is different!
And FWIW, it's third-generation mobile-first social media platforms we're talking about. It's hard to make a case they're not a huge net negative for society. In any other thread, people would happily agree they shouldn't exist in the current form in the first place.
Maybe this causes fragmentation of large platforms, that'd also be a net good imo.
Society certainly didn't anticipate a lot of the drawbacks of anonymous presence.
The town square metaphor is really not a great one for the internet. You don't run nearly as high a risk of getting doxxed or swatted for speaking your mind in a physical public place.
And if the unspoken suggestion is that anonymous doxxing would be impossible or too costly/risky in a hypothetical de-anonymized world, I'd call BS. Even if it worked, that would require some kind of "panopticon internet". Sounds bad...
You either need the right to be forgotten, or the right to be anonymous.
Historically, it wasn't current-moment anonymization that was good, but ephemerality.
Sadly, I think the right/ability-to-record is a genie that can't be put back in the bottle (no one can scrape anything?), so we may need to switch from identifiable-but-emphemral (historical state) to anonymous-but-recordable (future state) to preserve the same freedoms.
IMHO, we'd be better off working to curb the worst consequences of broad anonymity (e.g. astroturfing / artificial amplification).
I think Internet anonymity has some benefits though: it's certainly helpful for whistleblowers revealing crimes committed by a company, government or other organization. While you could in theory still drop folders containing documents or a USB drive to different news organizations, with how widespread CCTVs are, so I think that path may become more difficult. In countries with oppressive regimes, that's even less of an option.
I'm also not sure that the lack of anonymity is a sure-fire way to improve public discourse: just look at Facebook comments (which are rarely anonymous.)
As you mention, perhaps anonymity could be allowed on the Internet, but not on the big 5 platforms — that could be a balancing act between chaos and oppression.
Though, while a policy like that might be a net good for someplace like the EU, the precedent of requiring government IDs for Facebook etc. could set a dangerous precedent for places that are less free. Not every country is a full-on liberal democracy OR an authoritarian state where Facebook etc. is outright banned — there are places in-between, where the government oppresses people but still has elections and some degree of dissent is permitted. It's in those places that I see government IDs being required to post on major platforms being a major issue. Being able to share instances of government oppression on major platforms is crucial for those places, but if the identity of those sharing it is revealed, then fewer people may speak up and share such instances.
It's a complex issue to say the least.
[1] https://i.kym-cdn.com/photos/images/original/000/325/699/4fc...
Wouldn't whatever "signal amplification" downsides happen just as much with decentralized services
This isn’t a case of “oops we didn’t know the age”, this is about accounts that had an underage DOB set.
So this is quite the timely ruling.
However why would people between 13 and 18 be prohibited from streaming? If you say "the lurking perverts", that argument doesn't work for chat control, so why should it work here? It's a moot point. Sexual content is not allowed on Tiktok. You can see women in bikinis, but you can see them, even topless, in real life on public beaches too. So what other reason would there be?
The parasocial relationship with an audience, especially a large one, does weird things even to adults.
In the other case you have anonymous strangers rewarding children for edging closer to sexual performances
Also EU companies tend to be more mindful and take data protection very seriously, even before GDPR was a thing, so finding gross offenders is a rare occurrence anyway.
Edit: for anyone wondering SAP has ~110,000 employees worldwide, Google has ~180,000, so comparably mega scale tech company.
I am not sure that is completely correct, considering SAP's cloud offerings.
SAP runs your instance, but isn't responsible for what you do with it.
I'm absolutely in favor of making it impossible for adtech to make any profit at all as long as they build their business on monetizing user data and exposing their users to all kinds of hazards.
I find it funny that so few people here see a problem with that kind of behavior. It's as if they expect society to serve the market, instead of the other way around.
Ironically, currently 2023 entries.
At least in my experience, when I deal with a service in the EU, their privacy policy fits on a few A4s, with the important bits frontloaded and written in an easily understandable way. Even most banks don't really hide what they collect on you and they explain why they collect it.
It's only foreign companies that tend to insist on massive privacy policies that border on being incomprehensible and use them to skirt the law. Seriously, just look at Googles privacy page for example - it's a single giant page that mostly just restates over and over "Google may collect info about you". It's unclear what the data is being used for, it's extremely reliant on other pages to detail what's being used and your average person has probably lost the plot by now.
It's difficult to put it in any other way, but foreign companies are the ones who think they can get away with breaking the law and make it as difficult as possible to trace what they're doing with your data. European companies just tend to actually follow the law. That's why all the landmark cases are against foreign tech giants.
It's probably different for organisations coming from outside the EU who get EU customers over the Internet.
A lot of people were wrongly influenced by DPD consulting wannabes on their first gig. I have seen small org burn years of contacts they could have kept or easily manage in respect with the provisions of the law.
These are the moments I’m grateful to be living in the EU. GDPR was a huge circus of blame on EU bureaucracy back when it was introduced. A lot of hate poured out that every single paper you sign now needs to have a second separate GDPR thing for you to sign. Stupid Brussels making your life more complicated! But now everyone seems to be used to it.
But also, primarily European companies did generally take it a lot more seriously than multinationals. (Sometimes too seriously; while this has calmed down a bit, you'll sometimes see companies enforcing absolutely absurd policies around data on the basis that they incorrectly think they're required for compliance).
For example, it was US companies that stopped serving ads until they had GDPR infrastructure in place, while some very bad actors in the UK where not collecting consent at all.
On the other side, European companies are usually smaller, so their get lower fines, which won't make the headlines. Which is, why you might not hear so often about the fines against European companies, which still happen. And if we are honest, we usually only hear about the super-penalties anyway.
The Irish DPC is also reportedly quite busy, by virtue of shouldering a disproportionate amount of the enforcement work for non-EU companies (due to tax-driven HQing there). They have taken cases against European entities as well however: notably they even even taken cases against the Irish government for violations around mandating biometric public service ID cards.
Such a thing would need to exist before the EU would be able to fine it.
I'm explicitly saying Twitter not X Corp because Musk in his infamous wisdom fired everyone at Twitter Ireland who was involved in ensuring they remained compliant. I think part of the requirement was also that every feature launch is run past the Ireland team to make sure it doesn't violeate EU data laws. Musk has not done that for any of the changes he introduced since the leveraged buyout.
Do you think 345M grow on trees?
An alternative to that, used e.g. in my country - Poland - is to create a "secondary currency" of penalty points. Rich or poor, you only have 24 of them, and if you lose them all, kiss your driving license goodbye.
One would think that penalty points could work here too, instead of scaling revenue, but the problem is, companies can rapidly split, merge, or otherwise shed their legal identity, so there's nothing to pin those penalty points to.
Increase the fines into the billions of dollars if they repeatedly continue to violate the privacy of their users. This has happened with Facebook before.
There is no defense in large compaines getting away with this and all social media companies with over hundreds of millions of users that violate their users privacy should be fined, as found with TikTok. No more exceptions or excuses.
So that concludes that TikTok is no different to Meta when they screw over their own users privacy.
It also seems likely that number will be litigated down to something much smaller by the time the legal dust settles.
If you don't know the answer, don't just make up fictions and present it as fact.
>“While the GDPR determines which infringements can lead to the imposition of a fine and which DPA [data protection administration] in the EU/EEA has the power to impose a fine for infringements, the GDPR does not determine what happens to administrative fines [my emphasis]. This is determined by national law and differs between member states. For all aspects of enforcement not governed by the GDPR, national law applies.”
https://cybernews.com/editorial/who-keeps-gdpr-fine-money/#:....
As for where specifically in Ireland, it seems to just go to the general government budget.
Where do all those fines go?
Will they be blocked from the EU? Is there some international way that they can get a US or Chinese company to pay up?
The clearest sign for me was Meta's decision to delay the launch of Threads in the EU. Even for a company with the financial might of Meta, two billion euros in fines in the past two years has put the brakes on the "move fast and break stuff" mentality. Of course that creates the possibility of a two-tier internet where EU customers simply don't get access to products that are inherently intrusive, but I think that's a feature rather than a bug - either respect the privacy of our citizens, or take your seedy surveillance business elsewhere.
this has already happened. google’s bard took it’s time to launch in europe.
the young kid in me that always thought we finally have a piece of tech that is beyond what politicians can control, that transcend borders and nationalities is saddened. but it is what it is, and without some breakthroughs (a system that cannot be controlled, censored etc by design) i don’t think there’s going back.
You can't change the world just with technology, as society is a "social construct". And if people want regulation, that's what they are going to get.
Speaking of EU's data protection regulations, it's funny because many people here claim that it doesn't work, and then are shocked to see that it does.
For what is worth, I think EU's data protections are a good thing. Big Tech acted irresponsibly for too long.
agree, it is naive. but for a while it did feel liberating to a lot of people.
> without some breakthroughs (a system that cannot be controlled, censored etc by design)
This isn't really a technical issue; some small criminal entity could run an AI bot on Tor (or even, realistically, on the open internet) which forwarded all your personal data directly to the North Korean government and the Mafia or whatever, and realistically they'd get away with that. But if there's a large company behind the service, then that company is going to have to _obey the law_, and no amount of technology will change that.
i agree on the first part. but that second part could probably also be reinvented by new tech, futuristically speaking.
sounds like the Safe Network! too bad it will never be finished in our lifetimes
It's been 7 years that every company operating in the EU knows about these rules, 3 years ago it was already 4 years into effect. There's no excuse, they broke the law, pay the fine.
/s
You don't work for TikTok by amy chance?
I assume you also support the death penalty for J walking?
If McD is knowlingly selling carcinogenic burgers world wide and reguses to stop, sure, bankcrupt McD.
The course changes occasionally, but companies adapt quickly and learn to handle the course changes efficiently on the next run, skimming by the poles on the way to the finish line.
Every once in a while a new pole smacks them in the face, but by the next fiscal year, they’ve learned to navigate past it as if it weren’t there.
Lawyer are usually damn fine slalom racers, but occasionally you do need to donate money to the course to encourage the owner to move the poles.
This fine looks to be an estimated 1/8 of TikTok's profit in 2022.
Any further infringement and the App is banned from the EU.
"Harms children". To make the analogy fair, imagine you're keeping a diary, and recording the observable information of every child that walks past your house. $2k seems like a reasonable fine.
But 25% revenue might work.
3 strikes, and the company is dissolved. In fact, this should definitely happen for US credit rating companies which keep on leaking data.
1st strike blocks you from working as CxO for 5 years, 2nd strike for 10 years, 3rd strike is forever.
Right now too many bad CxO jump from one ship to the next again and again.
If you let the company get away with crimes over and over and only punish a CxO the company will simply hire a guy to take the fall for them. There's an endless number of people working minimum wage who would happily take a CxO title and salary for years knowing full well that there's a chance they might get fired eventually.
#2: It is not the company to decide who to take the fall. It is the court/judge.
I'd be down with this, but we need to decide which kinds of violations are speeding tickets and which are serious felonies.
Should it be the current C-suite that’s fired or the ones in charge when the violation occurred? Or maybe the ones in charge when the original policy at TikTok was created? Or what if the current C-suite was in charge, briefly, for the violating period but they’re also they ones that changed things to be in compliance before the investigation began, should they still be fired?
The diffuse responsibility makes this stuff tricky to implement.
How about 100% of TikTok's profit in 2022, and go from there.
Why go that route instead of claiming its assets in the jurisdiction and revoking its right to operate?
EU is like, what, a fifth of that at most?
It’s not a good idea to play chicken with a continent.
The EUs fight against encryption is a good example
https://www.wired.com/story/europe-break-encryption-leaked-d...
Imagine if a US state were in serious debt, and the US federal response were to slash Social Security, Medicaid and Medicare benefits to the state. The EU view was that Greece should get out of debt by massively slashing government spending, including on virtually all social services, which sent the country spiralling into a Great-Depression-level economic collapse. That made repaying the debt even more difficult, which necessitated even deeper cuts, which made the economy collapse even further, and so on for years. Greece endured years of 20+% unemployment, and GDP/capita has fallen to the level it was 20 years ago.
Years of government mismanagement and fraudulent reports had put Greece in a state where nobody reputable would lend them money, in extreme debt, and without an economy to recover by itself any time soon.
Greece could've decided not to take up the bailouts, of course. All austerity packages were passed by the democratically elected Greek parliament.
The EU would've liked Greece to magically go out of debt, but it's not like they were just going to hand the Greek government hundreds of billions of gifts and a pat on the back with a quick "try not to go bankrupt again, OK?". If you lend someone money, you want some kind of guarantee that you're going to get it back. The EU wasn't being evil, it was watching its own back while the worldwide economy took a hit. They weren't alone either; the IMF also demanded reforms to ensure their loans got paid back down the line.
At every step along the way, the Greek government was involved, including causing the instability in the first place. There are plenty of evil things the EU and its many bodies do, but this wasn't a good example.
When the elected Greek government put the Nth austerity package to a popular referendum, the EU began cutting Greece off from the international banking system (one effect was that people were unable to withdraw more than a tiny amount from ATMs), in order to put pressure on the population to vote "yes." The population voted "no" anyways, because Greeks were massively against austerity by that point. The EU then put enormous pressure on the Greek government to ignore the result of the referendum, threatening to intentionally destroy the Greek economy. The Greek government caved and agreed to the new austerity package. This was extremely undemocratic: a popular referendum was simply ignored, and the government - which had been elected specifically to reject austerity - basically had a gun to its head.
> The EU would've liked Greece to magically go out of debt, but it's not like they were just going to hand the Greek government hundreds of billions of gifts and a pat on the back with a quick "try not to go bankrupt again, OK?".
If this were an American state, the citizens of the state would have received massive Federal transfers, in the form on Social Security, Medicare, Medicaid and unemployment payments. Instead, the equivalent of all of those things were massively slashed in Greece. This is the equivalent of throwing debtors in prison. In punishing them, you destroy their ability to pay back their creditors. It's an insane thing to do, even from the point of view of the creditors.
What the newly elected Greek government (not the old, corrupt government) was proposing was for the creditors to take a hit, and for stricter tax enforcement (particularly on the wealthy). It wasn't just saying, "Give us money and we'll do nothing." It was saying, "Don't force us into an artificial economic depression, and give us breathing space to reform the corrupt system we inherited."
The Greek government specifically asked the EU not to keep lending Greece money for the purpose of paying back creditors. The Greek government correctly pointed out that the inherited debt was unsustainable, and that you don't lend a bankrupt person money: you force the creditors to take a hit and create a realistic payment plan.
> There are plenty of evil things the EU and its many bodies do, but this wasn't a good example.
Imposing a completely unnecessary Great-Depression-level event on a member state - while running roughshod over that country's democratic system - was pretty evil. Greece went through years of massive unemployment, people's pensions and healthcare were slashed, and young people left the country in droves as practical economic refugees. The reason why the EU took this hard line was that some of the member states (like Germany and the Netherlands) wanted to send a message to the other financially weak states (like Portugal, Spain and Italy). In Germany, there was also a lot of populist politics involved: bashing "lazy Greeks" was good politics, and plenty of politicians made a lot of hay over being tough on the Greeks.
EU "fiscal discipline" combined with bank bailouts looks so harmful in retrospect.
> Imagine if a US state were in serious debt
Except the EU is not responsible for and does not control their member states' finances. The EU has a limited jurisdiction. E.g. taxation, education and defence are not part of it. Being part of the Euro zone does bring certain obligations.
"They" is ill defined here. The people who falsified the finances were not the people who suffered under austerity.
> Except the EU is not responsible for and does not control their member states' finances.
During austerity, the "troika" (which included the European Commission and the European Central Bank) micromanaged Greece's finances. The Greek government was basically held hostage and forced to take very specific measures, down to which tax to change by which amount and which state assets to privatize in which way. The EU publicly aspires to be much more than just some soulless customs and currency union, and throwing a member state under the bus in this way and immiserating its population goes against what the EU supposedly stands for.
That just confounds the issue. The people who profit from pensions, infrastructure, healthcare, etc. are also not the people who set it up.
Every good EU idea seems to come with a terrible idea. On average things seem to get better, but it's a two-steps-forward-one-step-back kind of progress. It's better than an all-bad government, but they do plenty of shitty things. I'm very happy to live in the EU, but it's certainly not for everyone.
The EU is rich and safe and will commit whatever atrocities to maintain it.
There's no easy solution to the mass immigration problem, but this "solution" makes things worse for everyone.
We're massively cutting back on our business with Russia over their atrocities in Ukraine, but when it comes to human rights in Tunisia, we're willing to let this stuff slide. Sure, there's no war, but handing a country money to enforce their deadly anti-refugee violence is very bad.
But in that view, the fine is whatever size it is and if it isn’t enough, too bad.
…that isn’t how Europe works.
So either they've woken up to the same reality the rest of us inhabit, or their inhibition to do their job doesn't apply to Chinese companies...
if TikTok simply had an age selection box, and if you choose anything under 18 it said "too bad. wait until you're 18", I'm sure all of those children would say, "gee darn it, guess I'll wait" :eyeroll.
This sort of nonsense is why government's are trying to enforce age verification because god forbid your children go on a website or app.
at the end of the day these fines exist because it's easy money for the EU - there's really no way of stopping children from using TikTok, or any social media for that matter but the EU knows that so they fine the companies and keep the gravy train going.
Actually, the fines exist to make sure laws are respected. Also, the issue wasn't about users lying about their age, it was about underage users signing up for an account and having access to all content, instead of only child-safe content, as other platforms do.
The correct thing for the EU to do if they actually cared about this is to enforce true validation of ages on social media. This is exactly what's being proposed in the United States, with a 3rd party verification service being required for all social media to actually verify ages.
The law in its current form, both in the EU or United States, is pointless and trivially circumvented. Charging a third of a billion for something like this is so laughable.
Sure, this can be done already with KYC on the platform. YouTube and Meta already has this.
Even with those mechanisms, Meta still delayed their release for Threads in the EU after getting fined repeatedly and Google still got fined for privacy violations around user location again.
So fineing companies works well. They just need to increase it into the billions of dollars for repeat offenders for them to cave and think again.
This is not the case. You can easily create an account on both in the EU as an adult even if you're a child.
You seem to think fining is great, but consider the EU pretty much miss the boat on the internet economy. Consider even the richest country in the EU barely even compares to only California, let alone the entire country of USA. Bolstering their economy and innovation is better than strangling everything with regulation, but to each their own.
My only hope is that those laws won't prevent a new major high tech company to appear in the EU.
If Threads gains traction in the other parts, of course they will launch it EU wide.
The EU is often a too big market to be ignored, see Apple and USB C for example. They caved and released the iPhone 15 with that connector now for the whole world. Companies wanting to do business will need to adapt.
I dont think Tiktok will close up shop here to be honest.
I wouldn't phrase it as "losing out" though. I would put it as "not being in the crosshairs of endless streams of manipulative content whose only purpose it to induce a demand for low-quality consumerism products whose entire existence is a burden for our planet."
Those with FOMO can still use VPNs and pretend to be US citizens.
losing out on companies that are detrimental to our social fabric, democracy, and psychological health of children is a good thing. Mistaking company values on a stock market for population health is the human equivalent of acting like a paperclip AI
This is a naive take. I wish we Americans had "lost out" on Facebook, because the world would be a better place if we had.
To most of them, everytime someone is trying to yank their chain by talking about “losing out” or lack of big tech companies, it’s the equivalent of someone suffering from the bubonic plague bragging about their fashionable buboes.
$367M USD (If that's the final cost to Tik Tok) vs their $11B revenue for 2022 - is a noticeable hit for the company.