Summary
- TikTok has withdrawn its appeal against the ICO’s £12.7m 2023 privacy penalty.
- A second withdrawn appeal allows the ICO to continue investigating the use of data from 13 to 17-year-olds in recommender systems.
- The proceedings place age assurance, profiling, and platform design under continuing UK data-protection scrutiny.
TikTok has withdrawn two UK privacy appeals, making a £12.7 million penalty over children’s data final and allowing the Information Commissioner’s Office to continue a separate investigation into how the platform’s recommender systems use teenagers’ personal information.
The first appeal challenged a fine imposed in 2023 after the ICO concluded that TikTok had breached data-protection law in its handling of children’s information. The regulator estimated that up to 1.75 million UK children under 13 used the service during 2020 despite TikTok’s own minimum age being 13.
The ICO found that the company had not carried out adequate checks to identify and remove underage users, had failed to provide sufficiently clear information about data use, and had failed to obtain parental consent where it should have known younger children were using the platform.
TikTok’s withdrawal makes the penalty notice final and the company has agreed to pay the £12.7 million fine.
The recommender investigation can resume
The second appeal concerned an information notice rather than the monetary penalty. The ICO had required TikTok to provide documents and details concerning how it processes the personal information of users aged between 13 and 17 in its recommender systems.
The challenge prevented the investigation from progressing. With that appeal withdrawn, the regulator can resume examining how younger users are profiled and how their information influences the content they are shown.
Recommender systems sit at the centre of the economics of large social platforms because they determine which material is most likely to hold an individual user’s attention. They can draw on activity, interactions, viewing behaviour, inferred interests, and other signals to personalise what appears next.
The regulatory issue becomes more sensitive where the user is a child. The ICO says its research indicates that repeated personalised content can make it harder for some children to stop scrolling.
Age assurance and privacy increasingly overlap
The finalised penalty also illustrates why age assurance cannot be separated neatly from data protection. A platform cannot apply different safeguards reliably if it has limited confidence about whether a user is a child.
More intrusive age checks can create privacy risks of their own, however, particularly where services collect identity documents or biometric information simply to establish that somebody is above an age threshold.
Platforms therefore have to balance reliability, proportionality, and data minimisation while regulators become less willing to accept a minimum-age statement as sufficient where significant numbers of younger children still gain access.
Regulation moves into product architecture
The two proceedings show privacy enforcement reaching further into product design. The settled case dealt with access and handling of children’s information, while the continuing investigation concerns the systems deciding what teenage users see.
That second question is technically harder because a recommender system is not one database or policy. It is a collection of models, behavioural signals, ranking rules, experiments, and safeguards that can change continuously.
Information notices therefore become important regulatory tools because an authority needs sufficient technical and documentary access before it can determine whether a system complies with the law.
The resumed investigation has not produced a finding that TikTok’s recommender systems breach data-protection law, and it should not be reported as though it has. The £12.7 million children’s-data case, by contrast, is now settled.
The distinction illustrates where platform regulation is heading. Compliance is increasingly judged not only by what a company says in a privacy notice, but by who the product admits, which information its systems collect, and how that data shapes the experience delivered back to the user.












