TikTok has withdrawn its appeal against a £12.7 million ICO penalty, making the 2023 penalty notice final. A separate appeal about an information notice has also been withdrawn, allowing the ICO’s investigation into the processing of 13–17-year-olds’ data in recommender systems to continue. For organisations offering online services that children may use, the practical lesson is clear: protections must work in the service itself and be supported by evidence.
What the ICO’s latest update confirms
The ICO issued the original monetary penalty notice on 15 May 2023 against TikTok Information Technologies UK Limited and TikTok Inc. The penalty was £12.7 million. In its 24 September 2026 update, the ICO says TikTok has withdrawn its appeal against that penalty. The notice is therefore final and the fine is accepted.
The ICO says the underlying failures included inadequate checks to identify and remove children under 13, unclear information about how children’s data was collected, used and shared, and failure to obtain parental consent where it was required. The regulator estimated that up to 1.75 million UK children under 13 used TikTok in 2020, although TikTok’s own rules did not allow children that age to create an account. The underlying enforcement record links to the monetary penalty notice and its annexes.
This is a final enforcement outcome, not a finding that every online service must use one particular age-checking technology. The relevant question for a service team is whether its controls are appropriate to the risks, proportionate to the service, and demonstrably effective in practice.
Why the recommender-systems investigation matters
TikTok has also withdrawn its appeal against an information notice seeking documents and details about how it processes the personal information of 13–17-year-olds in recommender systems. The ICO says the appeal had prevented the investigation from progressing; it can now continue. That is not a concluded finding against TikTok, so organisations should not treat the investigation as proof that a particular recommender design is unlawful.
It is, however, a useful governance signal. Recommender systems can profile users and shape what they see based on their activity. If a service is likely to be accessed by children, teams need to understand what personal data feeds recommendations, which decisions are automated, how profiles are created, how long signals are retained, and how a child or parent can challenge or reset the experience.
Four controls online-service teams should test
1. Age assurance is a control, not a form field
Start by mapping where age is declared, inferred, checked and re-checked. Test whether an under-13 user can create an account, continue browsing, trigger profiling, receive personalised recommendations or access age-sensitive features after providing a false date of birth. Record the assumptions behind the chosen approach and the points at which it fails closed or escalates for review.
Do not measure success only by the number of users stopped at registration. Monitor false negatives, repeat attempts, accessibility impacts, customer-support escalations and the data created by the assurance process itself. The assurance method should not create a new, poorly governed identity dataset.
2. Make the explanation usable for children
Privacy information must support an informed decision, not merely satisfy a documentation task. Test explanations with the audiences who will use the service: what data is collected, why it is needed, who receives it, how recommendations work at a high level, and what choices are available. Use layered, age-appropriate notices and make the important message visible at the moment a decision is made.
3. Make parental-consent controls operational
Where the service relies on consent and the law requires parental authorisation for a child, document the trigger, the verification step, the evidence retained and the process for withdrawal. Check what happens when consent is refused or withdrawn: processing should stop or change as designed, rather than leaving old permissions active in downstream systems.
4. Govern recommendations with evidence
Maintain an inventory of recommender inputs, profiling purposes, sensitive or high-risk signals, model changes, testing results and escalation owners. Include child-safety scenarios in pre-release testing and monitor outcomes after deployment. A governance file should allow a reviewer to see what the team believed would happen, what actually happened, and what changed when the evidence disagreed.
What managers should ask this quarter
- Can we show where children may enter the service and what protections apply at each step?
- What evidence shows that our age-assurance controls work against realistic misuse?
- Can a child understand our key data uses without reading a long legal notice?
- Where parental consent is relevant, can we prove how it was obtained, withdrawn and propagated?
- What personal data and model behaviour are covered by our recommender-system testing?
- Would our DPIA and change records let us explain the service to the ICO quickly and accurately?
Teams can also compare their controls against the existing Reddit children’s privacy case and our age assurance explainer. Those links provide broader context; neither changes the specific facts of the TikTok enforcement action.
FAQs
Is the ICO’s £12.7 million TikTok fine final?
Yes. The ICO says TikTok withdrew its appeal against the 2023 penalty notice, making the notice final.
Has the ICO found TikTok’s recommender systems unlawful?
Not in the 24 September 2026 update. The ICO says a separate investigation can now continue after TikTok withdrew its appeal against an information notice.
Does this case require every service to use the same age-checking method?
No. Teams should choose proportionate controls for their service and risk profile, then test and document whether those controls work in practice.
