A Different Kind of Issue This Week
If you've been reading Identity Decoded for a while, you know this isn't usually where I go. I write about zero trust, identity architecture, breach post-mortems — the stuff I deal with professionally. This week I'm making an exception, because a story crossed my desk that sits right at the intersection of my job and my home life, and I couldn't let it pass without saying something.
I have two kids — 10 and 9. Neither of them has TikTok. Neither of them plays Roblox. That's not a small thing in our house; it's a decision I've had to defend more than once, including to my own kids, who point out that "literally everyone" in their class is on it.
Two stories converged for me recently and confirmed I'd made the right call.
The first is the one that anchors this issue: TikTok just paid a $400 million fine — the largest child-privacy penalty in U.S. history — for collecting data from kids under 13 without consent, despite officially banning them. The company knew younger kids were on the platform. It kept collecting anyway.
The second is Roblox. Right now, well over a hundred lawsuits — consolidated into a federal multidistrict litigation in California — allege the platform's design made it easy for predators to reach children through chat and in-game messaging, often migrating conversations to apps with even less oversight, like Discord. Several state attorneys general have opened their own investigations. Roblox has since rolled out mandatory age verification for chat access, but for the families now suing, that came after the fact, not before.
And then, two days ago, Meta settled too — agreeing to pay up to $17.1 billion to 47 states over claims that Instagram and Facebook were built to be addictive to kids and that Meta was collecting data from minors without consent. Three of the biggest platforms my kids' friends are on, three separate reckonings, all in the same stretch of weeks.
I read professionally about companies failing to secure the things they're trusted with. But when the thing being mishandled is a kid's data, or a kid's safety, it stops being an abstract security failure and starts being personal — because it's my kids' generation this is happening to, and it could just as easily be one of them on the other end of that chat window.
So this week, I'm setting aside the usual format to talk about what I actually do about it as a parent — not as a theoretical best practice, but as the rules that exist in my house right now.
When the Fine Is Bigger Than the Warning
TikTok just paid $400 million to settle a federal lawsuit over child privacy violations. That's the largest child privacy penalty in U.S. history — four times bigger than the previous record. But here's what matters more than the number: the Department of Justice didn't just collect the check and walk away. The settlement comes with a list of things TikTok must actually change about how it collects, stores, and uses data from kids under 13. And every app company with a legal team is reading that list right now — because they know they're next.
Your kid's school app, their gaming platform, that "educational" video service, the chat app they swear all their friends use — every single one of them is watching what TikTok just agreed to do. Because the precedent is set. The government just showed it's willing to enforce child privacy laws with penalties big enough to matter.
This isn't about TikTok. It's about what happens next.
What TikTok Actually Did Wrong (And What Every App Does)
The lawsuit accused TikTok of collecting personal information from millions of children under 13 without parental consent. That violates COPPA — the Children's Online Privacy Protection Act — a law from 1998 that requires apps to get verified parental permission before collecting data from kids.
Here's the thing: TikTok's official terms say you have to be 13 or older to use the app. But the DOJ's case showed that TikTok knew younger kids were using the platform anyway — and kept collecting their data. Location. Device identifiers. Viewing habits. Biometric data from face filters. All the invisible signals that apps use to build profiles, serve ads, and feed recommendation algorithms.
The word "collected" makes it sound voluntary. It's not. The moment a child opens the app, data flows automatically. There's no opt-in screen. No parental verification gate. No way to use the app without giving up information.
And this pattern isn't unique to TikTok. Walk into any middle school and count how many apps kids use that technically require users to be 13+. Then ask yourself: how many of those apps actually enforce that rule? How many verify age in a way that a 10-year-old couldn't bypass in six seconds by entering a fake birthday?
The answer is almost none. Because until now, the cost of ignoring the rule was lower than the cost of losing young users.
Why This Settlement Lands Differently Than Past Fines
Tech companies get fined all the time. They pay, issue a statement about taking privacy seriously, and keep operating exactly as before. So why does this one matter?
Three reasons.
First, $400 million is large enough that it affects investor expectations. TikTok's parent company ByteDance is valued in the hundreds of billions, so the fine won't bankrupt them — but it's big enough that every board of directors at every app company is now asking their legal team: "Could we be next? And how much would it cost us?"
Second, the settlement includes operational requirements, not just a payment. TikTok has to delete data it collected from kids improperly. It has to build new systems to detect underage users. It has to restrict data collection even for users who claim to be old enough if the app suspects they're lying. Those changes cost money and engineering time — and they limit how the app can operate. That's enforcement with teeth.
Third, this case represents a shift in how the DOJ approaches platform accountability. For years, child privacy enforcement came from the FTC and resulted in relatively small fines. The DOJ bringing the case signals a new level of seriousness — and a willingness to use stronger legal tools.
Every other app with a young user base just watched the government prove it can win these cases and impose penalties that actually hurt.
Then Meta Settled for $17 Billion. Two Days Later.
If TikTok's fine felt like a signal, Meta's settlement — announced August 26 — feels like confirmation that the dam is breaking.
Meta agreed to pay up to $17.1 billion to 47 states, D.C., and several U.S. territories, ending a federal trial that alleged the company designed Instagram and Facebook to be addictive to kids and knew about the mental health toll, while also improperly collecting data from children under 13. That's roughly 40 times the size of TikTok's fine — and it's not the only number in play. Texas negotiated its own separate $1 billion settlement, and New Mexico had already won a $375 million jury verdict against Meta earlier this year.
As part of the deal, Meta committed to real product changes for teen users: daily time limits, nighttime restrictions, and — notably — stronger age-verification measures and expanded parental controls. That last part matters more than the dollar figure. A company with some of the most sophisticated engineering in the world is now under a legal obligation to actually verify who's using its platform, not just ask.
Here's the detail that tells you everything about how this industry actually thinks: Meta said it will only pay the final $5.3 billion of that settlement if TikTok and YouTube adopt matching safety measures and contribute a comparable amount themselves. In other words, even in the act of settling, Meta's message to its competitors was: we'll do this if you do it too. Not because it's right. Because doing it alone is a competitive disadvantage.
That's not an indictment of Meta specifically. It's an indictment of an entire business model that treats child safety as a coordination problem between competitors, rather than a baseline cost of building a product for kids in the first place.
Three platforms. Three admissions, in everything but name, that they knew. All in the same year my daughter is asking me why she can't have what everyone else already has.
If You Can't Verify Age, You Shouldn't Be Operating
I'll say this plainly, because I think it needs to be said plainly: if a platform cannot verify that its users meet the minimum age it claims to require, that platform should not be allowed to operate. Full stop.
This isn't a fringe position from someone who doesn't understand the technology. I work in identity for a living. Verifying who someone is — or at minimum, verifying an attribute like age — is a solved problem. It's not easy, and it's not free, but it is absolutely within reach of companies with the engineering budgets TikTok, Roblox, Discord, and Meta have. These are some of the most sophisticated technology organizations on the planet. They can build recommendation engines that predict what you want to watch before you know it yourself. They can serve billions of personalized ads in milliseconds. The idea that they can't reliably determine whether a user is 10 or 16 or 30 doesn't hold up — it's that verifying age honestly would cost them engagement, and engagement is the business model.
A birthdate field a child can lie about in three seconds is not age verification. It's a liability shield dressed up as a safety feature. TikTok's settlement proves the company knew that distinction and exploited it anyway. Roblox's ongoing litigation alleges the same failure enabled predators to reach children directly.
So here's where I land: identity verification for platforms serving minors shouldn't be a nice-to-have buried in a trust-and-safety roadmap. It should be a condition of doing business — enforced the same way we'd never accept a bank operating without KYC, or a bar operating without checking IDs at the door. If your business model depends on not knowing who's actually using your product, that's not an oversight. That's the design.
Companies that can't or won't solve this shouldn't get to keep operating platforms aimed at children while they figure it out on their own timeline. The cost of getting this wrong isn't a fine they can absorb — it's kids.
What You Can Actually Do About It
The framework I keep coming back to is the one Jonathan Haidt lays out in The Anxious Generation — three commitments that only work if enough parents make them together, because peer pressure is the whole mechanism these platforms exploit:
1. No smartphones before high school.
A basic phone that calls and texts covers 90% of what a kid actually needs for safety and coordination. A smartphone hands them an always-on portal to algorithmic feeds, DMs from strangers, and app ecosystems explicitly designed — as this case shows — to keep collecting data on them whether the rules allow it or not. The delay isn't about distrust of your kid. It's about recognizing that no 10-year-old, and frankly very few adults, can outmaneuver systems engineered by the smartest product teams in the world.
2. No social media before age 16.
This is the one that maps most directly onto what TikTok just got caught doing. Social media platforms aren't just distracting — they're actively harvesting behavioral and biometric data from users the platform knows are underage, because enforcement was never real. Waiting until 16 isn't about being overprotective; it's about waiting until your kid has enough neurological and social maturity to navigate a system that's optimized to exploit exactly the vulnerabilities that are strongest in early adolescence.
3. Phone-free schools.
This one you can't fix alone — it takes your school, other parents, and often your district. But it's worth pushing for, because a phone in a backpack during the school day undercuts everything else. If you want to get involved, talk to your PTA or school board about device policies. You're not the only parent who's uneasy about this — you just might be the one willing to say it out loud first.
None of this requires you to become an alarmist or unplug your family from technology entirely. It requires deciding, deliberately, on a timeline that isn't set by what's normal among your kid's classmates or what an app's terms of service technically allow.
If your kids are already on these platforms, you're not stuck — a few concrete steps:
Audit what's actually installed. Not what you approved originally — what's on the phone right now.
Check whether the "kids" version is real. YouTube Kids and Messenger Kids exist for a reason; the adult versions collect more and restrict less.
Revoke permissions that don't make sense — camera, contacts, and location access an app doesn't actually need to function.
Have a conversation about what "free" means. Kids are more perceptive than we give them credit for once they understand the actual business model.
Where I'd Draw the Line
Age verification is a solvable problem, not an unsolvable one. Every parent reading this gets to decide when their own kid is ready for a phone or a platform — but the platforms don't get to decide, on our behalf, whether they'll bother checking who's actually on the other side of the screen.
So: would you support a law that required real identity or age verification before a kid could create a social media account — even if it meant more friction, more data checks, and yes, more identity infrastructure? Or does that trade-off worry you more than the platforms do?
Identity Decoded publishes every week at identity-decoded.com
