Blog

TikTok Accepts £12.7M ICO Fine Over Children’s Privacy and Irish DPC Fines Google €403M Over Location Data

Julie Rubash, General Counsel and Chief Privacy Officer
September 29, 2026

Do you want to receive these privacy recaps in your inbox each week? Subscribe here or follow us on LinkedIn.

This week, TikTok dropped its appeal of a 2023 UK Information Commissioner’s Office children’s privacy action and will pay a £12.7 million fine. Meanwhile, the Irish Data Protection Commission fined Google €403 million following its inquiry into Google’s processing of location data under the GDPR.

Read on to see what regulators found and the key takeaways.

Europe

TikTok to Pay ICO Fine for Children’s Privacy Violations

The UK Information Commissioner’s Office (ICO) announced that TikTok has dropped its appeal of a 2023 children’s privacy action and will pay a £12.7 million fine based on allegations that TikTok used children’s data without parental consent, failed to conduct adequate checks to identify and remove underage children from its platform, and failed to provide easy-to-understand information about how user data was collected, used and shared. 

TikTok also withdrew its appeal against an ICO information notice requiring documents and details for a separate investigation, opened in February 2025, into its use of 13–17-year-olds’ personal information in recommender systems. Dropping the appeal means the ICO can proceed with the investigation.


Takeaway

The UK Age Appropriate Design Code applies to services within the scope of the UK data protection laws that are likely to be accessed by UK children under the age of 18, even if children are not the service’s target audience or if the company is not based in the UK. Since the 2023 TikTok action, the ICO has taken action against several other companies as part of wider work to improve how digital platforms use children’s personal data. This includes two major actions in 2026: 

  1. A £247,590 fine against MediaLab.AI based on ICO findings that its image sharing and hosting platform, Imgur, failed to implement any measures to check the age of users, processed the personal information of children under 13 without parental consent or another lawful basis, and failed to conduct a data protection impact assessment to identify and reduce risks to children; and 
  2. A £14.47m fine against Reddit based on findings that the platform failed to apply any robust age assurance mechanism, thus lacking a lawful basis for processing the personal information of children under 13, and failed to conduct a data protection impact assessment (DPIA) to assess and mitigate risks to children. 

As part of announcing the Imgur action, the ICO warned that companies that choose to ignore the fact that children use their service can expect to face similar enforcement action.

Irish DPC Fines Google €403 Million Over Its Processing of Location Data

The Irish Data Protection Commission (DPC), Google’s lead supervisory authority, announced it issued a €403 Million fine against Google following an inquiry launched in 2020 into Google’s use of location data under the GDPR. Specifically, the DPC found that Google infringed the GDPR regarding (a) the lawfulness and fairness of its processing of location data in its Web & App Activity account setting and Location History service, (b) its accountability obligations under the GDPR by failing to demonstrate compliance with the lawfulness, fairness and transparency principle regarding its processing of personal data in its Location Accuracy feature; (c) its transparency obligations in respect of all three features referred to above; and (d) its retention of location data in Web & App Activity and Location History. Google will have 6 months to bring its processing into compliance.


Takeaway

The full decision has not been released yet, so specific details about Google’s non-compliance and the DPC’s expectations are likely forthcoming. In the meantime, this is a reminder that a mere opt-in is not always sufficient to comply with GDPR requirements.

Here, Google required an opt-in for at least its Location History feature, but the DPC still found the processing unlawful and unfair, citing insufficient transparency and data retention longer than necessary. Specifically, the DPC said, “Individuals could have been unaware that their location was being used to, for example, influence them with ads or to infer their interests, and could lose control over their personal data. The retention of users’ location data for longer than necessary aggravated this loss of control”.

A Little More Privacy, if You Please

A Little Privacy, Please weekly recaps are provided for general, informational purposes only, do not constitute legal advice, and should not be relied upon for legal decision-making. Please consult an attorney to determine how legal updates may impact you or your business.

Latest Blog Posts

California’s 2027 Privacy Bills Explained (SB 923, SB 690, and AB 2561)

September 2, 2026

SB 923, SB 690, and AB 2561 update California's...

Latest White Papers

Connecting Legal & Marketing Teams on Consent and Preferences

February 4, 2025

Break down data silos and unlock better collaboration. Marketing...

Navigating Sensitive Data in the U.S.

February 4, 2025

Download our comprehensive guide to learn how different states...

Enterprise Guide To Cookie management & Tracker List Curation

July 1, 2024

How to review the tracking tech on your websites...

Keep in touch

Sign up for our newsletter to keep up with privacy news for adtech and martech,
plus occasional company news.

Let's explore what we can do together.

We'll be in touch within 48 hours

    First name *

    Last name *

    Email address *

    Company *

    Message *

    * indicates required fields