The protection of children's personal data has become a global concern amid the rapid development of the Internet and social platforms. In the EU, the General Data Protection Regulation (GDPR) has special provisions aimed at protecting children online. Similarly, the U.S. applies the COPPA Child Privacy Protection Act.
It can be seen that TikTok – a short video-sharing platform owned by ByteDance, is increasingly popular among young people around the world. However, it also entails many risks to children's privacy. In recent years, many watchdog agencies have focused on investigating and dealing with TikTok for violating children's privacy, from Europe to the UK and the US.

Decision 02/2023 of the EDPB is a strict and considered decision
On August 2, 2023, the European Data Protection Board (EDPB) issued Binding Decision No. 2/2023 regarding TikTok Technology Ltd, following the coordinated discussion procedure among member Data Protection Authorities. This decision recognizes that TikTok seriously violates the privacy of minor users in the EU, and provides mandatory handling measures.
However, before that, the Irish Data Protection Authority (DPC Ireland) was the focal point in the EU to supervise TikTok. The DPC conducted an investigation into TikTok's processing of personal data of children (under the age of 16) during the period of 2020. The DPC's Draft Decision proposes many violations, including making accounts under the age of 16 public by default, failing to effectively check parental relationships in the Family Pairing feature, lacking appropriate security measures for children, etc., and asking TikTok to fix it without proposing fines. Subsequently, some member agencies, notably the Italian Data Protection Authority – IT SA and the Netherlands – DE SAs, objected, arguing that the DPC was not strict enough, suggesting that the EDPB look into further violations.
On August 2, 2023, the EDPB issued Binding Decision 02/2023 under Article 65 GDPR[1], including the following conclusions:
Violation of the principle of fairness (Article 5(1)(a) GDPR): The EDPB determined that TikTok had seriously violated the "fairness" rule when designing the interface and defaulting child accounts. Specifically, TikTok uses inductive designs (called dark patterns) to encourage young users to accept public accounts instead of private, as well as "layout, button colors" that make it difficult for children to refuse to post public content. This impairs children's ability to make informed decisions and invades their privacy. The EDPB asked the Irish agency to add in its Final Decision an order forcing TikTok to "remove all misleading design tricks" that had been indicated.
Transparency violation (Article 12/13 GDPR): In the Irish Draft, it is stated that TikTok does not provide clear information to children about the consequences of public accounts, for example, the registration pop-up uses the word "anyone/everyone" without explanation, does not link to the specific Privacy Policy for children. The DPC concluded that TikTok violated Article 12.13 GDPR in informing children about their privacy. However, the DPC does not consider this to be a breach of the principle of fairness in Article 5(1)(a). The EDPB in its decision does not change this assessment.
Remedy: The EDPB did not penalize itself but instructed the Irish authorities to extend the compliance order to TikTok. Accordingly, TikTok must take the necessary technical and organizational measures to comply with the regulation, including removing the unfair designs mentioned above in the children's video registration and posting interface. The Irish DPC will base on the decision of the EDPB to make the final decision. The EDPB also asked the DPC to clarify whether it is currently unable to conclude whether TikTok's age verification system violates Article 25 GDPR on Data Protection by default, due to the lack of sufficient evidence to evaluate.
EDPB's Decision 02/2023 affirms that TikTok has committed serious violations of children's privacy due to its insecure default design and misleading interface measures. The EDPB has ordered TikTok to fix it by modifying the design such as default privacy, more transparency, not using colors/content that "lures" children to post publicly. Stakeholders (TikTok, CSA Italy, Denmark/Germany) are all involved in presenting arguments in this process. The end result of the case was that the Irish DPC fined TikTok 345 million euros, marking a major legal blow to TikTok in the EU.
Decision 02 is a big lesson for Tiktok and global social media platforms
The EDPB's Binding Decision 02/2023 has had a great impact both legally and socially on TikTok and other technology platforms, not only in Europe but on a worldwide scale:
For TikTok: This is a strong warning that forces TikTok to fundamentally change its policies and design. After the decision, TikTok announced a change in the privacy account default for users under the age of 16 (similar to the DPC announcing the end of public defaults from early 2021), tightening the Family Pairing feature, and updating the privacy transparency document. In the Final Decision on September 15, 2023, the Irish DPC fined TikTok EUR 345 million for child data breaches. The amount of fines is unprecedentedly large for this issue, second only to the huge fines given to Meta. This fine is equivalent to about 1.5% of TikTok's global revenue, demonstrating the EU's strict position. In the long run, TikTok will have to continue to maintain stricter child protection measures to avoid serious legal consequences. In terms of image, public opinion in the EU and the world sees TikTok as a good example of a platform that needs to be held accountable when underage users are violated.
For other technology platforms: The EDPB's decision sets an important legal precedent for protecting children online. It affirms the EU principle that platforms must be designed by default to be safer, more transparent, and more responsible when targeting children. Since then, many data protection authorities have fined TikTok for children such as the Dutch Data Protection Authority fined EUR 750,000 for child privacy violations in 2021, the UK fined £12.7 million in 2023 for Tiktok giving uncontrolled access to children under the age of 13. This decision is the first time that the EDPB has entered the trial under a consistent mechanism on the principles of design, fairness and children, which should create psychological pressure for the entire technology industry. It signals a trend toward stricter controls, especially in terms of "dark patterns" – the EDPB has published guidance on how to identify and avoid deceptive designs on social media. Other companies such as Meta, Snap or YouTube also need to reconsider their UX to avoid the same consequences. Society in general is therefore more conscious of children's privacy: parents and schools will have to pay attention to checking their children's privacy settings and require developers of children's products to be more transparent. At the same time, this decision prompted lawmakers in many countries to tighten regulations on children online, triggering specific laws or technical regulations for apps that target children.
Social impact: For users, especially children and parents, this is a positive signal. Children's rights are more focused on digital platforms. From a legal perspective, the EDPB decision and the subsequent penalty by the Irish DPC provide a benchmark for comparison as new countries' children's data laws are enacted, leaving global tech platforms facing more new regulations to comply with.

The U.S. head office of TikTok. Source: Reuters
Policy recommendations for Vietnam
Vietnam has issued Decree 13/2023/ND-CP regulating personal data protection effective July 1, 2023, including Article 20 for children's data. Accordingly, "the processing of children's personal data is always carried out on the principle of protecting the rights and in the best interests of children" and "must have the consent of children who are full 7 years old or older and have the consent of their parents or guardians" along with "verifying the age of the child" before processing. Subsequently, on June 26, 2025, Vietnam continued to promulgate the Law on Personal Data Protection to continue to recognize children's data as one of the special protection objects. These are positive initiatives in protecting children in cyberspace. However, from the lessons learned by EDPB and TikTok, Vietnam needs to continue to improve and effectively enforce the law on child data protection. Some solutions that Vietnam can consider implementing in the coming time include:
Firstly, raising awareness and monitoring
In order for the legal framework on children's data protection to be promoted in practice, the state needs to pay attention to propagating and guiding parents and children on personal data protection. At the same time, parents must supervise and instruct their children on how to use the application safely. Schools and management agencies should coordinate to organize a campaign to raise awareness of "children's data safety". In terms of law, it is necessary to equip enforcement agencies with the capacity to detect and sanction violations related to children's data. As it is possible to clearly stipulate the authority to handle child data breaches, force businesses to report serious violations and immediately stop the processing of children's data upon request not only from the competent authorities but especially from parents and children themselves.
Second, the legal framework needs to be synchronous and tight
The Law on Personal Data Protection has been promulgated by the National Assembly but provides general provisions on the processing of children's data in Article 2. We believe that in the Decree guiding the Law, it is necessary to clearly guide the requirements in the process of processing children's data such as determining the age of children, dividing the age of children and requiring appropriate consent. In addition, the guiding Decree also needs to clarify the regulation on safe default mode for minor users on platforms. For example, even if you don't ask for it, your service provider should default to your child's account to private. Besides, Vietnam should also have regulations prohibiting misleading interface designs. Platforms that provide services to children must fully display public/private registration options, agree to opt out,... in a fair and balanced regime. For example, do not take advantage of colors or arrange criteria to push children into less safe options. Authorities can develop a Code of Conduct or interface standards for online services with children, similar to the "Children's Code" in the UK. This also encourages the app developer's awareness of child protection. At the same time, the competent authority requires built-in privacy features or legal supervision for guardians.
As mentioned above, the EDPB emphasizes the importance of providing information in clear, easy-to-understand language. In Vietnam, providers need to ensure that the terms and privacy policies for children (if any) must be presented concisely and clearly on the children's interface, and have a convenient link to those documents. The use of ambiguous language must be clarified. Regulators should issue language guidelines for minor users.
Third, strict and effective enforcement of violations
Child protection laws are only on paper if all the measures mentioned are not strictly and effectively enforced in practice. Therefore, the agency managing personal data activities in Vietnam, the Ministry of Public Security, needs to establish a specialized agency for personal data protection to ensure the transparent implementation of requirements on the protection of personal data and especially children's personal data. safe. Only when businesses see the harmony in policies and strict compliance with Vietnamese laws will their compliance be no longer a mere countermeasure but a way to improve the reputation and brand of enterprises in Vietnam as well as globally.
The EDPB decision emphasizes the responsibility of social media platforms to enforce children's rights in cyberspace. To see that for Europe and many developed countries in protecting sensitive and vulnerable subjects is a top priority in enforcing legal policies. Vietnam, as a leading country in this field, will draw many valuable lessons from Europe's data breach handling practices to apply in accordance with the country's context.
