The Department of Justice announced a $400 million settlement with TikTok and ByteDance resolving a 2024 lawsuit alleging violations of the Children's Online Privacy Protection Act (COPPA), the U.S. law requiring parental consent before collecting personal data from children under 13. TikTok will pay $300 million immediately, with a further $100 million due once a court vacates an older consent decree tied to Musical.ly, the app TikTok's parent company acquired and rebuilt the platform on. The DOJ's press release notes the settlement reflects compliance improvements TikTok has already made since the suit was filed, including stronger age-verification controls and expanded parental oversight tools, rather than a determination of legal liability. For engineers and product teams building anything that touches minors' data, social apps, ed-tech platforms, gaming services, or any consumer product with an under-13 user base, this settlement is a concrete reminder of how expensive COPPA non-compliance can be, and of what regulators consider adequate remediation. The DOJ specifically cited improved age-related controls and expanded parental oversight as evidence of good-faith compliance, which is a useful signal for what auditors and legal teams will look for: verifiable, technical age-gating mechanisms rather than self-reported birthdates, plus parental consent flows that are auditable after the fact. It's also a reminder that COPPA enforcement doesn't require proof of intent to harm children; the statute functions close to a strict-liability framework around data collection practices, so any team collecting analytics, ad-targeting signals, or account data from a mixed-age user base should treat age-assurance infrastructure as a first-class engineering requirement, not an afterthought bolted on for legal sign-off.