TikTok and parent company ByteDance have agreed to pay $400 million to settle a Department of Justice lawsuit alleging violations of the Children's Online Privacy Protection Act, one of the largest COPPA recoveries in the law's history. Under the settlement, TikTok will pay $300 million immediately, with the remaining $100 million due when a prior consent decree against its predecessor, Musical.ly, is vacated by a court.
The case lands at a moment when privacy enforcement is accelerating on both sides of the Atlantic. According to regulatory intelligence firm Corlytics, global regulators issued approximately $542 million in fines during Q1 2026 alone, with data privacy breaches among the categories driving the largest individual penalties. In the US specifically, the FTC's 2025 amendments to the COPPA Rule - the first major update since 2013, taking effect June 23, 2025 - expanded the definition of personal information, imposed more prescriptive data retention and security requirements, and required separate parental consent for third-party data disclosures. The compliance bar has moved, and enforcement is following.
TikTok's history with regulators makes the insurance angle particularly instructive. The company was subject to a prior consent decree stemming from its Musical.ly predecessor, which is now being vacated as part of this settlement's structure. That sequence - prior regulatory contact, subsequent enforcement action, nine-figure penalty - illustrates precisely the exposure chain that cyber and management liability policies often handle less completely than their headline limits suggest.
Cyber and D&O policies typically address regulatory enforcement in two distinct layers. Defense costs - attorneys' fees, investigation costs, regulatory response - are generally covered broadly under regulatory defense insuring clauses and are reliably available up to the full policy limit. The fine or penalty itself is a different matter entirely.
Most cyber and management liability policies either exclude regulatory fines and penalties outright, or cap them under a dedicated sub-limit that sits well below the overall policy limit. This reflects the legal principle, embedded in many state insurance codes, that punitive regulatory penalties are uninsurable as a matter of public policy. The result is that a company can carry a cyber program with a $25 million headline limit and find its actual fine coverage capped at $1 million - or excluded altogether from the penalty itself while defense costs remain fully available.
As COPPA settlements, GDPR fines and state privacy enforcement actions have scaled toward nine-figure territory, the distance between what a policy's headline limit implies and what it would actually pay toward a fine at that scale has become a material blind spot. For most risk managers reviewing a program designed even three years ago, the sub-limit for regulatory penalties was set at a time when these numbers looked very different.
Two other policy mechanics deserve attention alongside sub-limits, particularly for any client that has had prior regulatory contact.
Retentions for regulatory investigation triggers are being pushed higher by some underwriters as privacy enforcement frequency increases across their books, reflecting the fact that investigations are no longer rare events but a recurring cost of operating at scale in data-driven businesses. A client whose retention was set before this shift may find it is absorbing more of an investigation's cost than the program was designed to allow.
Prior-knowledge or prior-circumstances exclusions are the more acute risk. A company that received a warning letter, an earlier consent decree or a civil investigative demand before the policy incepted may find a subsequent enforcement action falls entirely outside coverage if the exclusion is triggered by that earlier contact. TikTok's 2019 consent decree is a concrete example: any policy written after that decree would need to be reviewed carefully for whether the subsequent DOJ action - which the complaint itself traced back to conduct predating and post-dating that earlier settlement - could be treated as a related circumstance.
For brokers placing cyber and management liability for platform companies, data-driven businesses or any client that processes information from users under 13, the TikTok settlement is a concrete prompt to walk clients through what their current program would and would not pay if a comparable enforcement action landed.
That conversation should specifically address the sub-limit applying to regulatory fines versus the broader defense cost limit, whether any prior regulatory correspondence - warning letters, civil investigative demands, consent decrees - could trigger prior-knowledge exclusions on the current program, and whether retention levels for regulatory triggers still reflect the actual frequency with which this class of client is now encountering enforcement activity. These are renewal questions, not claims questions - the time to identify the gap is before the DOJ announces a settlement, not after.