Compliance frameworks, security audits, and quality certifications this company maintains.
TikTok's European operations under Project Clover store EU user data in Norway and Ireland data centers with independent security oversight by NEC, meeting GDPR data residency and processor accountability requirements for TikTok's 150M+ European users.
TikTok provides California residents with CCPA rights including data access, deletion, and opt-out of data sale, with a dedicated privacy center allowing US users to download their TikTok data or request deletion of their account and associated data.
TikTok complies with COPPA by prohibiting users under 13 from creating accounts and implementing restricted privacy settings for users aged 13–15, including private-by-default accounts and disabled direct messaging as required by FTC guidelines for youth-facing platforms.
Regulatory
EU Digital Services Act (DSA)
CompliantTikTok was designated a Very Large Online Platform under the EU Digital Services Act in 2023, requiring TikTok to publish transparency reports, enable algorithm audits, provide non-profiling-based feed options, and conduct systemic risk assessments for its EU user base.
TikTok's US infrastructure under Project Texas achieves SOC 2 Type II certification, covering the security, availability, and confidentiality of US user data stored on Oracle Cloud servers with USDS (TikTok U.S. Data Security) oversight.
TikTok's global engineering and data center operations maintain ISO 27001 information security management certification, covering TikTok's content moderation infrastructure, advertiser data handling, and creator monetization platform systems.
Privacy
FTC COPPA Settlement Compliance
CompliantTikTok operates under FTC COPPA consent decree requirements following its 2019 $5.7M settlement (as Musical.ly), requiring ongoing age-gate enforcement, parental consent workflows, and compliance monitoring for users below the age of 13 on the TikTok platform.
Security
NIST Cybersecurity Framework
CompliantTikTok's US Data Security (USDS) team aligns to the NIST Cybersecurity Framework for managing cybersecurity risk across TikTok's US operations, covering identify, protect, detect, respond, and recover functions for US user data protection.
TikTok is certified to ISO 27018, establishing controls for the protection of personally identifiable information processed in its cloud infrastructure and ensuring that creator and viewer data on the platform is handled in accordance with international privacy standards.
TikTok's mobile applications and web platform conform to WCAG 2.1 AA accessibility guidelines, ensuring that users with visual, motor, or cognitive disabilities can discover, watch, and create short-form video content without accessibility barriers.