Editor’s Note: A quarter of the Justice Department’s announced $400 million TikTok settlement does not become due unless a judge first vacates a 2019 consent decree. The government filed the motion asking for exactly that on Aug. 21, and a hearing is calendared for Sept. 21 before U.S. District Judge Otis D. Wright II.
The decree it seeks to unwind was never only a $5.7 million penalty. It carried a permanent COPPA injunction, a sworn compliance report, event-triggered notices running 10 years, a record-creation duty with its own five-year retention, compliance monitoring and retained jurisdiction. The government argues under Rule 60(b) that changed ownership, new compliance systems and the settlement itself make continued enforcement inequitable and unnecessary.
For cybersecurity, data privacy, regulatory compliance and eDiscovery professionals, the operative gap is what the motion leaves out. It says nothing about retention, preservation or the disposition of records created under the order, so it does not resolve which other duties, holds or policies would govern them. Retention schedules citing a court order as their sole legal basis may become orphaned when it is vacated, and automated disposition does not pause to ask whether an independent duty still applies.
Watch the Sept. 21 hearing, and watch harder for whether any resulting order reaches the records.
Content Assessment: DOJ ties a quarter of TikTok's $400 million to vacating a 2019 order
Information - 93%
Insight - 94%
Relevance - 93%
Objectivity - 92%
Authority - 90%
92%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "DOJ ties a quarter of TikTok's $400 million to vacating a 2019 order."
News Analysis – Data Privacy and Protection Beat
DOJ ties a quarter of TikTok’s $400 million to vacating a 2019 order
ComplexDiscovery Staff
A quarter of the Justice Department’s announced $400 million settlement with TikTok does not come due unless a judge first vacates a seven-year-old court order. Read the structure that way, and the deal appears to link payment to two forms of relief: resolving the claims and ending the earlier order.
The department announced the settlement Friday, resolving Children’s Online Privacy Protection Act litigation it filed in 2024 in the U.S. District Court for the Central District of California. TikTok will pay $300 million immediately, the release says. The last $100 million comes due, in the release’s own words, “upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly.”
That reading is an interpretation and should be labeled as one. The public materials establish a payment condition. They do not allocate what the parties assigned to penalties, to closing out the claims, to compliance improvements, or to ending the decree. The government’s own motion to vacate, filed the same day, never mentions a dollar figure at all.
The department calls the result one of the largest recoveries ever obtained in a COPPA case, a hedge it declines to sharpen into a claim of the largest.
What the 2019 order actually required
The decree at issue is the stipulated order for civil penalties, permanent injunction and other relief that U.S. District Judge Otis D. Wright II entered March 27, 2019, in United States v. Musical.ly, case 2:19-cv-01439. The $5.7 million civil penalty is the number the trade press repeated in 2019. The obligations around it were built to run considerably longer.
According to the proposed stipulated order the parties filed in February 2019, which is the version the Federal Trade Commission publishes rather than the text Wright signed a month later, Section I permanently restrained the defendants from violating the COPPA Rule and states no expiration. Section VII required a single sworn compliance report one year after entry, plus sworn compliance notices within 14 days of specified changes to contact points or corporate structure, for 10 years. Section VIII required the defendants to create three categories of records for 10 years after entry and to retain each record for five years: records necessary to demonstrate compliance, including all submissions to the commission; copies of consumer complaints about the defendants’ information practices and any response; and a copy of each materially different form, page or screen through which personal information was collected from a child. Section IX authorized compliance monitoring, including depositions and document production on 14 days’ notice, and states no duration. Section X retained the court’s jurisdiction and names no end date.
The government’s own motion confirms the general shape of that structure. It describes the entered order as carrying a permanent injunction against COPPA Rule violations, long-term compliance reporting, long-term recordkeeping, and monitoring that reaches interviews of employees who agree to them. It does not track the proposed text on every point. The motion describes sworn compliance reports running ten years, while the published proposed order provides for one sworn report at one year and sworn compliance notices over the decade that follows. The entered text was not obtained for this article, which leaves the difference unresolved.
The distinction between those periods carries weight that a single headline number hides. The 10-year record-creation and change-notice periods run through March 2029. Because each covered record carried its own five-year retention, some decree-based retention periods could extend past that date. The permanent injunction, the monitoring provision and the retained jurisdiction were not written to expire at all.
How the government argues for vacatur
The motion is the document to read, and it is public. Captioned in the 2019 action and filed Aug. 21, the United States’ consent motion asks Wright to set aside the stipulated order under Federal Rule of Civil Procedure 60(b)(5) and 60(b)(6). Its publicly available copy bears an electronic filing stamp identifying it as Document 84 in the 2024 case, 2:24-cv-06535. A hearing is calendared for Sept. 21 at 1:30 p.m. The defendants consent to the motion.
The argument runs on changed circumstances. The government describes TikTok US as a newly formed, American-controlled entity in which ByteDance and its affiliates hold under 20 percent, and points to age gates and moderation systems built since 2019. It treats the 2024 statute forcing divestiture of foreign-adversary-controlled applications as a development nobody anticipated when the order was entered. It argues the settlement gave the United States a durable remedy that makes continued enforcement unnecessary, and that applying the order prospectively is no longer equitable. Its conclusion argues that COPPA, the COPPA Rule, and the FTC Act would keep binding TikTok US whatever happens to the decree.
One thing the motion does not do is name a number. It refers to a substantial payment without quantifying it, which is why the pricing read in this article is offered as interpretation rather than as the government’s own account of the bargain.
Why the second tranche invites a reading
Vacatur is not forgiveness of a fine. It removes the instrument, and with the instrument go the reporting obligations, the record-creation duty, the monitoring provision and the court’s supervisory jurisdiction. A company that pays a penalty stays under the order. A company that obtains vacatur does not.
The scope is worth stating precisely, because it is easy to overstate, and here the government and Fairplay agree on the boundary. COPPA still binds TikTok, and so do applicable state privacy laws. What vacatur reaches is the supervisory apparatus the 2019 order built on top of the statute, which is narrower than immunity and distinct from a discount.
That distinction may help explain the structure. The announced settlement is roughly 70 times the 2019 civil penalty, a comparison that uses the full $400 million including the tranche not yet owed, and the government still left the last quarter of that figure conditional.
Records the order required, and what is unknown
Here is where information governance teams should slow down. Vacating a decree ends the decree’s obligations going forward. It does not reach back and unmake records the decree caused to exist, and it does not by itself release those records from any other preservation duty that may have attached.
What the public materials do not establish is which records were created, which still exist, or whether anything else now requires keeping them. Records created earlier in the decree’s life may already have run out their five-year retention. Any applicable class-action hold, state attorney general inquiry or duty arising once litigation is reasonably anticipated would operate independently of the decree, and a hold grounded in any of those suspends routine deletion for the identified custodians and sources, whatever happens Sept. 21.
The motion is silent on the whole question. Nothing in the government’s filing addresses retention, preservation or the disposition of materials created under the 2019 order, so it does not resolve which other duties, holds or policies would govern what happens to them.
The practical exposure is a retention schedule that names the wrong authority. Any organization operating under a consent decree should already know which schedule entries cite that decree as their sole legal basis, because those entries may become orphaned when an order is vacated. Map them now, re-paper the basis where an independent duty still applies, and route disposition through counsel rather than letting an automated rule fire on a changed status flag. The failure mode is not malice. It is a records system that sees the order gone and helpfully purges.
Security and privacy teams have a parallel stake, because the order’s record categories are operational evidence rather than paperwork. Compliance submissions, consumer complaints and the responses to them, and copies of the collection forms, pages and screens are the material an investigation or an insurance review may ask for. If the decree is vacated, the decree itself would no longer compel their continued creation, whatever another law, hold, contract or internal policy might still require.
Fairplay objects to ending the decree’s oversight
Fairplay, a nonprofit that campaigns against marketing to children and opposed the settlement the day it was announced, focused its objection on that loss of oversight. “Even worse, it relieves TikTok of its compliance and monitoring obligations under the 2019 consent decree,” said Haley Hinkle, the group’s policy counsel, in a statement issued Aug. 21.
Hinkle also argued the money is too small to bite, calling it “a drop in the bucket compared to its $33 billion annual revenue,” a figure Fairplay attributes to TikTok without defining its legal-entity or business scope and one this article does not independently verify. She urged the public “to object to this sweetheart deal for TikTok.” She also contrasted the agreement with the FTC’s 2022 resolution with Epic Games, maker of Fortnite, which she said required substantial changes to make platforms safer for minors. The TikTok agreement, she said, places TikTok under no new obligations.
The record supports the contrast on its face. Epic agreed in December 2022 to a $275 million civil penalty the FTC called the largest ever obtained for violating an FTC rule, one component of a $520 million package whose remainder covered refunds for unwanted charges rather than children’s privacy. The commission said the settlements also required Epic to turn voice and text communications off by default for children and teens, delete personal information collected from children under 13 without parental consent, establish a comprehensive privacy program and obtain regular independent audits. The court entered the COPPA order in February 2023, according to the FTC’s case page. Fairplay is an advocacy organization arguing a declared policy position, and its framing should be weighed as such. Its structural observation remains relevant: the settlement links a contingent payment to the requested termination of decree-specific obligations.
Where practitioners should be watching
The docket in the Central District of California is the thing to follow, and 2:24-cv-06535 is where the motion was stamped. Two questions matter rather than one. Whether Wright grants vacatur is the first. Whether any resulting order addresses residual record obligations is the second, and it is the one the motion does not reach. An order that vacates a decree without addressing those records would not itself resolve which other duties govern their retention. That uncertainty is how orphaned schedule entries can become discovery problems later.
Watch also for whether the FTC, which referred the matter and whose 2019 case produced the decree, says anything about the vacatur. The 2024 complaint alleged that TikTok knowingly permitted children to create regular accounts, collected and retained their personal information without notifying or obtaining consent from their parents, and frequently failed to honor parental deletion requests, all while under a court order barring that conduct. COPPA reaches operators that knowingly collect, use, or disclose personal information from children under 13 without parental notice and consent, and separately requires deletion at a parent’s request. That knowing element is part of the claim, and it was never adjudicated. The Justice Department’s release states plainly that the claims “are allegations only, and there has been no determination of liability.”
So the enforcement record closes with a large number and an unresolved vacatur motion. If a consent decree can be unwound as part of a settlement, what happens to the next one, and who keeps the records if this one goes?

News sources
- Justice Department Secures $400M Settlement with TikTok and ByteDance to Resolve Children’s Privacy Litigation (U.S. Department of Justice)
- The United States’ Notice of Consent Motion and Consent Motion to Vacate Stipulated Order (U.S. Department of Justice filing, hosted by Courthouse News Service)
- Justice Department Sues TikTok and Parent Company ByteDance for Widespread Violations of Children’s Privacy Laws (U.S. Department of Justice)
- [Proposed] Stipulated Order for Civil Penalties, Permanent Injunction, and Other Relief (Federal Trade Commission)
- Statement on the DOJ’s $400 million settlement with TikTok & ByteDance (Fairplay)
- Musical.ly, Inc., Matter 172 3004 (Federal Trade Commission)
- U.S. v. Musical.ly, Case No. 2:19-cv-01439-ODW (RAO) (Leagle)
- Epic Games, Inc., U.S. v., Matter 2223087 (Federal Trade Commission)
- TikTok reaches $400 million settlement with Justice Department over children’s privacy (PBS NewsHour and The Associated Press)
- TikTok pays $400 million as DOJ moves to vacate its 2019 COPPA decree (PPC Land)
- DOJ Settles TikTok Lawsuit for $400 Million (WinBuzzer)
Assisted by GAI and LLM technologies
Additional reading
- Four days offline, and a threshold already under review
- A program not yet publicly operational, and an untested Computer Fraud and Abuse Act defense
- Recent AI evaluation incidents expose gaps in containment, configuration and evidence
- When hacktivists join the fight: A closer read of Cyber Law Toolkit scenario 36
- Beijing contests House Salt Typhoon report as Congress weighs a wider cleanup
- Restore the controller, risk losing evidence: federal water guidance leaves the sequence open
- Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report
- ShinyHunters’ July 31 deadline for EY arrives after third-party tax-data breach
- The new negligence baseline: how voluntary CI Fortify guidance becomes Exhibit A in post-breach litigation
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.


























