TikTok is a social media app for creating and sharing short videos that has exploded in popularity in recent years. As of early 2023, TikTok has over 1 billion monthly active users globally. The app is especially popular among teenagers and young adults.
With its meteoric growth, TikTok has faced growing scrutiny over its data collection practices and privacy protections, especially given its ownership by a Chinese company. Critics have accused TikTok of being a potential national security threat, citing fears that American user data could be accessed and used by the Chinese government. There are also concerns around TikTok’s targeted advertising and algorithmic feed, and whether it could negatively impact things like mental health and body image.
In this article, we’ll take an in-depth look at what types of data TikTok collects, who has access to that data, and the privacy concerns and controversies surrounding the platform.
What data does TikTok collect?
TikTok collects a significant amount of data from its users. According to research, this includes:
- User information: TikTok collects information users provide during sign up, including name, email address, phone number, username, password, date of birth, and profile bio (IdentityReview).
- Device data: TikTok gathers data on the devices used to access the app, including IP address, device model, operating system, mobile carrier, and unique device identifiers (IdentityReview).
- Location data: TikTok accesses the precise geolocation of users when the app is in use, as well as approximate location data based on IP address (IdentityReview). The company claims this data helps serve relevant content and ads to users.
- Contacts: TikTok has the ability to access users’ address books to find friends to connect with on the platform, although they claim not to actually access or store this data without consent (JSTOR).
- Usage data: TikTok records extensive information on how users interact with the app, including liked, shared, or posted videos, search terms and history, comments, messages, time in app, and more (IdentityReview).
In summary, TikTok gathers a wide range of user data, including sensitive information like geolocation, that allows them to understand user behavior and preferences.
Does TikTok share user data with China?
TikTok is owned by the Chinese company ByteDance, headquartered in Beijing, which has raised concerns about potential ties to the Chinese government. While TikTok stores American user data in Virginia with a backup in Singapore, its parent company ByteDance is still based in China and subject to Chinese laws.
TikTok has consistently denied sharing any data with the Chinese government, stating that the data of American users is not subject to Chinese law. However, experts have warned that the Chinese government could potentially pressure ByteDance to share data in the future.
There have been no confirmed reports of TikTok data being accessed from China so far. But given the legal and political climate in China, the ties between TikTok and ByteDance has remained an issue regarding national security and data privacy protections. TikTok is reportedly working to restructure its organization to separate American operations from ByteDance control.
Overall, while there is no direct evidence currently that TikTok shares data with China, the fact that its parent company is Chinese has led to ongoing suspicions and investigations by Western governments.
Sources: CNN, The Guardian
TikTok’s privacy policy
TikTok’s privacy policy details the types of data the app collects from users. This includes information like profile and account data, user-generated content, location data, and device data (https://www.tiktok.com/legal/privacy-policy-row).
According to the policy, TikTok may share user data with third-party service providers to assist in providing and optimizing the platform and with TikTok’s parent company ByteDance (https://www.tiktok.com/legal/page/row/privacy-policy/en). There have been concerns that data could potentially be accessed by the Chinese government through ByteDance, since the company is based in China.
Some aspects of TikTok’s data practices that have raised concerns include:
- Collecting an extensive amount of user data
- Vague disclosures about how data may be used
- Potential sharing of data with Chinese authorities due to ByteDance’s location
Investigations into TikTok’s data practices
Several investigations have looked into TikTok’s data collection and privacy practices. In 2019, the U.S. government launched a national security review of TikTok’s parent company ByteDance’s acquisition of Musical.ly ([1]). The investigation aimed to determine if TikTok poses a risk to U.S. national security by collecting data on U.S. citizens.
In 2021, BuzzFeed News found that TikTok was accessing users’ sensitive biometric data through a behind-the-scenes tracking tool called Sensor Tower ([2]). This allowed TikTok to gather detailed information about users’ locations, devices, and browsing habits.
The Australian government conducted an audit of TikTok in 2020 and found no evidence user data was being transferred to China ([3]). However, they noted that TikTok’s data collection practices were opaque.
While investigations have not found conclusive evidence of data misuse, concerns remain about TikTok’s large data collection and relationship to its Chinese parent company.
Steps TikTok has taken
TikTok has taken some steps in recent years to assure users of stronger privacy protections and secure user data. In 2022, TikTok announced it was routing all U.S. user traffic to Oracle cloud servers located in the United States. This was done to store U.S. user data domestically rather than in data centers in China where TikTok’s parent company ByteDance is located.
TikTok also partnered with Oracle to manage U.S. user data security through new data security protocols. According to TikTok, this allows Oracle to regularly review and verify its data security practices. TikTok claims this provides an “unprecedented level of transparency” into how it secures user data.
In 2021, TikTok introduced new privacy settings and protections for teenage users under 16, including the ability to mute push notifications, restrict sharing personal information, and limit content recommendations. TikTok has also added resources to educate younger users on online safety and privacy best practices.
Remaining concerns
Despite TikTok’s efforts to address privacy issues, some oversight and transparency concerns remain (Kaspersky). As a Chinese company, TikTok is still subject to Chinese law and government oversight to some extent. While TikTok claims user data is stored in the US and Singapore, experts question how much access Chinese regulators have (Forbes). There is limited visibility into TikTok’s data and security practices, making it difficult to verify their claims.
Additionally, technically savvy users may be able to circumvent some of TikTok’s restrictions and privacy controls through technical workarounds. Concerns remain that user data could still be surreptitiously collected without consent (Kaspersky). More transparency and independent audits of TikTok’s systems could help alleviate these concerns.
Best practices for users
There are some steps TikTok users can take to better protect their privacy on the platform:
Enable all privacy settings in the app, like making an account private, restricting comments and messages, and limiting data collection. Go to “Privacy and Settings” and adjust options for an account, comments, messages, etc (source).
Be aware of the type of data being shared. TikTok collects user data like location, contacts, and device info. Avoid sharing sensitive info. Also be cautious of linking other social media accounts (source).
Users should carefully consider what they post. Even with privacy settings, anything shared on the platform could potentially be accessed or distributed beyond intended audiences.
Frequently check privacy settings and update as needed. TikTok often adds new options and changes how previous settings work.
The future of TikTok’s privacy
As controversies continue, TikTok faces increasing pressure to restrict data access from its parent company ByteDance and the Chinese government. Critics argue that TikTok should store international user data in countries like the US or EU, not China.[1] US lawmakers have introduced legislation aiming to ban TikTok unless it meets stricter privacy standards.[2]
Several key developments will shape TikTok’s future approach to privacy:
- Ongoing negotiations with policymakers over data storage and access.
- Potential leadership changes if controversies escalate.
- Expansion of encryption and other technical safeguards.
- Continued scrutiny from researchers and journalists.
TikTok will likely implement incremental changes to alleviate concerns while preserving core business models. Radical shifts seem unlikely unless new regulations mandate them. For now, users must weigh risks against TikTok’s entertainment value.
[1] https://tiktukmoneycalculator.com/how-to-unsync-contacts-on-tiktok
[2] https://tiktukmoneycalculator.com/how-to-unsync-contacts-on-tiktok
Conclusion
After reviewing TikTok’s privacy policies, data collection practices, and the ongoing investigations into its handling of user information, a few key points emerge. While TikTok gathers a significant amount of data on its users, as most social media platforms do, there is no definitive evidence that it shares private user data directly with the Chinese government. However, given China’s data surveillance laws, the level of access Chinese-based employees have to TikTok’s systems is concerning to some cybersecurity experts.
TikTok has taken steps to assuage privacy fears by storing more US user data domestically rather than in China, establishing content moderation policies, and seeking greater transparency in its operations. But questions remain about the degree of influence and control its parent company ByteDance yields over the platform and user data. There are also questions about whether TikTok’s security defenses and data practices meet the highest standards globally.
For users, it is wise to understand that any data shared on social platforms may be accessed and analyzed for commercial purposes. Maintaining strong security and privacy settings, being selective in sharing personal information, and avoiding linking social accounts to other private services can help reduce exposure. But there are still inherent risks in any social media use.
The debate over TikTok’s handling of private user data will persist, especially as governments apply more scrutiny to tech platforms. While definitive evidence of systemic privacy violations remains elusive, TikTok faces ongoing pressure to enforce the highest data security standards and uphold user privacy if it aims to maintain and grow its massive user base over the long-term.