10 Total
4 High severity
5 Medium severity
1 Low severity
Summary

This is TikTok's global privacy policy, explaining what personal data TikTok collects from users of its app and website and how that data is used, shared, and protected. The most important thing to know is that TikTok collects a broad range of data including your location, the faces and body features in your videos, your device's keystroke patterns, your contacts, and your off-platform shopping and browsing behavior supplied by advertisers, and uses all of this to build a profile of you for personalized advertising both on and off TikTok. You can review and adjust some data and ad preferences through TikTok's Privacy Settings in the app, and in some regions you have rights to access, delete, or port your personal data by submitting a request through TikTok's privacy request portal.

Technical / Legal Breakdown

This document is TikTok's global Privacy Policy (last updated July 8, 2025), governing data collection, processing, and sharing practices for TikTok apps, websites, and related services operated by TikTok Pte. Ltd. (Singapore), and applies to all users of the Platform outside jurisdictions with separate dedicated policies. The policy states that TikTok collects an extensive range of personal data including account credentials, user-generated content and associated metadata, messages and message metadata, precise and approximate location, device identifiers (including keystroke patterns and audio settings), face and body feature data extracted from videos and images, clipboard content, phone and social network contacts, and off-platform behavioral data supplied by advertisers and business partners; the terms authorize use of this data for purposes including personalized advertising on and off the Platform, training machine learning models and algorithms, inferred profiling of age, gender, and interests, and sharing with corporate affiliates, advertisers, measurement partners, and independent researchers. The policy's scope of biometric-adjacent data collection (face and body feature identification from user content) and the explicit authorization to use user content in advertising and marketing campaigns, combined with broad off-platform data ingestion from advertiser partners, are operationally notable; the agreement asserts these rights on a global basis, though applicable law in specific jurisdictions (including GDPR in the EU/EEA, UK GDPR, CCPA/CPRA in California, and PDPA in Singapore) may constrain the legal bases, consent requirements, and data subject rights that govern these practices in practice. The policy engages GDPR, UK GDPR, CCPA/CPRA, COPPA (given minor-user considerations), Singapore PDPA, and potentially the EU AI Act given AI/ML training uses; material compliance considerations include the adequacy of consent mechanisms for biometric-adjacent processing, the legal basis for cross-context behavioral advertising, and the robustness of data subject rights mechanisms across jurisdictions.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

1 important change detected

2 versions captured · Last updated: May 2026

What changed TikTok Ads updated its privacy policy on May 5, 2026, replacing the U.S.-specific version with language addressing 'other regions.' The controlled entity shifted from TikTok USDS Joint Venture LLC to TikTok Pte. Ltd., a Singapore-registered company. The document removed references to Washington state health data law compliance and restructured how information collection categories are presented, adding explicit language about user-generated content processing and associated metadata.
Why this matters The updated policy states that TikTok Pte. Ltd., a Singapore-registered entity, now provides and controls the Platform, replacing the previous U.S.-based operator. The policy removes its prior explicit reference to compliance with Washington's My Health My Data Act and similar state health data laws, without stating what replaces that compliance framework. This shift in controlling entity and removal of specific health data law compliance language may affect what consumer protections apply depending on user jurisdiction. The policy now applies to 'other regions' rather than specifically to U.S. users, creating ambiguity about which jurisdiction's consumer protections govern.
View full change record →
High — 4 provisions
Medium — 5 provisions
Low — 1 provision

Monitoring

TikTok Ads has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle Behavioral Advertising and Third-Party Data Sharing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 09:40 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000673
Version ID CA-V-002196
SHA-256 4ea25d87dda793e626e521fab7dfee9733e5118afd630c840e62738871d9e3ac
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans