10 Total
4 High severity
5 Medium severity
1 Low severity
Summary

This document establishes TikTok's global privacy policy governing personal data collection, processing, and sharing for users of its app and website. The policy authorizes collection of location data, biometric features extracted from video content, keystroke patterns, device contacts, and off-platform shopping and browsing behavior supplied by advertising partners, with this data used to construct user profiles for personalized advertising served on and off the TikTok platform. Users may access, modify, or request deletion of personal data through TikTok's Privacy Center, with availability of these rights varying by jurisdiction.

Technical / Legal Breakdown

This document is TikTok's global Privacy Policy (last updated July 8, 2025), governing data collection, processing, and sharing practices for TikTok apps, websites, and related services operated by TikTok Pte. Ltd. (Singapore), and applies to all users of the Platform outside jurisdictions with separate dedicated policies. The policy states that TikTok collects an extensive range of personal data including account credentials, user-generated content and associated metadata, messages and message metadata, precise and approximate location, device identifiers (including keystroke patterns and audio settings), face and body feature data extracted from videos and images, clipboard content, phone and social network contacts, and off-platform behavioral data supplied by advertisers and business partners; the terms authorize use of this data for purposes including personalized advertising on and off the Platform, training machine learning models and algorithms, inferred profiling of age, gender, and interests, and sharing with corporate affiliates, advertisers, measurement partners, and independent researchers. The policy's scope of biometric-adjacent data collection (face and body feature identification from user content) and the explicit authorization to use user content in advertising and marketing campaigns, combined with broad off-platform data ingestion from advertiser partners, are operationally notable; the agreement asserts these rights on a global basis, though applicable law in specific jurisdictions (including GDPR in the EU/EEA, UK GDPR, CCPA/CPRA in California, and PDPA in Singapore) may constrain the legal bases, consent requirements, and data subject rights that govern these practices in practice. The policy engages GDPR, UK GDPR, CCPA/CPRA, COPPA (given minor-user considerations), Singapore PDPA, and potentially the EU AI Act given AI/ML training uses; material compliance considerations include the adequacy of consent mechanisms for biometric-adjacent processing, the legal basis for cross-context behavioral advertising, and the robustness of data subject rights mechanisms across jurisdictions.

Institutional Analysis

Institutional analysis available with Compliance

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Compliance.

Start Compliance free trial

1 important change detected

2 versions captured · Last updated: May 2026

What changed TikTok Ads replaced its U.S.-specific privacy policy with language covering "other regions." The controlling entity shifted from TikTok USDS Joint Venture LLC to TikTok Pte. Ltd., a Singapore-registered company.
Why this matters The updated policy changed the controlling entity from TikTok USDS Joint Venture LLC to TikTok Pte. Ltd., a Singapore-registered company. The U.S.-specific privacy policy language was replaced with terms covering "other regions." Users previously governed under U.S. privacy protections are now subject to different jurisdictional terms.
View full change record →
High — 4 provisions
Medium — 5 provisions
Low — 1 provision

Monitoring

TikTok Ads has updated this document before.

Monitor includes same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Start Monitor free trial Or create a free account →

Compliance Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Compliance includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Compliance free trial

Cross-platform context

See how other platforms handle Behavioral Advertising and Third-Party Data Sharing and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
DMA
European Union
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 5, 2026 09:40 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000673
Version ID CA-V-002196
SHA-256 4ea25d87dda793e626e521fab7dfee9733e5118afd630c840e62738871d9e3ac
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans