Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The guidelines prohibit sharing personal information on the platform where such sharing could lead to harm including identity theft, stalking, or fraud; the provision references doxing as a prohibited form of harassment.
This analysis describes what TikTok's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes a harm-linked standard for prohibited personal information sharing, covering doxing and information disclosure that enables identity theft, stalking, or fraud. The scope of 'personal information' is not defined in the document, leaving boundary determination to platform enforcement.
Interpretive note: The document does not define 'personal information' or specify the harm-likelihood threshold required to trigger enforcement, leaving classification to platform discretion.
The updated Community Guidelines footer no longer includes a direct link to TikTok's Children's Privacy Policy. Previously, users navigating the Community Guidelines could access child-specific privacy disclosures through the footer link. The Children's Privacy Policy itself may remain available on TikTok's platform, but this change reduces the visibility and discoverability of that document from the Community Guidelines page. Users seeking child privacy information from the Community Guidelines will need to navigate elsewhere or search for it independently.
View change record →Under this provision, content that shares personal information in ways that could facilitate identity theft, stalking, or fraud is subject to removal. The guidelines also classify doxing as a prohibited form of harassment under the separate harassment and bullying provision.
Cross-platform context
See how other platforms handle Privacy and Personal Information Prohibition and similar clauses.
Compare across platforms →Monitoring
TikTok has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"We don't allow sharing personal information that could lead to harm, such as identity theft, stalking, or fraud.Excerpt from TikTok's Community Guidelines
1) REGULATORY LANDSCAPE: This provision engages GDPR in EU/EEA jurisdictions regarding unlawful processing and disclosure of personal data, and state privacy laws in the U.S. including the California Consumer Privacy Act. The FTC has authority over unfair or deceptive data practices that harm consumers. State-level anti-doxing statutes in various U.S. jurisdictions may also be relevant. 2) GOVERNANCE EXPOSURE: Medium. The provision's harm-linked threshold means that enforcement depends on a contextual assessment of whether information sharing could lead to specified harms, rather than a categorical definition of prohibited information types. This creates operational uncertainty for users and content moderators alike. 3) JURISDICTION FLAGS: EU/EEA jurisdictions under GDPR create heightened exposure for any content that discloses personal data without lawful basis. California residents may have additional protections under CCPA regarding personal information disclosed on the platform. Illinois residents may have protections under the Illinois BIPA where biometric information is involved. 4) CONTRACT AND VENDOR IMPLICATIONS: B2B users and developers accessing TikTok APIs must ensure that their use of platform data does not involve sharing personal information in ways that could satisfy TikTok's harm threshold, as API terms may incorporate Community Guideline obligations by reference. 5) COMPLIANCE CONSIDERATIONS: Trust and safety teams should evaluate whether content moderation workflows include detection for doxing-type content and personal information disclosures. Data mapping exercises should account for personal information that users may expose in UGC, and escalation procedures should address potential GDPR or state law reporting obligations where disclosed information constitutes a personal data breach.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes a harm-linked standard for prohibited personal information sharing, covering doxing and information disclosure that enables identity theft, stalking, or fraud. The scope of 'personal information' is not defined in the document, leaving boundary determination to platform enforcement.
Under this provision, content that shares personal information in ways that could facilitate identity theft, stalking, or fraud is subject to removal. The guidelines also classify doxing as a prohibited form of harassment under the separate harassment and bullying provision.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by TikTok.