Skip to content

TikTok Events SDK: Korea fines TikTok KRW 10.3B over ad data

Filip LuchianencoUpdated 6 min read

Last updated: 2026-10-03

On July 22, 2026, South Korea's Personal Information Protection Commission (PIPC), the national data protection authority, decided at its 14th plenary meeting to fine Tiktok Pte. Ltd. KRW 10,306,000,000 (about KRW 10.3 billion) and to issue a corrective order and a publication order, according to the PIPC press release of July 23, 2026. The PIPC found that TikTok collected and used "third-party behavioral information" without a lawful basis through tools it distributes to other web and app operators: TikTok Pixel, the TikTok Events SDK and the Events API. At the same meeting the PIPC fined Apple Distribution International Limited KRW 252,000,000 over Siri recordings and transcripts, for a combined total of KRW 10,558,000,000 against TikTok and two Apple affiliates.

Quotations from Korean sources are translations by CanITrustThat; each links to the Korean original.

What did the PIPC find about the TikTok Events SDK and Pixel?

The release states that TikTok "distributes behavioral information collection tools (TikTok Pixel, Events SDK, Events API, etc.) to other web and app operators" and collects "the activity records of users who visit the web and app pages of other companies where the tools are installed". The release lists the activity as "clicks, purchases, add to cart, inquiries, downloads, searches, content views, etc."

The release gives two figures:

  • about 71,000 Korean companies use TikTok's behavioral information collection tools;
  • as of December 2025, TikTok collected third-party behavioral information through those tools from 9.45 million active users in Korea.

The PIPC describes the processing chain: TikTok "collects users' third-party behavioral information together with users' device identifiers and other information, links it to TikTok member accounts, analyzes it to infer users' characteristics and interests, and uses it for targeted advertising". A footnote defines the device identifiers as "the advertising identifier of each mobile device (Android: GAID / iOS: IDFA) and the internet browser identifier assigned by TikTok (cookie: ttp)".

On consent, the PIPC found that TikTok did not inform users at sign-up in a way they could clearly recognize. It found that TikTok took consent "in the form of mandatory consent together with other personal information strictly necessary to provide the service", which "in effect forced" collection of third-party behavioral information for targeted advertising on anyone who wanted to use TikTok. The release states that TikTok thereby left users unable to "exercise a meaningful right to consent".

The PIPC also found that, in providing TikTok Lite's points cash-withdrawal service, TikTok transferred users' personal information to affiliates without disclosing or notifying the statutory items, such as the personal information transferred, the recipients' purposes of use and the retention period.

Which provisions did the PIPC apply, and what are the penalties?

Respondent PIPC finding Provision Outcome
Tiktok Pte. Ltd. collection and use of third-party behavioral information without a lawful basis PIPA Article 15(1) (collection and use) KRW 10,306,000,000, corrective order, publication order
Tiktok Pte. Ltd. TikTok Lite transfers to affiliates without the statutory disclosures PIPA Article 28-8(1) (overseas transfer) included in the same fine and orders
Apple Distribution International Limited Siri recordings and transcripts used without separate consent until August 2019; transcripts used for service improvement without a separate legal basis after October 2019 former Information and Communications Network Act KRW 252,000,000
Apple Services Pte. Ltd. overseas transfers to Apple Inc. and other affiliates with incomplete privacy policy disclosures PIPA (overseas transfer) corrective order, including review of overseas transfers

Source: PIPC press release, July 23, 2026 (Korean). PIPA is the Personal Information Protection Act.

Article 15(1) lists the grounds for collecting personal information, the first being "where the consent of the data subject has been obtained". Article 28-8(1) bars transfers abroad unless one of five conditions applies, the first being "separate consent" to the transfer.

Article 64-2(1) allows a penalty surcharge of up to 3% of total revenue for breaches of Article 15(1) and Article 28-8(1), and Article 64-2(3) excludes revenue unrelated to the violation from the base. The linked text is the version in force from September 11, 2026; in the version in force when the PIPC decided in July 2026, the same exclusion was paragraph (2). A PIPC official told Asia Economy (press) that the TikTok fine is relatively large because "revenue from targeted advertising using user behavioral information is large" and that the penalty "was calculated on the basis of the related revenue". The release gives no revenue figure and no detail of the corrective order; the written decision (의결서) was not found on the PIPC site on October 3, 2026.

Has TikTok challenged the PIPC decision?

On July 23, 2026, a TikTok representative told Asia Economy that TikTok "considers the protection of users' personal information and information security among its most important values and is doing its best to comply with Korea's relevant laws and regulations", and that it "will state its position after receiving the written decision and fully reviewing its contents".

Korean press searches on October 3, 2026 returned no report of an administrative lawsuit by TikTok against the decision. Korean court records were not searched for this post.

How does the TikTok decision relate to the 2022 Google and Meta fines?

The PIPC applied the same theory of "third-party behavioral information" in September 2022, when it fined Google KRW 69.2 billion and Meta KRW 30.8 billion. In the PIPC's briefing of September 14, 2022, its director general for investigation called it the first sanction on behavioral information collection by targeted-advertising platforms, and said the investigation examined whether platforms had lawful consent to collect what their members did on other websites and apps. The briefing states that 82% of Korean Google users, and 98% or more of Korean Meta users, had settings that allowed the collection.

Yonhap (press) reported that the first-instance court dismissed both companies' challenges in January 2025, finding that they "did not obtain meaningful consent under the Personal Information Protection Act" to collect third-party behavioral information. Law Times (press) reported on September 5, 2026 that both appeals are pending at the Seoul High Court: Google's as case 2025누5923 and Meta's as case 2025누6020, with a Meta hearing set for October 15, 2026. Law Times reports Meta's argument that "the operators of those websites and apps are the entities collecting the personal information" and that users were informed through its privacy policy.

That argument bears on the TikTok case. The PIPC's 2026 release treats TikTok as the collector of data gathered by its Pixel and Events SDK inside other companies' sites and apps. How the Seoul High Court rules on who collects the data in the Meta appeal is open as of October 3, 2026.

What does the TikTok Events SDK source show?

TikTok publishes the Events SDK, which it calls the TikTok App Events SDK, on GitHub for Android and iOS. The README states that the SDK lets an app "transmit app events, such as Installs, Add to Cart, or Purchases, directly from your mobile app to TikTok", where they are used to "create audiences for targeting". In the current releases (Android 1.7.1 of September 1, 2026; iOS 1.7.2 of August 28, 2026):

These are the August and September 2026 releases; the PIPC counts users as of December 2025, and the release names no SDK version.

What can a scan and a traffic capture show for an app with the TikTok Events SDK?

The PIPC decision covers collection inside third-party apps, linking to TikTok accounts, and consent at TikTok sign-up. A device capture of a third-party app documents the collection; the account linking happens on TikTok's servers, outside what a capture on a phone records.

When I scan an Android app, the static report lists the URL hosts written in the app package, with the file and line for each. A host in the package establishes presence in the build; only a capture shows that data was sent. A traffic capture on a test device records each request the app sends, the host that receives it, whether the device's own GAID value appears in the body, headers or query string, and whether the request was sent before or after the app's consent screen. What a scan checks and the limits of a scan are on the methodology page. A capture records one app on one device on one date; what TikTok does with an event after receipt is outside it.

Related posts: Brazil's ANPD fine against TikTok over children's data, where the ANPD's vote lists GAID and IDFA among the identifiers in a data inventory of TikTok's logged-out feed, and the FTC's Hims & Hers complaint, which names TikTok among the website pixels on Hims' site.

I run these SDK investigations for lawyers and for researchers working with lawyers, on one app or on a list of apps in bulk. Sign up for a CanITrustThat account to run your own research, let us run an investigation for you, or browse the scanned apps.

App privacy law, applied to real apps.

Posts on new laws, fines and studies, and teardowns of the apps those laws apply to.

How we use your address: privacy notice. Prefer a feed reader? Use the RSS feed.