惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 聂微东
GbyAI
GbyAI
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 叶小钗
A
About on SuperTechFans
M
MIT News - Artificial intelligence
宝玉的分享
宝玉的分享
雷峰网
雷峰网
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Martin Fowler
Martin Fowler
Google DeepMind News
Google DeepMind News
博客园 - Franky
B
Blog RSS Feed
Y
Y Combinator Blog
Stack Overflow Blog
Stack Overflow Blog
MongoDB | Blog
MongoDB | Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
S
SegmentFault 最新的问题
罗磊的独立博客
Apple Machine Learning Research
Apple Machine Learning Research

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
TikTok's Privacy Crisis: Unveiling Data and Security Conc...
Jessica Ryder · 2023-05-31 · via Compliance Solutions for Websites, Apps and Organizations | iubenda

In August 2021, a TikTok user from Britain reported a disturbing incident on the platform. During her livestream, a man engaged in inappropriate behavior. To address the complaint, TikTok employees used an internal tool called Lark, similar to Slack, to discuss the incident and share the user’s personal data.

Lark, which is used by thousands of employees of TikTok’s Chinese owner, ByteDance, raised concerns because it allowed access to user data, including potentially illegal content. Some TikTok employees expressed alarm about this, as employees in China and elsewhere could easily view the information.

These revelations highlight the data and privacy practices of TikTok and its close ties to ByteDance. It has faced scrutiny over security risks and connections to China. In order to continue operating in the United States, TikTok presented a plan called Project Texas, which aimed to store American user data within the country and limit access to it by ByteDance and TikTok employees outside the United States.

However, there were contradictions regarding the level of access China-based workers had to U.S. user data. TikTok’s CEO downplayed their access, but internal reports and Lark communications revealed otherwise.

TikTok responded to these findings by stating that the documents were outdated and did not reflect their current data handling practices. They claimed to be in the process of deleting pre-June 2022 U.S. user data and making changes to their data management.

The use of Lark, an internal tool used across ByteDance subsidiaries, including TikTok, highlights ByteDance’s oversight of TikTok’s processes. Lark has been used to handle individual account issues and share documents containing personal information since at least 2019.

Instances of mishandled data on Lark included sharing images of identification documents and child sexual abuse materials. TikTok acknowledged these incidents and claimed to have reviewed and addressed them while implementing new processes.

The privacy and security division of TikTok has experienced reorganizations and departures, which may have affected their focus on privacy and security initiatives. The company assured that they have multiple teams working on privacy and security and have invested significant resources in Project Texas, but no completion timeline was provided.

Once Project Texas is finished, TikTok plans to conduct communications involving U.S. user data through a separate internal collaboration tool.