TikTok Says Some China-Based Employees Can Access U.S. User Data, Outlines Plan for Better Safeguards

TikTok is working on a plan to better safeguard the data of its U.S. users, the company said in an open letter [PDF] to several U.S. Senators that have expressed concern that the China-based app is a national security risk.

tiktok logo
Shared by The New York Times, the letter outlines a multi-pronged undertaking called "Project Texas," aimed at strengthening data security. TikTok says that 100 percent of U.S. user data is stored in an Oracle cloud environment located in the U.S., and it is working with Oracle on more advanced data security controls that will be finalized "in the near future."

TikTok is planning to delete U.S. data from its servers and store information with Oracle exclusively. The company says all data sharing outside of the United States will be pursuant to "protocols and terms approved by the U.S. government."

The broad goal for Project Texas is to help build trust with users and key stakeholders by improving our systems and controls, but it is also to make substantive progress toward compliance with a final agreement with the U.S. Government that will fully safeguard user data and U.S. national security interests. We have not spoken publicly about these plans out of respect for the confidentiality of the engagement with the U.S. Government, but circumstances now require that we share some of that information publicly to clear up the errors and misconceptions in the article and some ongoing concerns related to other aspects of our business.

Concerns over TikTok have heightened over the last two weeks following a BuzzFeed News report that suggested TikTok engineers in China had access to the data of U.S. users between September 2021 and January 2022. "Everything is seen in China," said one TikTok employee in recordings reviewed by BuzzFeed, with the recordings also referencing a "Master Admin" engineer in China who "has access to everything."

Given the concerns over U.S. data access, the United States Federal Communications Commission earlier this week asked Apple and Google to remove TikTok from their app stores because of a "pattern of surreptitious data practices."

TikTok in its letter confirmed that some China-based employees are indeed able to access data from U.S. TikTok users, "subject to a series of robust cybersecurity controls" overseen by a U.S.-based security team. TikTok says that it has an internal data classification system and approval process in place that assign levels of access based on the sensitivity of the data. It will work with the Biden Administration going forward to continue to limit data access.

In response to a question on why TikTok does not plan to block all U.S. user data from the view of employees in China, TikTok said that "certain China-based employees will have access to a narrow, non-sensitive set of TikTok U.S. user data" in order to ensure global interoperability. Employees will also be able to develop the TikTok video recommendation algorithm using U.S. data, though training of the algorithm will be limited to Oracle's servers.

TikTok promises that access will be "very limited" and will not include "private TikTok U.S. user information." TikTok says that it has not been asked to provide data to the Chinese government, and would not provide data if the CCP requested information.

Apple and Google have not as of yet responded to the FCC's request to remove the TikTok app from their app stores.

Note: Due to the political or social nature of the discussion regarding this topic, the discussion thread is located in our Political News forum. All forum members and site visitors are welcome to read and follow the thread, but posting is limited to forum members with at least 100 posts.

Tag: TikTok

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Rumored to Use Same Rear Chassis as iPhone 16

Friday July 19, 2024 7:16 am PDT by
Apple will adopt the same rear chassis manufacturing process for the iPhone SE 4 that it is using for the upcoming standard iPhone 16, claims a new rumor coming out of China. According to the Weibo-based leaker "Fixed Focus Digital," the backplate manufacturing process for the iPhone SE 4 is "exactly the same" as the standard model in Apple's upcoming iPhone 16 lineup, which is expected to...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Just Two Months Away: Everything We Know

Monday July 15, 2024 4:44 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
iphone 14 lineup

Cellebrite Unable to Unlock iPhones on iOS 17.4 or Later, Leak Reveals

Thursday July 18, 2024 4:18 am PDT by
Israel-based mobile forensics company Cellebrite is unable to unlock iPhones running iOS 17.4 or later, according to leaked documents verified by 404 Media. The documents provide a rare glimpse into the capabilities of the company's mobile forensics tools and highlight the ongoing security improvements in Apple's latest devices. The leaked "Cellebrite iOS Support Matrix" obtained by 404 Media...
tinypod apple watch

TinyPod Turns Your Apple Watch Into an iPod

Wednesday July 17, 2024 3:18 pm PDT by
If you have an old Apple Watch and you're not sure what to do with it, a new product called TinyPod might be the answer. Priced at $79, the TinyPod is a silicone case with a built-in scroll wheel that houses the Apple Watch chassis. When an Apple Watch is placed inside the TinyPod, the click wheel on the case is able to be used to scroll through the Apple Watch interface. The feature works...
bsod

Crowdstrike Says Global IT Outage Impacting Windows PCs, But Mac and Linux Hosts Not Affected

Friday July 19, 2024 3:12 am PDT by
A widespread system failure is currently affecting numerous Windows devices globally, causing critical boot failures across various industries, including banks, rail networks, airlines, retailers, broadcasters, healthcare, and many more sectors. The issue, manifesting as a Blue Screen of Death (BSOD), is preventing computers from starting up properly and forcing them into continuous recovery...
New MacBook Pros Launching Tomorrow With These 4 New Features 2

M5 MacBook Models to Use New Compact Camera Module in 2025

Wednesday July 17, 2024 2:58 am PDT by
Apple in 2025 will take on a new compact camera module (CCM) supplier for future MacBook models powered by its next-generation M5 chip, according to Apple analyst Ming-Chi Kuo. Writing in his latest investor note on unny-opticals-2025-business-momentum-to-benefit-509819818c2a">Medium, Kuo said Apple will turn to Sunny Optical for the CCM in its M5 MacBooks. The Chinese optical lens company...

Top Rated Comments

Think|Different Avatar
27 months ago
Nope. You simply cannot trust them.
Score: 52 Votes (Like | Disagree)
Villarrealadrian Avatar
27 months ago
Get it off the stores already!
Score: 34 Votes (Like | Disagree)
antiprotest Avatar
27 months ago

TikTok says that it has not been asked to provide data to the Chinese government, and would not provide data if the CCP requested information.
Wait, really? Even Apple would comply like a good little ?.
Score: 20 Votes (Like | Disagree)
Hastings101 Avatar
27 months ago
Should have let Trump ban it. Add it to the list of national security concerns like ZTE, Huawei, and all the others
Score: 17 Votes (Like | Disagree)
jz0309 Avatar
27 months ago
what a surprise ...
Score: 17 Votes (Like | Disagree)
kesenwangs Avatar
27 months ago

That's not true.

Apple is adhering to local laws in terms of hosting Chinese data within China, but that's not the same thing as just freely handing over data at CCP's request.
This response is also simply not true. Apple has previously removed encryption technology ('https://www.nytimes.com/2021/05/17/technology/apple-china-censorship-data.amp.html') used elsewhere because it wouldn’t be allowed in China, so there’s not really a need to “freely hand over data” at the CCP’s request anyways. No business entity has a choice in this matter.
Score: 16 Votes (Like | Disagree)