No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Data Privacy

What Oracle’s TikTok Dance Can Teach Everyone About Good Data Governance

Four core principles — data knowledge, systems assessment, continuous testing and empowered accountability — emerge from stewardship role

by Rita W. Garry
February 4, 2026
in Data Privacy, Featured
tiktok on phone screen

Many US companies still resist recognizing data governance and structured management as a value center, but the regulatory and technological landscape increasingly demands organizational discipline around digital assets. Howard & Howard’s Rita W. Garry uses Oracle’s mandate for the newly restructured US TikTok — storing 150 million users’ data, retraining the algorithm without Chinese interference and maintaining secure gateways for global interoperability — to map fair information practices applicable across industries, from establishing data governance councils to vetting vendor integrity to creating empowered roles that measure digital asset value financially, reputationally and regulatorily. 

As of Jan. 22, TikTok is under new ownership — tech giant Oracle and investment firms Silver Lake and MGX now own a supermajority of TikTok USDS Joint Venture LLC, better known as US TikTok, with an estimated valuation of $14 billion. 

Oracle has received a copy of the TikTok algorithm and US users’ data — an estimated 150 million of them — to “re-train” the algorithm on this data without interference from the Chinese ByteDance owner, which is a 19.9% owner of the new US TikTok organization. 

Oracle is the “trusted security partner” with a 15% ownership stake in the US TikTo. The data governance implications of this transition speak not only to TikTok’s unique position as a social media platform originally owned in China but the ever-increasing expanse of data in the world. (TikTok recently settled a social media addiction lawsuit.)

Oracle’s mandates for the US version of the app include: 

Data sovereignty and hosting

  • Exclusive hosting: Oracle will store all sensitive US user data within its secure Oracle Cloud infrastructure in the US.
  • Access controls: Oracle is responsible for establishing and maintaining firewalls to ensure that ByteDance employees in China cannot access US use information.

Algorithm oversight and retraining

  • Independent algorithm: Because Chinese law prohibits the outright sale of the algorithm, the US joint venture will lease a copy. Oracle will oversee the “retraining” of this algorithm from the ground up using only US data.
  • Integrity monitoring: Oracle will continuously audit the recommendation engine to ensure the content feed is free from outside manipulation or foreign influence.
  • Source code review: In partnership with the US government, Oracle will inspect the app’s source code for backdoors or unauthorized access points.

Compliance and auditing

  • Validation: Oracle is tasked with auditing and validating that the new US entity complies with all national security terms set by the US government.
  • Secure gateways: Oracle will build and manage secure gateways that allow US users to remain globally interoperable (interacting with international users) while keeping domestic data isolated.

Financial and strategic interest

  • Revenue impact: TikTok is one of Oracle’s largest cloud customers, contributing an estimated $800 million in revenue for fiscal year 2025.
  • Board representation: While not managing daily social media operations, Oracle’s involvement supports the new seven-member board, which will be 85% American-controlled.
small child using smartphone
Data Privacy

The US Is Not Alone in Regulating Children’s Data Privacy. Here’s a Primer on the Global State of Play.

by Ceren Canal Aruoba
February 2, 2026

Emerging policies extend beyond data privacy into product governance and algorithmic accountability

Read moreDetails

Data governance roadmap

Oracle’s mandate as the US TikTok data steward provides a basic roadmap for other organizations looking to build their own data governance programs. This is especially relevant as legal requirements, regulatory scrutiny and technological advances are all increasing at a rapid rate.

With 20 US states’ having passed comprehensive consumer privacy and data protection laws and over 100 new laws and regulations focused on AI systems and services, compliance is becoming increasingly chaotic, and the ever-growing volume of data that organizations collect, use, share and store requires decisive efforts in data governance and privacy.

Oracle’s obligations to US TikTok trace fair information practices and principles, which can benefit all organizations in building their data governance and compliance projects and programs, including:

Data knowledge

To exercise sovereignty over digital assets you must know what assets you have, where they are located and who has access to them. Set up a data governance council (DGC) to map data inflows/outflows and classify data into governance schemas, such as operational and/or marketing data, personal information, human resources data and confidential data.

All systems assessments

Every system, both internally and externally sourced, must be inventoried and provenance established to determine how they all interact. Unknown or rogue AI systems pose significant regulatory risks. All vendors must be rigorously vetted to verify integrity and outcomes. Identify all first- and third-party data connections, vet the vendors exposed to data classification type, bind internal/external PI vendors to data protection agreements. Keep a human in the loop of decision-making software and, if AI is involved, voluntarily disclose that fact to the end users.

Test, test and retest

Data management compliance is a relentless process requiring frequent and recurring examinations. Conduct routine audits of all systems to detect gaps in functionality, transparency and risk/response capabilities.

Accountability

To receive the true benefit from digital assets management programs, someone needs to be empowered to measure and report on the value impact of managed digital assets financially, reputationally and risk regulatorily. Set up a data governance czar with autonomy to report to C-suite executives and board committees committed to data value and integrity.

While these principles and practical guidance may seem simplistic, many US companies are still resisting the reality and importance of data governance and structured management as a value center. In many ways, the regulatory environment, whether international, national or local, does not matter. Rather, the value realized through organizational discipline and honored digital asset governance systems comes from knowing the organization is a good steward of personal data that consumers can trust. 

When this is established, it positions the organization to mitigate and defend against regulatory, cybersecurity and litigation risks, as well as lessen compliance chaos and avoid digital entropy.


Tags: Artificial Intelligence (AI)Data Governance
Previous Post

With Executives Becoming the Targets of Digital Anger, True Protection Begins Online, Long Before the Guards & Gates

Next Post

What DOJ’s Highest-Ever FCA Recoveries Signal for Cybersecurity, Customs and DEI Enforcement

Rita W. Garry

Rita W. Garry

Rita W. Garry, CIPP/US, is an attorney at Howard & Howard in Chicago. She is a seasoned corporate, transactional, AI and data privacy attorney with experience across an array of industries, including professional services, banking and finance, healthcare, manufacturing, technology and aviation supply.

Related Posts

news roundup bundled papers

Almost 40% of US Workers Have Witnessed Harassment in the Past 5 Years

by Staff and Wire Reports
February 5, 2026

Board-GC communication frequency doesn’t match organizational objectives

small child using smartphone

The US Is Not Alone in Regulating Children’s Data Privacy. Here’s a Primer on the Global State of Play.

by Ceren Canal Aruoba
February 2, 2026

Emerging policies extend beyond data privacy into product governance and algorithmic accountability

federal trade commission building sign

What Recent FTC Enforcement Actions Reveal About COPPA Risks

by Stacey Brandenburg and Yiannis Vandris
February 2, 2026

Companies need to evaluate whether they have actual knowledge of users younger than 13

pentagon aerial view

CMMC Phase One Reality Check: Documentation Alone Won’t Pass Muster

by Marci Womack
January 29, 2026

With Phase Two enforcement approaching in November 2026, early preparation matters in a market where assessment capacity has become limited

Next Post
doj building sign

What DOJ’s Highest-Ever FCA Recoveries Signal for Cybersecurity, Customs and DEI Enforcement

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2026 Corporate Compliance Insights