Sources and documents: TikTok employees have regularly posted user data on messaging tool Lark, used by ByteDance, leading some staff to raise privacy concerns
Employees of the Chinese-owned video app have regularly posted user information on a messaging and collaboration tool called Lark, according to internal documents. Tweets: @sapna , @sapna , @sapna , and @rmac18 Tweets: Sapna Maheshwari / @sapna : NEW: Since at least July 2021, security employees at TikTok have been warning ByteDance and TikTok execs about risks tied to Lark — its version of Slack — and how employees were using it to share and store sensitive data from TikTok users https://www.nytimes.com/... with @RMac18 Sapna Maheshwari / @sapna : Internal documents show that American driver's licenses, passports & potentially illegal content like child sexual abuse materials were among materials shared in Lark groups, which were basically chat rooms that often had 1,000+ people in them, including China-based employees Sapna Maheshwari / @sapna : Current & former employees said Lark data from TikTok was stored on servers in China as of last year. We reviewed dozens of screenshots of reports, chat messages & employee comments on Lark, plus video and audio of internal comms, spanning 2019 to 2022 https://www.nytimes.com/... Ryan Mac / @rmac18 : Internal docs from TikTok show employees have been sharing private user data — from driver's licenses to locations — in Lark, a workplace collab tool, that was accessed by China-based workers of its parent company Bytedance. (w/ @sapna) https://www.nytimes.com/... Expand More For Next Unexpand More For Next
Context & Ripple Effects
This report extends a documented arc of concern over ByteDance personnel’s access to TikTok information: leaked internal-meeting audio had already indicated China-based ByteDance staff accessed US user data. The issue here is not only who could reach the data, but how ordinary collaboration workflows could distribute it.
It also sits alongside reports that TikTok maintained sensitive audience-data tools, including a dashboard for users who watched LGBTQ content. Together, the coverage puts internal data handling—not just external collection—at the center of TikTok’s privacy exposure.
First-order effects
- TikTok and ByteDance face an immediate internal-control problem: sensitive user materials reportedly circulated in Lark groups with access extending to ByteDance staff, increasing the number of people and systems involved in handling them.
- Employees who need user data for operational or safety work may face tighter rules on what can be posted in collaboration tools, where it is retained, and who can view it.
Second-order effects
- Any privacy assurances based on formal access channels become harder to validate if staff can use workplace messaging as an alternate route for sensitive data; that concern later resurfaced in reports of Project Texas data being sent outside official channels.
- The case raises the compliance burden for companies whose collaboration platforms span jurisdictions: permissions, retention, and audit logs in internal messaging become as consequential as production databases.
Third-order effects
- If similar workflow gaps persist, data-localization and access-separation commitments will be judged by day-to-day employee behavior and enforceable technical controls, rather than by organizational boundaries alone.
- The broader structural pressure is toward privacy programs that treat internal collaboration systems as regulated data environments, with durable controls over sharing, storage, and cross-border access.
The trend: This is one data point in the shift from scrutinizing consumer apps’ data collection to scrutinizing the internal workflows that move sensitive data across corporate boundaries.