European Union regulators concluded on July 24 2026 that TikTok breached the Digital Services Act by failing to enforce adequate privacy defaults for users under 16 and exposing minors to safety risks. The finding follows a formal investigation into how the platform sets account visibility for young people and how much of their content remains accessible to adults and to users without TikTok accounts. The decision marks a significant test of the bloc authority to enforce child safety obligations on global social media companies and sets the stage for possible fines or remedial orders if TikTok does not bring its systems into compliance.
What the investigation found and why it matters
The European Commission determined that TikTok privacy settings left minors accounts and content too widely visible. In practice that meant an adult could view a young users profile and posts even when the account was set to private. Profile photographs remained public and minors could still be discovered through other users follower and following lists. Some content posted by minors remained accessible outside the platform or was promoted through the For You feed. The Commission said these gaps contravened Article 28 1 of the Digital Services Act which requires platforms accessible to minors to provide a high level of privacy safety and security.
The stakes are not abstract. When a child can be contacted by strangers or when their images and videos circulate beyond their intended audience the risks include cyberbullying unwanted contact and predatory behavior. Content posted in adolescence can persist into adulthood and affect education employment and personal relationships. The Commission findings focus on the design choices that make those outcomes more likely. Default settings matter because most users never change them. If the default leaves a young person exposed the system fails the test of safety by design.
How the Digital Services Act sets the rules for online safety
The Digital Services Act establishes a tiered framework of obligations for online platforms based on size and reach. Very large online platforms and very large online search engines face the strictest duties including risk assessments independent audits and specific protections for minors. The law requires that platforms accessible to children must configure services so that privacy safety and security are the default. It also demands that content from minors should not be accessible outside the platform or promoted in ways that amplify exposure to unknown audiences.
Enforcement is centralized for the largest platforms. The European Commission can open formal proceedings issue preliminary findings and if necessary adopt a non compliance decision. Penalties can reach up to six percent of global annual turnover. The Commission can also impose interim measures to stop ongoing harm while a case is resolved. The goal is to move beyond voluntary promises and toward binding obligations that are backed by credible sanctions.
What changes TikTok must make to comply
The Commission said TikTok should make minors content visible by default only to users they have accepted. That means shifting the default from public or semi public visibility to a closed circle of approved followers. The platform should also ensure that content from minors is not accessible outside the platform or promoted through the For You feed in ways that expose it to unknown audiences. Profile photographs and other metadata that can identify a young user should be hidden from public view by default.
Age assurance and verification mechanisms will need to be robust enough to ensure that under 16 users receive the enhanced protections. The Commission has not prescribed a single technical solution but it has made clear that self declaration without corroboration is insufficient where it leaves minors exposed. The changes must be implemented across the European Union and must be durable. A temporary toggle that can be switched off does not meet the requirement for safety by design.
Why default settings are the frontline of child safety
Defaults shape behavior. Most users accept the configuration they see when they create an account. For young people who may not fully understand the long term consequences of sharing personal content the default is a safeguard. When the default is open the burden falls on the child and their family to find and change complex settings. When the default is closed the burden shifts to the platform to justify any expansion of visibility and to obtain meaningful consent where appropriate.
This approach aligns with broader child protection principles that treat children as a vulnerable group entitled to special safeguards. It does not ban social media for minors. It requires that the terms of participation are safe from the outset. The lesson from years of online harm cases is clear. Relying on after the fact reporting and takedown is too slow. Prevention through design is the only strategy that scales.
What comes next in the enforcement process
TikTok can now respond to the preliminary findings and propose remedial measures. The Commission will review the response and decide whether the proposed changes are sufficient to bring the platform into compliance. If the Commission is not satisfied it can issue a non compliance decision and open the door to fines. The maximum penalty under the Digital Services Act is six percent of global annual turnover. The Commission can also order specific actions such as changing default settings within a defined timeline and subject to independent audit.
Parallel proceedings continue in other areas. Ireland Data Protection Commission has examined TikTok handling of children data and cross border transfers. Past fines under the GDPR have reached hundreds of millions of euros. The European Court of Justice is also considering challenges to TikTok designation as a gatekeeper under the Digital Markets Act. The cumulative effect is a web of obligations that will determine how the platform operates in Europe for years to come.
How parents and young users can protect themselves now
While the regulatory process unfolds families can take practical steps to reduce risk. Review privacy settings on any account used by a minor and set the account to private. Disable public visibility of profile photographs and biographical details. Turn off location tagging and restrict who can comment or send messages. Use the platforms reporting tools to flag unwanted contact or abusive content. Teach young users not to accept follow requests from strangers and to avoid sharing identifiable information such as school names or home addresses.
Parents should also consider the broader digital footprint. Content posted in childhood can be downloaded reshared and resurfaced years later. The safest approach is to limit the amount of personal content that is posted at all and to assume that anything that appears online could become permanent. Schools and youth organizations can support this effort by providing clear guidance on safe sharing and by modeling good practices in their own communications.
Broader implications for the social media industry
The TikTok decision is a signal to the entire industry. The European Union has made clear that child safety is not optional and that compliance will be measured against the design of the service not just the policies on paper. Other platforms that host minors will need to review their default settings age assurance mechanisms and content amplification systems. The cost of non compliance is rising. Fines reputation damage and operational restrictions are real business risks.
For regulators the challenge is to sustain momentum. Investigations must be timely. Remedies must be specific and enforceable. And the public must be able to see whether platforms are meeting their obligations. The European Commission maintains a transparency center that publishes decisions and compliance reports. Researchers and civil society groups play a vital role in testing whether changes on paper translate into safer experiences for young users.
Where to follow developments and find guidance
The European Commission press release and the Digital Services Act portal provide the official record of the case and the legal framework behind it. The Irish Data Protection Commission website offers guidance on children data protection and cross border transfers under the GDPR. For parents and educators the safer internet programs run by national governments and by the EU provide practical toolkits on privacy settings reporting tools and digital literacy.
This case will be watched closely by policymakers in other regions who are considering similar rules for online safety. The outcome will shape the standards that global platforms apply and the expectations that families bring to the digital spaces where children learn play and socialize. The core question is simple. Are the defaults set to protect the most vulnerable. The European Union has answered that question with a clear demand. If the answer is no the system must change.

