The EU has levelled a serious charge at TikTok. According to preliminary findings released last week, the platform fails to protect the privacy of underage users.
Its default account settings and algorithmic recommendations clearly breach the strict minor-safety standards of the Digital Services Act, or DSA.
Public by Default and For You Become Safety Gaps
The European Commission identified two major weaknesses. First, TikTok lets underage users set their accounts to public. As a result, anyone online can easily view their content, including people who have never registered a TikTok account.
Second, the current algorithm actively works against young users. It pushes videos posted by 16- and 17-year-olds onto other users’ For You feeds.
The EU warned sharply about this exposure. Such broad reach could expose minors to unwanted contact from potential offenders, to cyberbullying, and even to predatory behaviour.
The problem persists despite privacy settings, too. Even when a minor chooses a private account, strangers can still find them through other users’ following and follower lists. Moreover, their profile photo stays fully public.
Facing Fines up to 6% of Revenue
Article 28 of the DSA sets a clear bar. Any platform accessible to minors must guarantee a high standard of privacy and safety. In the EU’s view, TikTok’s current settings overexpose minors’ accounts and content, and they fall well short of that standard.
To close these gaps, the Commission put forward several concrete recommendations.
- Adjust default privacy so that minors’ accounts default to visibility for accepted contacts only.
- Stop broad promotion, ending the random recommendation of minors’ content to a global audience beyond the platform through the For You feed.
TikTok now has the right to respond to these preliminary findings in writing. However, a final ruling of non-compliance without meaningful improvement carries a steep price. The company could face fines of up to 6% of its total annual worldwide revenue.
Addictive Algorithms Meet Minor Protection
This is not TikTok’s first European reckoning over child safety. Earlier this year, the EU opened an investigation into its addictive design, including infinite scroll, autoplay, and push notifications. The UK regulator Ofcom has likewise faulted TikTok for doing too little to keep children away from harmful content.
This time, the EU struck at two of TikTok’s proudest traffic engines: public-by-default accounts and the feed recommendation algorithm. Consequently, the action lands squarely on the core of the platform’s business model.
The challenge for TikTok is delicate. It must raise privacy protection for minors to meet the DSA’s demanding requirements, yet avoid gutting user activity and ad traffic in the process. That balance will decide whether it can operate securely in a European market of nearly 170 million users.
The stakes reach beyond one fine. Ultimately, this European test could trigger a chain reaction in how governments worldwide regulate short-video platforms.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.