Commission Challenges TikTok’s Privacy Protections for Minors
On 24 July, the European Commission issued preliminary findings that TikTok may have breached the Digital Services Act (DSA) by failing to provide effective privacy protections for minors by default. The assessment focuses on the practical effect of TikTok’s account settings, rather than the number of safety tools available somewhere within the service.
According to the Commission, users aged 13 to 15 could make their accounts public with limited friction, while accounts of users aged 16 and 17 could be visible to anyone online, including people without a TikTok account. The Commission considers that this exposure can increase risks of unwanted contact, cyberbullying, and predatory behavior.
The case is legally significant because Article 28 DSA requires online platforms accessible to minors to ensure “a high level of privacy, safety, and security of minors.” For very large online platforms such as TikTok, those obligations also sit alongside the systemic-risk framework in Articles 34 and 35 DSA. The Commission’s position appears to be that a privacy setting is not an effective child-safety measure if a young user can readily disable it and become visible to unknown users.
The findings remain preliminary. TikTok may inspect the Commission’s file and submit written observations before the Commission adopts any final non-compliance decision. If the alleged breach is confirmed, the Commission may require corrective measures and impose fines of up to 6% of ByteDance’s total worldwide annual turnover. It may also impose periodic penalty payments to secure compliance.
TikTok disputes the Commission’s assessment and has referred to its preset teen-account privacy and safety features. The proceeding forms part of the wider DSA investigation opened against TikTok in February 2024 and follows other Commission scrutiny concerning potentially addictive design features. It also confirms a broader enforcement direction: for minors’ privacy, the Commission is assessing whether safeguards work by default in real use, not merely whether they are technically available.