The European Commission has found TikTok inadequate in protecting young users, alleging that the platform's standard configuration exposes minors to predatory behaviour and online harassment. In a statement released on July 24, European regulators highlighted a critical vulnerability: children can maintain public profiles viewable to anyone on the internet, regardless of whether those viewers hold TikTok accounts themselves. This broad visibility creates circumstances where unknown individuals may initiate contact with minors or harvest content for malicious purposes including cyberbullying campaigns.
Beyond account visibility, the commission criticised TikTok's algorithmic recommendation system for actively promoting content created by teenagers aged 16 and 17 to other users. This automated amplification of teen-generated material compounds the exposure problem, potentially reaching audiences far beyond intended connections. Additionally, the regulator identified that private accounts set by young users remain discoverable through the platform's search and suggestion mechanisms, undermining the intended privacy protections that many parents and guardians believe they have activated.
The Brussels-based authority asserts these design choices breach obligations under the Digital Services Act, the EU's landmark regulation establishing strict baseline protections for minor accounts. According to the commission, TikTok's current architecture fails to meet these standards by disseminating minors' accounts and associated content excessively. The regulatory language emphasises that such exposure contradicts the act's foundational principle that young people deserve enhanced safeguarding rather than merely optional privacy controls.
TikTok now enters a formal response phase, during which the Chinese-owned platform operated by ByteDance can present written arguments and evidence to challenge the commission's findings. Should the commission ultimately determine that TikTok has violated EU law, the consequences could prove substantial. The platform faces potential fines reaching six per cent of its global annual revenue, a calculation that would yield extraordinary sums given ByteDance's valuation and TikTok's commercial scale. For context, TikTok serves more than 200 million users across Europe, making it among the continent's most influential digital services, particularly commanding significant engagement among adolescents and young adults.
The commission's directive is unambiguous: TikTok must substantially restrict who can access content posted by child users and fundamentally discontinue using algorithmic promotion for material uploaded by teenagers. This represents a direct intervention into core platform mechanics rather than merely cosmetic adjustments to interface design. The regulatory approach signals Brussels's expectation that companies should embed protective architecture throughout their services rather than relegating safety features to secondary, opt-in configurations.
Henna Virkkunen, the European Commission Vice President, framed the enforcement action within a broader philosophy of digital rights for young people. She stated that minors warrant safe digital environments automatically, not through parental navigation of labyrinthine settings menus. Her comments reflect frustration that platforms have long placed responsibility for safety onto users and guardians rather than building protection into default experiences. Virkkunen emphasised that the Digital Services Act specifically mandates that platforms construct minor-protective features into service design architecture and accept accountability when implementation proves inadequate.
This regulatory push extends beyond isolated concern about TikTok. The commission previously published allegations in February that TikTok's interface design encourages addictive engagement patterns, suggesting a pattern of concern about the platform's overall approach to vulnerable users. The current child safety inquiry thus represents part of a widening examination of how ByteDance's app affects young European users across multiple dimensions, from predatory risks to psychological dependency.
The enforcement action arrives amid accelerating momentum across Europe toward age-based restrictions on social media access. France broke significant ground on July 21 when its parliament passed legislation establishing a minimum age of 15 for social media use, making it the first EU member to adopt such comprehensive national prohibition. Several other member states have similarly proposed age-based bans, indicating a shift in political appetite toward more restrictive approaches. European Commission President Ursula von der Leyen has previously endorsed such age restrictions, providing political air cover for national governments pursuing restrictive policies.
TikTok's defence emphasises the sophistication of existing safeguards. A company spokeswoman contended that teenage accounts come pre-configured with more than 50 privacy and security settings activated from account creation. She highlighted that TikTok distinguishes itself among major platforms by preventing younger teenagers from using direct messaging functionality, a feature designed to reduce one-to-one contact with unknown adults. The platform's framing suggests that adequate protections exist within its current system and that the issue involves user awareness rather than systemic inadequacy.
Yet the commission's allegations suggest that optional privacy settings and feature restrictions prove insufficient without corresponding changes to algorithmic curation and profile visibility defaults. The regulatory position implies that even sophisticated privacy controls fail when profiles remain publicly discoverable and content receives algorithmic amplification. This represents a fundamental disagreement about burden allocation: whether responsibility for protection should rest primarily on users configuring settings or on platforms designing systems where exposure is constrained by default.
The implications extend beyond TikTok or Europe. As Southeast Asian regulators increasingly scrutinise social media platforms' impact on young users, the EU's enforcement provides regulatory precedent and technical specifications for child protection standards. Malaysia, Thailand, and other regional governments monitoring child safety may reference the commission's findings when evaluating their own platform oversight approaches. The case also demonstrates how global digital services increasingly face tailored regulatory requirements across jurisdictions, forcing companies toward more stringent baseline protections to satisfy multiple regulators simultaneously.
