What Brussels Found in TikTok’s Account Settings
The European Commission’s preliminary finding, announced on 24 July 2026, does not accuse TikTok of a data breach or a single dramatic failure. It accuses the platform of a structural design choice: how it sets, and lets users change, the default privacy of a minor’s account. According to the Commission’s own announcement, TikTok accounts belonging to minors do not meet the safety standards required under the Digital Services Act because their settings continue to expose them to risks including unwanted contact, cyberbullying, and predatory behavior.
The specifics matter. Investigators found that users aged 13 to 15 could switch their accounts from private to public with little friction, undermining the private-by-default protection those younger teens are supposed to have. For 16- and 17-year-olds, the problem is more structural: their accounts remain visible to anyone online by default, including people who are not even registered TikTok users — meaning their videos, photos, and profile information can circulate well beyond the platform’s own user base without the minor or their parents actively choosing that level of exposure.
The Commission is also concerned about how TikTok’s recommendation system interacts with those settings. Content from older minors, 16- and 17-year-olds, gets surfaced through TikTok’s “For You Feed” to all users, the algorithmic recommendation engine that drives most viewing on the app — meaning a minor’s content is not just theoretically visible to strangers, it can be actively pushed to them.
TikTok’s Response and the Compliance Path Forward
The Commission is not fining TikTok yet. A preliminary finding under the DSA gives the company the opportunity to review the Commission’s file and respond before any final non-compliance decision is issued — a procedural step distinct from a completed enforcement action. Specifically, the Commission is asking TikTok to change the default settings so that minors’ public accounts are, by default, visible only to followers the minor has actively approved, and to stop recommending minors’ content through the For You Feed to the general public.
TikTok has pushed back on the characterization while still endorsing the underlying goal. In a statement, the company said “children’s content must never be visible to strangers,” calling minor safety “a goal we share,” and pointed to more than 50 preset privacy and safety features already built into teen accounts, private-by-default settings for under-18 users, and a block on direct messaging aimed at younger teenagers. The company’s framing suggests it will argue its existing safeguards already substantially meet the DSA’s requirements, setting up a dispute over degree rather than principle.
If the preliminary finding becomes final, TikTok faces a fine of up to 6% of its worldwide annual turnover — measured against ByteDance’s global revenue as the parent company, not just TikTok’s EU business. That percentage places the case among the most consequential Digital Services Act enforcement actions to date, given how directly it targets the design of a product used by millions of minors.
Advertisement
Part of a Broader Pattern Against TikTok
This is not TikTok’s first brush with DSA enforcement over platform design. In February 2026, the Commission issued a separate preliminary finding that TikTok’s addictive design — specifically its infinite scroll, autoplay, and push notification mechanics — breached the same rulebook. TikTok contested that assessment. Taken together, the two cases show the Commission treating TikTok’s core product architecture, not just isolated moderation failures, as the target of its DSA scrutiny.
The minors’ account-safety case also arrives in a summer of intensified DSA enforcement across multiple platforms. On 20 July 2026, just four days before the TikTok finding, the Commission fined AliExpress €550 million for failing to adequately assess and mitigate risks from illegal, unsafe, or counterfeit products sold on its marketplace — the highest DSA fine issued to date at the time. The clustering of major DSA actions in a single month signals the Commission moving from the law’s early implementation phase into sustained, multi-platform enforcement, with child-safety design and marketplace risk assessment emerging as the two enforcement priorities drawing the largest penalties.
What This Means for Platforms Serving Minors
1. Treat default settings, not just available settings, as the compliance surface
The Commission’s finding does not allege TikTok lacks privacy controls for minors — it alleges the defaults are wrong and too easy to change. Any platform serving users under 18 in the EU should audit what a minor’s account looks like on day one, before any settings are touched, rather than relying on the existence of privacy options a young user may never find or use.
2. Separate recommendation-engine exposure from account-visibility settings in your risk assessment
The Commission flagged TikTok’s For You Feed distribution of minors’ content as a distinct problem from account visibility itself — meaning a technically private-by-default account can still be undermined if the recommendation system pushes that user’s content externally. Platforms with algorithmic recommendation systems should assess whether minors’ content can be surfaced to non-followers even when account-level privacy settings appear correct.
3. Document the gap between “goal we share” and measurable compliance before regulators do
TikTok’s public response emphasized shared intent and a list of existing features rather than disputing the underlying facts about default visibility. Companies in a similar position should be able to demonstrate, with data, what percentage of minor accounts are actually public under current defaults — a defense built on feature lists without usage data is unlikely to satisfy a regulator focused on real-world exposure.
4. Expect DSA minor-safety findings to move faster than the addictive-design case has
TikTok’s February 2026 addictive-design finding remains contested months later, but the July 2026 minors’-privacy finding addresses a narrower, more mechanically verifiable question — what a default setting is and who can see an account. Platforms should assume factual, settings-based DSA findings resolve faster than design-philosophy disputes, and prioritize remediation on the narrower cases first.
The Regulatory Question
TikTok’s case tests whether the DSA’s minor-protection provisions can force product-level changes as effectively as its marketplace and gatekeeper rules already have. The AliExpress fine four days earlier showed the Commission willing to levy record marketplace penalties; the TikTok finding shows it applying the same enforcement posture to a harder-to-quantify harm — not counterfeit goods with a traceable sales figure, but exposure risk to minors that depends on default settings and algorithmic distribution choices.
The outcome will also shape how the Commission’s parallel addictive-design case against TikTok gets resolved. If the minors’-account-visibility finding moves to a final decision and fine relatively quickly, it establishes that narrowly defined, settings-based DSA violations are the Commission’s fastest enforcement lane — leaving broader design disputes, like addictive scrolling mechanics, as the harder and slower fights still to come.
Frequently Asked Questions
What exactly did the European Commission find TikTok did wrong?
The Commission’s preliminary finding, announced 24 July 2026, says TikTok’s default account settings for minors fail to meet Digital Services Act safety standards: 13-15-year-olds can switch accounts from private to public with little friction, and 16-17-year-olds’ accounts remain visible by default to anyone online, including non-TikTok users, with their content also surfaced through TikTok’s For You Feed recommendation system, according to the European Commission.
Has TikTok been fined yet?
No. This is a preliminary finding, not a final decision. TikTok has the opportunity to review the Commission’s evidence file and respond before any non-compliance decision is issued. If the finding is confirmed, TikTok could face a fine of up to 6% of its worldwide annual turnover, measured against parent company ByteDance’s global revenue.
Is this related to TikTok’s other EU regulatory problems?
Yes. In February 2026, the Commission separately found that TikTok’s addictive design — infinite scroll, autoplay, and push notifications — breached the DSA, a finding TikTok has contested. The minors’-account-settings case is a distinct, later finding focused specifically on default privacy and visibility rather than addictive design mechanics.
Sources & Further Reading
- Commission Preliminary Finds TikTok in Breach of Digital Services Act for Failing to Ensure Safe Accounts for Minors — European Commission
- EU Charges TikTok With Failing to Protect Children’s Privacy Under the DSA — The Next Web
- EU Charges TikTok With Failing to Protect Children’s Privacy Under the DSA — ChinaTechNews.com
- EU Fines AliExpress €550 Million for Breaching the DSA — EUnews














