Preliminary findings released by the European Commission on July 24 allege that TikTok has failed to meet the European Union’s legally mandated standards for protecting minors’ accounts and privacy under the Digital Services Act (DSA).
EU officials said the platform’s default settings and account-design weaknesses are exposing minors to cyberbullying, unwanted contact, and potential online predators. If the allegations are ultimately confirmed, TikTok could face a fine of up to six percent of its global annual revenue.
EU identifies three major flaws in TikTok’s account design
According to the European Commission’s investigation, which lasted more than two years, TikTok has significant product-design flaws in the way it protects children’s privacy:
- Public accounts are easy to enable: Underage users can easily set their accounts to “public,” meaning anyone online—including strangers who do not have TikTok accounts—can view the content they post.
- Algorithmic distribution to strangers: Content posted by users aged 16 and 17 can be automatically recommended to strangers around the world through TikTok’s “For You” feed, potentially extending beyond the platform itself.
- Private accounts remain exposed: Even when minors set their accounts to “private,” other users—including people who are not registered with TikTok—can still easily find the accounts through “Following” and “Followers” lists. Their profiles and profile pictures also remain accessible to anyone.
“Children’s content must never be visible to strangers,” European Commission spokesperson Thomas Regnier said, according to the Associated Press.
He emphasized that platform safety settings must provide genuinely effective, high-standard protections by default.

Success
You are now signed up for our newsletter
Success
Check your email to complete sign up
TikTok faces fourth set of DSA allegations
The preliminary finding concerning the safety of minors’ accounts represents the fourth set of allegations brought against TikTok since the EU formally launched its DSA compliance investigation into the platform in February 2024.
The EU has previously raised concerns about potentially addictive elements of TikTok’s algorithmic design, including infinite scrolling and autoplay, warning that such features could harm users’ mental health.
In response, TikTok issued a statement saying it would carefully review the EU’s preliminary findings.
“Protecting minors online is a goal we share, and we are committed to building on our strong track record of continuous improvement,” TikTok said. The company added that it would review the findings and “continue to engage constructively with the Commission.”
RELATED:
- Concerns Grow That TikTok and Xiaohongshu Could Shape Taiwanese Perceptions of the CCP
- TikTok’s Restructuring Opens a Window for Human Rights Content
No final decision
According to the Associated Press, the European Commission stressed that the preliminary report does not represent a final decision. The commission will next consult the European Board for Digital Services, while TikTok will have the right to submit a written response within a specified period.
Should the commission ultimately determine that TikTok violated the law, it will assess the seriousness, recurrence, and duration of the violations before imposing penalties.
The EU’s latest action against TikTok comes as European authorities move to tighten online safety rules for children and teenagers.
Just days earlier, the French parliament formally approved landmark legislation that will strictly prohibit children under the age of 15 from registering for social media platforms beginning in September. Existing accounts belonging to children will also be gradually deactivated.
European Commission President Ursula von der Leyen has recently issued a series of strongly worded statements, reiterating that “social media is not a toy” and arguing that developers must bear full responsibility for ensuring their products are safe for children.
Market analysts say the EU’s latest action signals that major technology platforms will face increasingly stringent “privacy by default” product-design requirements in Europe.