European regulators warn ByteDance-owned app could face penalties up to 6% of global turnover over default privacy loopholes and child safety risks.
BRUSSELS, July 27, 2026 : European Union regulators have formally notified TikTok that its privacy controls fall short of mandatory child-safety standards under the bloc’s Digital Services Act, exposing minors to cyberbullying, unwanted contact, and online predators.
The European Commission’s preliminary findings, delivered to the platform on Friday, mark a major escalation in Brussels’ regulatory oversight of global tech giants. Officials warned that default privacy configurations on the video-sharing app fail to insulate underage users from public exposure, creating structural loopholes that undermine minor protection rules.
According to EU investigators, children aged 13 to 15 can easily toggle their accounts from private to public modes. For older teenagers aged 16 and 17, default system settings permit their videos to appear in TikTok’s algorithmically driven “For You” feed, making their content accessible to any user, including adults without registered accounts.
“Children’s content must never be visible to strangers,” European Commission spokesperson Thomas Regnier said during a press briefing in Brussels. “Putting default settings for minors is not a beauty contest under the DSA. It must be effective.”
Regulators highlighted that even when underage users select private account status, key personal data remains visible. Profile photos, follower counts, and following lists remain publicly accessible, allowing third parties to track and identify minors. The Commission warned that permanent digital footprints established during adolescence carry lifelong privacy risks.
The enforcement action forms part of a broader formal probe launched against TikTok in February 2024 under Article 28(1) of the Digital Services Act (DSA). The statute mandates that Very Large Online Platforms (VLOPs) accessible to children enforce high default baselines for privacy, safety, and security. Brussels estimates that a significant portion of TikTok’s nearly 170 million European users are minors, with data showing that 7% of children aged 12 to 15 spend between four and five hours on the platform daily.
In response to the preliminary conclusions, TikTok, owned by Beijing-based ByteDance, stated that it will review the findings. “Protecting minors online is a goal we share, and we are committed to building on our strong track record of continuous improvement,” the company said, adding that it will engage constructively with European regulators.
TikTok has been granted a formal window to examine the evidence and submit written defenses. Should the European Commission determine that TikTok’s remediations are insufficient, it can issue a formal non-compliance decision. Penalties under the DSA carry fines reaching up to 6% of a parent company’s total global annual turnover, alongside legally binding operational mandates.
This privacy notification represents one pillar of Brussels’ multi-pronged scrutiny of the app. In earlier regulatory findings, European authorities called out TikTok’s “addictive design” elements—such as infinite scroll and auto-play functions—for posing risks to youth mental and physical well-being.






