On July 24, 2026, the European Commission sent TikTok preliminary findings concluding that the accounts of its minor users do not meet the safety standards required under the Digital Services Act. The finding centers on a design choice, not a data breach or a leaked database: TikTok lets minors set their account to "public," and once they do, anyone can see their content, including people who have never created a TikTok account at all.

This is a Digital Services Act enforcement action, not a GDPR one, which puts it in different legal territory than most of the EU privacy fines that make headlines. The DSA regulates platform design and risk management, and Article 28(1) specifically requires that any service accessible to minors provide a high level of privacy, safety, and security for them. The Commission's preliminary view is that TikTok's account defaults fail that bar.

ByteDance, TikTok's parent company, now faces a potential fine of up to 6 percent of its global annual turnover if the Commission confirms these findings in a final non-compliance decision. TikTok has the right to examine the Commission's evidence and respond in writing before that happens, and the European Board for Digital Services will be consulted along the way.

European Commission press release dated July 24, 2026 announcing the preliminary finding that TikTok breaches the Digital Services Act by failing to ensure safe accounts for minors

Source: European Commission, Press corner, captured August 4, 2026.

What the Commission actually found

The preliminary findings describe three separate gaps in how TikTok handles minor accounts, and none of them require a security flaw or a hack to matter. According to the Commission's own announcement, 13- to 15-year-olds start with a private account by default but can switch it to public with little friction, while 16- and 17-year-olds can choose a public setting from the start. Once an account is public, its content is visible to anyone, TikTok user or not.

The second gap sits inside the app itself. Content posted by 16- and 17-year-olds can be surfaced to other users through TikTok's "For You" recommendation feed, which means a public minor account is not just passively viewable, it can be actively pushed in front of strangers by the platform's own recommendation system. The third gap affects accounts that are already set to private: follower and following lists, along with profile photos, remain visible to the public even when the rest of the account is locked down.

The Commission frames the combined effect as leaving minors exposed to unwanted contact, cyberbullying, and predatory behavior, and its preliminary view is that TikTok should flip the defaults, making a minor's content visible only to people that minor has actively accepted as followers, with no recommendation into the "For You" feed and no access from outside the platform. Executive Vice-President Henna Virkkunen, who oversees DSA enforcement, put the underlying principle bluntly in the Commission's statement: "A high level of protection should not be an opt-in; it should be the default."

Current defaults versus what the Commission wants

SettingTikTok's current defaultWhat the Commission's finding calls for
Account visibility, ages 13-15Private by default, easy to switch to publicPrivate, with no low-friction path to public
Account visibility, ages 16-17Can choose public from account creationVisible only to accepted followers by default
"For You" feed recommendationMinors' content can be recommended to any userNo recommendation of minors' content into the feed
Follower/following lists on private accountsVisible to anyone on the internetVisible only to the account's accepted followers
Profile photo on private accountsVisible to anyone on the internetRestricted along with the rest of the private account

What happens next

A preliminary finding is not a final ruling and carries no fine on its own. TikTok can review the Commission's evidence file and submit a written defense, and the Commission will consult the European Board for Digital Services before it decides whether to issue a formal non-compliance decision. Only a confirmed non-compliance decision opens the door to a fine, which under the DSA can reach 6 percent of ByteDance's global annual turnover, plus the possibility of periodic penalty payments if TikTok does not comply with any corrective measures the Commission orders.

There is no public deadline yet for when that final decision will land, and TikTok had not issued a public response to the preliminary findings as of this writing. Worth noting for context: this is a separate proceeding from the EU's ongoing scrutiny of TikTok under the DSA's addictive-design and recommender-system risk provisions, and separate again from the EDPB's coordinated GDPR transparency work. It is its own action, built specifically around Article 28(1) and the default settings applied to minor accounts.

What this means for your privacy policy

Almost no small or midsize site operator runs anything like TikTok's scale, and the DSA's strictest obligations apply only to platforms the Commission designates as Very Large Online Platforms. But the underlying principle the Commission is enforcing, that protective settings for minors should be the default rather than something a young user has to find and turn on, is not a TikTok-specific rule. It is the same design logic behind COPPA in the US, the UK's Age Appropriate Design Code, and the "children's data" provisions that already sit inside most state privacy laws and the GDPR itself.

If your site or app collects data from users who could be minors, whether that is an account-creation flow, a comment section, or a newsletter signup with no age gate at all, your privacy policy needs to say plainly what your default settings are for that group, not just what a user could theoretically change if they went looking. A generic line promising "special protections for children" without describing what the default actually is leaves the same gap the Commission just flagged in TikTok's policy: a protection that exists on paper but not in the account settings a young user actually gets on day one.

TikTok risks a fine of up to 6 percent of global turnover over minor account defaults 6% of global annual turnover is themax DSA fine TikTok now risks

Figure: The maximum fine ByteDance risks under the DSA if the Commission's preliminary findings are confirmed.

Bottom line

The Commission's action against TikTok is a reminder that regulators increasingly read a privacy policy's promises against a product's actual default settings, not just its written disclosures. If your business handles any data from users under 18, whether or not you operate at a scale that would ever draw DSA scrutiny, your privacy policy should describe your real default settings for that group in plain language, not a boilerplate children's-privacy paragraph copied from a template that does not match what your product actually does. Our Privacy Policy Generator builds minors' data handling and default-settings disclosures that reflect what your product actually ships, rather than a generic clause that would not survive the kind of scrutiny TikTok's account defaults just got.

The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.