DTWdailytechwire
Tech Intelligence, Wired Daily
Policy

Brussels Tells TikTok Default Privacy for Teen Accounts Must Be Mandatory

New preliminary findings under the Digital Services Act challenge the platform's approach to protecting minors through voluntary settings rather than enforceable design choices.

MT
Mei-Lin Tan
Staff Writer · Singapore
Jul 24, 2026
5 min read
Brussels Tells TikTok Default Privacy for Teen Accounts Must Be Mandatory
Brussels Tells TikTok Default Privacy for Teen Accounts Must Be MandatoryCredit: Nick Barclay / The Verge

The Core Dispute

The European Commission has issued preliminary findings that challenge a foundational assumption in TikTok's product architecture: that child safety can be achieved through features users must actively enable. The investigation, conducted under the Digital Services Act, centers on whether platforms should design mandatory privacy defaults for minors rather than offering protection as a menu of optional settings.

At DailyTechWire, we've tracked the evolution of platform accountability frameworks across Asia and Europe for the past three years, and this case represents a significant escalation in regulatory philosophy. The Commission's position suggests that compliance cannot rest on user behavior, particularly when those users are adolescents navigating algorithmically curated environments designed to maximize engagement.

What Brussels Wants Changed

The preliminary findings identify specific design practices that European regulators consider inadequate. The Commission argues that when a minor creates an account designated as "public," the platform should automatically restrict content visibility to users the teenager has explicitly chosen. Under current configurations, content from these accounts can surface in recommendation feeds viewed by strangers, a design choice the Commission believes places the burden of privacy on the least equipped users to manage it.

The investigation also highlights discoverability mechanisms that function independently of account privacy settings. Even when teens configure accounts as private, their profiles remain traceable through the "following" lists of other users, a pattern that regulators argue undermines the intended protections of privacy modes. The Commission's concern is not that these features exist, but that they operate as defaults rather than exceptions.

The Opt-In Architecture Under Scrutiny

TikTok's current framework offers a range of privacy controls, but most require users to navigate settings menus and make affirmative choices. The regulatory critique is that this architecture assumes digital literacy and risk awareness that may not align with adolescent cognitive development or usage patterns. In markets where platform adoption among minors is measured in tens of millions, the Commission's position is that relying on individual action at scale is structurally insufficient.

This is not the first time European regulators have questioned opt-in models for vulnerable populations. Similar debates have emerged around consent mechanisms for data collection, where regulators have increasingly required that the most protective option be the starting point rather than an elective upgrade. The DSA findings extend that logic to content distribution and algorithmic recommendation, areas where platform design directly shapes exposure and interaction.

Regional Context and Enforcement Momentum

The investigation arrives during a period of intensified regulatory pressure on social platforms operating in Europe. The Digital Services Act, which came into full effect for very large online platforms in 2024, grants the Commission enforcement authority that includes fines up to six percent of global annual revenue. Preliminary findings are not final determinations, but they signal the Commission's interpretation of DSA obligations and set the stage for formal proceedings if platforms do not adjust their practices.

Other jurisdictions in Asia have taken varied approaches to the same underlying tension. South Korea's legislative framework emphasizes parental verification and time-limit enforcement, while Singapore's regulatory model has focused on transparency obligations and harm reporting mechanisms. The European approach, as articulated in these findings, leans toward structural design requirements that remove discretion from both platforms and users when minors are involved.

The Algorithmic Recommendation Question

A central element of the Commission's findings concerns the For You feed, TikTok's primary discovery mechanism. The regulators argue that content posted by minors should be excluded from recommendation algorithms that surface material to users outside the teen's chosen network. This represents a direct challenge to the platform's engagement model, which relies on algorithmic curation to match content with audiences regardless of pre-existing social connections.

The tension here is between two competing platform logics: discovery-driven growth, which benefits creators by exposing their work to large audiences, and privacy-by-design, which limits exposure to minimize risk. For minors, the Commission's position is that the latter must take precedence, even if it constrains reach. The practical implementation would require TikTok to segment its recommendation systems by user age and relationship status, a non-trivial engineering challenge with implications for how the platform's core product functions.

What Preliminary Means in Practice

Preliminary findings under the DSA initiate a process rather than impose immediate obligations. TikTok will have the opportunity to respond, propose modifications, or contest the Commission's interpretation of its legal duties. If the Commission proceeds to a formal decision and TikTok does not comply, financial penalties and, in extreme cases, operational restrictions become possible.

The outcome will likely influence how other platforms structure their minor-facing products in European markets. If the Commission's interpretation holds, the principle that safety features must be default rather than optional could extend to adjacent areas: search visibility, direct messaging permissions, data retention practices, and third-party integrations. The preliminary findings are narrow in scope but broad in implication.

The Design Versus Enforcement Debate

The investigation surfaces a broader question about where regulatory intervention should focus: on platform design decisions made at the product level, or on enforcement actions taken after harm occurs. The Commission's approach in this case clearly favors the former, arguing that waiting for individual violations or harm reports is inadequate when design choices shape millions of interactions daily.

This philosophy aligns with emerging regulatory thinking in jurisdictions that have moved from reactive content moderation mandates to proactive design audits. The challenge for platforms is that design-level requirements are harder to satisfy through localized adjustments or regional feature variations. If Brussels insists on default privacy for minors, the engineering and product management implications ripple across global development roadmaps, not just European operations.

What Comes Next

TikTok's response will determine whether this proceeds to a formal enforcement action or resolves through negotiated design changes. The platform has historically argued that its existing tools provide robust protections when used, but that argument has not persuaded regulators who believe use rates among minors do not justify reliance on voluntary adoption.

The preliminary findings are part of a broader DSA workstream that includes parallel investigations into other aspects of TikTok's operations and similar scrutiny of competing platforms. The Commission has signaled that child safety, algorithmic transparency, and content moderation systems are priority areas for enforcement, and this case will set precedent for how far regulators can reach into product design decisions in the name of protecting minors online.

Read next
Policy

Government Equity Stakes in AI Companies Create More Problems Than They Solve

Priya Nair · 6 min
Policy

EPA Eyes Permitting Shortcut That Could Fast-Track Data Center Power Plants

Marcus Halloran · 6 min
Policy

Frontier AI Safety Limits Are Blocking Security Researchers Who Defend Networks

Arjun S. Mehta · 5 min
Spot something wrong? Email corrections@dailytechwire.com. We log every correction publicly.