Brussels Tells TikTok Default Privacy for Teen Accounts Must Be Mandatory
New preliminary findings under the Digital Services Act challenge the platform's approach to protecting minors through voluntary settings rather than enforceable design choices.

The Core Dispute
The European Commission has issued preliminary findings that challenge a foundational assumption in TikTok's product architecture: that child safety can be achieved through features users must actively enable. The investigation, conducted under the Digital Services Act, centers on whether platforms should design mandatory privacy defaults for minors rather than offering protection as a menu of optional settings.
At DailyTechWire, we've tracked the evolution of platform accountability frameworks across Asia and Europe for the past three years, and this case represents a significant escalation in regulatory philosophy. The Commission's position suggests that compliance cannot rest on user behavior, particularly when those users are adolescents navigating algorithmically curated environments designed to maximize engagement.
What Brussels Wants Changed
The preliminary findings identify specific design practices that European regulators consider inadequate. The Commission argues that when a minor creates an account designated as "public," the platform should automatically restrict content visibility to users the teenager has explicitly chosen. Under current configurations, content from these accounts can surface in recommendation feeds viewed by strangers, a design choice the Commission believes places the burden of privacy on the least equipped users to manage it.
The investigation also highlights discoverability mechanisms that function independently of account privacy settings. Even when teens configure accounts as private, their profiles remain traceable through the "following" lists of other users, a pattern that regulators argue undermines the intended protections of privacy modes. The Commission's concern is not that these features exist, but that they operate as defaults rather than exceptions.
The Opt-In Architecture Under Scrutiny
TikTok's current framework offers a range of privacy controls, but most require users to navigate settings menus and make affirmative choices. The regulatory critique is that this architecture assumes digital literacy and risk awareness that may not align with adolescent cognitive development or usage patterns. In markets where platform adoption among minors is measured in tens of millions, the Commission's position is that relying on individual action at scale is structurally insufficient.
This is not the first time European regulators have questioned opt-in models for vulnerable populations. Similar debates have emerged around consent mechanisms for data collection, where regulators have increasingly required that the most protective option be the starting point rather than an elective upgrade. The DSA findings extend that logic to content distribution and algorithmic recommendation, areas where platform design directly shapes exposure and interaction.
Regional Context and Enforcement Momentum
The investigation arrives during a period of intensified regulatory pressure on social platforms operating in Europe. The Digital Services Act, which came into full effect for very large online platforms in 2024, grants the Commission enforcement authority that includes fines up to six percent of global annual revenue. Preliminary findings are not final determinations, but they signal the Commission's interpretation of DSA obligations and set the stage for formal proceedings if platforms do not adjust their practices.
Other jurisdictions in Asia have taken varied approaches to the same underlying tension. South Korea's legislative framework emphasizes parental verification and time-limit enforcement, while Singapore's regulatory model has focused on transparency obligations and harm reporting mechanisms. The European approach, as articulated in these findings, leans toward structural design requirements that remove discretion from both platforms and users when minors are involved.
The Algorithmic Recommendation Question
A central element of the Commission's findings concerns the For You feed, TikTok's primary discovery mechanism. The regulators argue that content posted by minors should be excluded from recommendation algorithms that surface material to users outside the teen's chosen network. This represents a direct challenge to the platform's engagement model, which relies on algorithmic curation to match content with audiences regardless of pre-existing social connections.
The tension here is between two competing platform logics: discovery-driven growth, which benefits creators by exposing their work to large audiences, and privacy-by-design, which limits exposure to minimize risk. For minors, the Commission's position is that the latter must take precedence, even if it constrains reach. The practical implementation would require TikTok to segment its recommendation systems by user age and relationship status, a non-trivial engineering challenge with implications for how the platform's core product functions.
What Preliminary Means in Practice
Preliminary findings under the DSA initiate a process rather than impose immediate obligations. TikTok will have the opportunity to respond, propose modifications, or contest the Commission's interpretation of its legal duties. If the Commission proceeds to a formal decision and TikTok does not comply, financial penalties and, in extreme cases, operational restrictions become possible.
The outcome will likely influence how other platforms structure their minor-facing products in European markets. If the Commission's interpretation holds, the principle that safety features must be default rather than optional could extend to adjacent areas: search visibility, direct messaging permissions, data retention practices, and third-party integrations. The preliminary findings are narrow in scope but broad in implication.
The Design Versus Enforcement Debate
The investigation surfaces a broader question about where regulatory intervention should focus: on platform design decisions made at the product level, or on enforcement actions taken after harm occurs. The Commission's approach in this case clearly favors the former, arguing that waiting for individual violations or harm reports is inadequate when design choices shape millions of interactions daily.
This philosophy aligns with emerging regulatory thinking in jurisdictions that have moved from reactive content moderation mandates to proactive design audits. The challenge for platforms is that design-level requirements are harder to satisfy through localized adjustments or regional feature variations. If Brussels insists on default privacy for minors, the engineering and product management implications ripple across global development roadmaps, not just European operations.
What Comes Next
TikTok's response will determine whether this proceeds to a formal enforcement action or resolves through negotiated design changes. The platform has historically argued that its existing tools provide robust protections when used, but that argument has not persuaded regulators who believe use rates among minors do not justify reliance on voluntary adoption.
The preliminary findings are part of a broader DSA workstream that includes parallel investigations into other aspects of TikTok's operations and similar scrutiny of competing platforms. The Commission has signaled that child safety, algorithmic transparency, and content moderation systems are priority areas for enforcement, and this case will set precedent for how far regulators can reach into product design decisions in the name of protecting minors online.


