There is something quietly telling about the fact that this is the fourth set of formal allegations brought against TikTok by European regulators in the space of two years. The European Commission’s latest preliminary findings, issued under the Digital Services Act, concern the platform’s design choices in relation to minor users — specifically, the ease with which children’s accounts can be discovered and exposed to unwanted contact, cyberbullying, or predatory behaviour. The pattern of repeated enforcement action against the same company raises legitimate questions not only about TikTok’s conduct, but about the architecture of the regulatory regime itself.
The Commission’s case rests on a straightforward structural concern. TikTok, owned by ByteDance, permits children to set their accounts to public, making their content visible to anyone — including, crucially, individuals who hold no TikTok account at all. Even where a child’s account is nominally private, the platform’s “following” and “followers” lists remain accessible to outside parties, providing a route by which strangers can identify and approach young users. The Commission’s position, articulated by EU tech chief Henna Virkkunen and spokesperson Thomas Regnier, is that privacy-protective settings should be the default condition from the moment a minor registers, rather than an opt-in feature that many will never activate. “Children’s content must never be visible to strangers,” Regnier stated, a formulation that is difficult to argue with in principle.
TikTok’s response was measured. The company said it would review the findings and engage constructively with the regulator, pointing to the more than fifty preset privacy and safety features applied to teen accounts from sign-up, and noting that under-18 accounts are private by default and that younger teenagers are excluded from direct messaging and from the algorithmically curated “For You” feed. These are not trivial safeguards, and the Commission’s findings do not suggest they are wholly absent — the dispute appears to concern whether the default configuration is sufficiently restrictive, and whether the platform’s social-graph architecture creates residual vulnerabilities that undermine the headline protections.
The distinction matters. A regulator that conflates genuine negligence with imperfect implementation risks both overcorrecting and undermining the credibility of its own framework. That said, the specific vulnerability identified — the discoverability of children through third-party follower lists, even by non-account holders — is concrete and verifiable, and TikTok has not directly contested it.
Under the Digital Services Act, the Commission holds the power to impose fines of up to six percent of a company’s global annual turnover, a figure that, in TikTok’s case, would represent a substantial sum. TikTok now has the opportunity to examine the Commission’s documentation and submit a formal response before any binding decision is reached. The DSA’s procedural design deliberately separates preliminary findings from final rulings, preserving space for dialogue — a feature that distinguishes it from blunter regulatory instruments, even if critics on both sides of the debate question whether the process moves with sufficient urgency.
The broader context is one of sustained Brussels pressure on large technology platforms, with Meta and Apple having faced their own DSA proceedings in recent years. Whether this cumulative enforcement activity reflects a coherent and proportionate strategy, or an expanding regulatory appetite that risks substituting bureaucratic process for genuine consumer benefit, remains a live debate among those who follow EU digital policy closely. What is clear is that the Commission has chosen to make child safety online a central and recurring priority — and that TikTok, fairly or otherwise, has become its most prominent test case.

