Regulators in Brussels have escalated enforcement action against TikTok, formally charging the ByteDance-owned platform with breaching the EU's stringent Digital Services Act through inadequate safeguards for young users. The preliminary findings, announced on Friday, represent the fourth regulatory complaint lodged against the social media giant in two years, signalling intensifying pressure from European authorities determined to hold technology giants accountable for child protection failures.
The European Commission, which functions as the EU's chief technology regulator, determined that TikTok's account architecture permits design choices that leave children vulnerable to exploitation and abuse. Most critically, the platform allows minors to establish public accounts by default, meaning their content becomes visible to the broader platform and potentially to individuals seeking to target or manipulate vulnerable young people. This foundational design choice directly contradicts the safeguarding principles embedded within the Digital Services Act, which mandates that technology platforms must prioritise protection for minors rather than treating safety as an optional add-on.
The regulatory concerns extend beyond publicly visible accounts. Even when children opt for private account settings, the Commission found persistent vulnerabilities. Young users remain discoverable through the 'following' and 'followers' lists of other accounts, and notably, these profiles can be identified by individuals who do not themselves maintain TikTok accounts. Such architectural decisions effectively create multiple pathways through which bad actors can identify and contact minors, undermining the theoretical protection offered by private account designations.
EU tech commissioner Henna Virkkunen emphasised that the Digital Services Act demands platforms embed protective mechanisms directly into their service designs rather than relegating safety measures to optional features that users must actively enable. This philosophical approach represents a fundamental shift in regulatory thinking—one that positions child safety as a structural requirement rather than a consumer choice. The directive reflects growing frustration among European policymakers that technology companies have historically approached child protection as an afterthought rather than a foundational principle.
The Commission's proposed remedy requires TikTok to restructure how minor accounts function by default. Specifically, accounts for users under eighteen should automatically restrict content visibility to only those individuals whom the young user has explicitly approved. Furthermore, the platform must prevent the forced visibility of minor accounts through secondary discovery pathways that currently allow third parties and non-users to locate and contact children. These requirements would represent a significant operational shift for TikTok's platform, potentially affecting user engagement metrics and the virality mechanisms that have driven the service's popularity.
TikTok has mounted a spirited defence against the allegations, asserting that its teen accounts already incorporate over fifty preset privacy and safety features developed with expert consultation. The company pointed to existing restrictions on direct messaging for users under thirteen and the exclusion of underage users' content from the primary algorithmic feed that dominates platform engagement. However, the EU's position suggests that existing voluntarily-implemented features fail to meet the statutory minimum standards required under European law. The divergence highlights a fundamental tension: companies measure protection by the number of safety tools available, while regulators measure it by whether those protections are activated by default.
The formal charges trigger a procedural window during which TikTok can review the Commission's detailed findings and submit a response before Brussels issues a final decision. That decision could result in substantial financial penalties, potentially amounting to 6 percent of TikTok's annual global revenue. For context, such a calculation would translate to penalties in the hundreds of millions of dollars given the platform's estimated annual revenue from advertising and other commercial activities globally.
This enforcement action follows TikTok's previous experiences with EU regulators. In two earlier cases, the platform reached settlements by offering operational concessions to address specific violations, while a third investigation remains ongoing. The pattern suggests regulators increasingly view TikTok as requiring continuous oversight rather than one-off compliance fixes. For Southeast Asian observers, these developments carry particular significance given the region's enormous youth population and rapidly growing TikTok user base. Malaysian, Indonesian, and Thai regulators have watched European enforcement actions with increasing interest, and the EU's aggressive stance has begun influencing how authorities in this region approach technology oversight.
The broader context matters considerably. The Digital Services Act represents the most comprehensive technology regulation enacted by any major jurisdiction, establishing legal precedents that other regions including potentially Malaysia may eventually adopt or emulate. European enforcement decisions effectively shape global platform behaviour, as companies typically implement changes across all markets to maintain uniform policies rather than maintain region-specific alternatives.
For platform designers and policymakers alike, the case underscores a critical principle now embedded in European law: that platforms cannot simply offer safety options and expect to satisfy regulatory requirements. Protecting minors demands that protective measures operate automatically, invisibly, and without requiring young users or their guardians to navigate complex settings to activate them. As European authorities continue pressing these requirements against major technology companies, the outcomes will likely reverberate across Asia's digital landscape for years ahead.
